<?xml version="1.0" encoding="UTF-8"?>
  <testsuites tests="477" disabled="343" errors="0" failures="12" time="2644.709659487">
      <testsuite name="Red Hat App Studio E2E tests" package="/tmp/tmp.VA2UVYReoU/cmd" tests="477" disabled="88" skipped="255" errors="0" failures="12" time="2644.709659487" timestamp="2026-04-20T19:14:00">
          <properties>
              <property name="SuiteSucceeded" value="false"></property>
              <property name="SuiteHasProgrammaticFocus" value="false"></property>
              <property name="SpecialSuiteFailureReason" value=""></property>
              <property name="SuiteLabels" value="[]"></property>
              <property name="SuiteSemVerConstraints" value="[]"></property>
              <property name="RandomSeed" value="1776711374"></property>
              <property name="RandomizeAllSpecs" value="false"></property>
              <property name="LabelFilter" value="!upgrade-create &amp;&amp; !upgrade-verify &amp;&amp; !upgrade-cleanup &amp;&amp; !release-pipelines &amp;&amp; !disaster-recovery"></property>
              <property name="SemVerFilter" value=""></property>
              <property name="FocusStrings" value=""></property>
              <property name="SkipStrings" value=""></property>
              <property name="FocusFiles" value=""></property>
              <property name="SkipFiles" value=""></property>
              <property name="FailOnPending" value="false"></property>
              <property name="FailOnEmpty" value="false"></property>
              <property name="FailFast" value="false"></property>
              <property name="FlakeAttempts" value="0"></property>
              <property name="DryRun" value="false"></property>
              <property name="ParallelTotal" value="20"></property>
              <property name="OutputInterceptorMode" value="none"></property>
          </properties>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines triggers PipelineRun for symlink component with source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic with component name test-symlink-comp-pnms [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="failed" time="1334.436208294">
              <failure message="Timed out after 1200.001s.&#xA;timed out when waiting for the PipelineRun to start for the Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc000eb4370&gt;: &#xA;    no pipelinerun found for component test-symlink-comp-pnms&#xA;    {&#xA;        s: &#34;no pipelinerun found for component test-symlink-comp-pnms&#34;,&#xA;    }" type="failed">[FAILED] Timed out after 1200.001s.&#xA;timed out when waiting for the PipelineRun to start for the Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc000eb4370&gt;: &#xA;    no pipelinerun found for component test-symlink-comp-pnms&#xA;    {&#xA;        s: &#34;no pipelinerun found for component test-symlink-comp-pnms&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:200 @ 04/20/26 19:35:14.686&#xA;&#xA;There were additional failures detected after the initial failure. These are visible in the timeline&#xA;</failure>
              <system-err>&gt; Enter [BeforeAll] HACBS pipelines - /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:237 @ 04/20/26 19:14:00.456&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;found credentials for image ref quay.io/redhat-appstudio-qe/test-images:pipeline-bundle-1776712446-azvu -&gt; user: redhat-appstudio-qe+redhat_appstudio_quality&#34;&#xA;Created component for scenario sample-python-basic-oci: component: test-comp-jobv, repo: https://github.com/redhat-appstudio-qe/devfile-sample-python-basic, baseBranchName: base-nxcdon, pacBranchName: konflux-test-comp-jobv&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;found credentials for image ref quay.io/redhat-appstudio-qe/test-images:pipeline-bundle-1776712459-llbc -&gt; user: redhat-appstudio-qe+redhat_appstudio_quality&#34;&#xA;Created component for scenario sample-python-basic-oci: component: test-comp-qvnh, repo: https://github.com/redhat-appstudio-qe/devfile-sample-python-basic, baseBranchName: base-jhlkmc, pacBranchName: konflux-test-comp-qvnh&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;found credentials for image ref quay.io/redhat-appstudio-qe/test-images:pipeline-bundle-1776712472-pinr -&gt; user: redhat-appstudio-qe+redhat_appstudio_quality&#34;&#xA;Image repository for component test-comp-cknl in namespace build-e2e-eqjr do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Created component for scenario sample-python-basic-oci: component: test-comp-cknl, repo: https://github.com/redhat-appstudio-qe/devfile-sample-python-basic, baseBranchName: base-pzfsow, pacBranchName: konflux-test-comp-cknl&#xA;Image repository for component test-symlink-comp-pnms in namespace build-e2e-eqjr do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Created component for scenario sample-python-basic-oci: component: test-symlink-comp-pnms, repo: https://github.com/redhat-appstudio-qe/devfile-sample-python-basic, baseBranchName: base-oguozi, pacBranchName: konflux-test-symlink-comp-pnms&#xA;&lt; Exit [BeforeAll] HACBS pipelines - /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:237 @ 04/20/26 19:15:14.684 (1m14.228s)&#xA;&gt; Enter [It] triggers PipelineRun for symlink component with source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic with component name test-symlink-comp-pnms - /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:325 @ 04/20/26 19:15:14.684&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;PipelineRun has not been created yet for Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;[FAILED] Timed out after 1200.001s.&#xA;timed out when waiting for the PipelineRun to start for the Component build-e2e-eqjr/test-symlink-comp-pnms&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc000eb4370&gt;: &#xA;    no pipelinerun found for component test-symlink-comp-pnms&#xA;    {&#xA;        s: &#34;no pipelinerun found for component test-symlink-comp-pnms&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:200 @ 04/20/26 19:35:14.686&#xA;&lt; Exit [It] triggers PipelineRun for symlink component with source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic with component name test-symlink-comp-pnms - /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:325 @ 04/20/26 19:35:14.686 (20m0.002s)&#xA;&gt; Enter [AfterAll] HACBS pipelines - /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:271 @ 04/20/26 19:35:14.686&#xA;error while getting pipelineruns: no pipelinerun found for application test-app-nxdqerror while getting pipelineruns: no pipelinerun found for application test-app-nxdqerror while getting pipelineruns: no pipelinerun found for application test-app-nxdqerror while getting pipelineruns: no pipelinerun found for application test-app-nxdqerror while getting pipelineruns: no pipelinerun found for application test-app-nxdqerror while getting pipelineruns: no pipelinerun found for application test-app-nxdq&#xA;[FAILED] Timed out after 60.000s.&#xA;timed out when trying to remove the e2e-test finalizer from pipelineruns&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc001b86e90&gt;: &#xA;    no pipelinerun found for application test-app-nxdq&#xA;    {&#xA;        s: &#34;no pipelinerun found for application test-app-nxdq&#34;,&#xA;    }&#xA;In [AfterAll] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:289 @ 04/20/26 19:36:14.686&#xA;&lt; Exit [AfterAll] HACBS pipelines - /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:271 @ 04/20/26 19:36:14.686 (1m0s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build templates E2E test] - /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:207 @ 04/20/26 19:36:14.687&#xA;&lt; Exit [AfterEach] [build-service-suite Build templates E2E test] - /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:207 @ 04/20/26 19:36:14.892 (205ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci triggers PipelineRun for component with source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta-min [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:338 @ 04/20/26 19:36:14.893&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci triggers PipelineRun for component with source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:338 @ 04/20/26 19:36:14.893&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci triggers PipelineRun for component with source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:338 @ 04/20/26 19:36:14.893&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) should eventually finish successfully for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:356 @ 04/20/26 19:36:14.893&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) should push Dockerfile to registry [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:366 @ 04/20/26 19:36:14.894&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) floating tags are created successfully [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:378 @ 04/20/26 19:36:14.894&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) image manifest mediaType is correct [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:395 @ 04/20/26 19:36:14.894&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) check for source images if enabled in pipeline [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:420 @ 04/20/26 19:36:14.894&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build should have Pipeline Records [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:498 @ 04/20/26 19:36:14.894&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build should have Pipeline Logs [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) should validate tekton taskrun test results for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:540 @ 04/20/26 19:36:14.895&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry verify-enterprise-contract check should pass [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry should have Hermeto content in the SBOM in case the build was hermetic [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:661 @ 04/20/26 19:36:14.895&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) build-definitions ec pipelines runs ec pipeline pipelines/enterprise-contract.yaml [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) should eventually finish successfully for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:356 @ 04/20/26 19:36:14.895&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) should push Dockerfile to registry [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:366 @ 04/20/26 19:36:14.896&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) floating tags are created successfully [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:378 @ 04/20/26 19:36:14.896&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) image manifest mediaType is correct [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:395 @ 04/20/26 19:36:14.896&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) check for source images if enabled in pipeline [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:420 @ 04/20/26 19:36:14.896&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta should have Pipeline Records [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:498 @ 04/20/26 19:36:14.896&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta should have Pipeline Logs [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) should validate tekton taskrun test results for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:540 @ 04/20/26 19:36:14.897&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry verify-enterprise-contract check should pass [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry should have Hermeto content in the SBOM in case the build was hermetic [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:661 @ 04/20/26 19:36:14.897&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) build-definitions ec pipelines runs ec pipeline pipelines/enterprise-contract.yaml [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) should eventually finish successfully for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta-min [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:356 @ 04/20/26 19:36:14.897&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) should push Dockerfile to registry [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:366 @ 04/20/26 19:36:14.897&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) floating tags are created successfully [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:378 @ 04/20/26 19:36:14.898&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) image manifest mediaType is correct [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:395 @ 04/20/26 19:36:14.898&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) check for source images if enabled in pipeline [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:420 @ 04/20/26 19:36:14.898&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta-min should have Pipeline Records [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:498 @ 04/20/26 19:36:14.898&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta-min should have Pipeline Logs [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) should validate tekton taskrun test results for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta-min [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:540 @ 04/20/26 19:36:14.899&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry verify-enterprise-contract check should pass [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry should have Hermeto content in the SBOM in case the build was hermetic [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:661 @ 04/20/26 19:36:14.899&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) build-definitions ec pipelines runs ec pipeline pipelines/enterprise-contract.yaml [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines pipelineRun should fail for symlink component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic with component name test-symlink-comp-pnms [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/build_templates.go:816 @ 04/20/26 19:36:14.899&#xA;</system-err>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when creating tenants and running initial pipelines should create both tenants concurrently [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when creating tenants and running initial pipelines should wait for all build PipelineRuns to succeed [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when backing up tenant data should create backup CRs for both tenants concurrently [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when simulating disaster by deleting namespaces should delete both tenant namespaces [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when restoring from backup should restore tenant-1 (KokoHazamar) via velero CLI method [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when restoring from backup should restore tenant-2 (MosheKipod) via oc command method [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when performing post-restore recovery should rotate SA tokens on both tenants [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when verifying restored tenants should confirm structural integrity of both tenants [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when verifying restored tenants should confirm functional pipeline execution after restore [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when creating tenants on the old Konflux version should create both tenants concurrently [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when creating tenants on the old Konflux version should wait for all build PipelineRuns to succeed [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when backing up tenant data before upgrade should create backup CRs for both tenants concurrently [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when simulating disaster by deleting namespaces should delete both tenant namespaces [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when upgrading Konflux to the new version should upgrade the cluster and verify Velero survived [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when restoring tenants from backup on the new Konflux version should restore tenant-1 (KokoHazamar) via velero CLI method [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when restoring tenants from backup on the new Konflux version should restore tenant-2 (MosheKipod) via oc command method [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when performing post-restore recovery should rotate SA tokens on both tenants [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when verifying restored tenants should confirm structural integrity of both tenants [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when verifying restored tenants should confirm functional pipeline execution after restore [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build annotations when component is created with invalid build request annotations handles invalid request annotation [build-service, github, annotations]" classname="Red Hat App Studio E2E tests" status="passed" time="97.548097957">
              <system-err>&gt; Enter [BeforeAll] test build annotations - /tmp/tmp.VA2UVYReoU/tests/build/annotations.go:35 @ 04/20/26 19:14:00.459&#xA;&lt; Exit [BeforeAll] test build annotations - /tmp/tmp.VA2UVYReoU/tests/build/annotations.go:35 @ 04/20/26 19:14:25.351 (24.892s)&#xA;&gt; Enter [BeforeAll] when component is created with invalid build request annotations - /tmp/tmp.VA2UVYReoU/tests/build/annotations.go:69 @ 04/20/26 19:14:25.351&#xA;Image repository for component test-annotations-appsdq in namespace build-e2e-atdo do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [BeforeAll] when component is created with invalid build request annotations - /tmp/tmp.VA2UVYReoU/tests/build/annotations.go:69 @ 04/20/26 19:14:35.942 (10.591s)&#xA;&gt; Enter [It] handles invalid request annotation - /tmp/tmp.VA2UVYReoU/tests/build/annotations.go:89 @ 04/20/26 19:14:35.942&#xA;build status annotation value: {&#34;message&#34;:&#34;unexpected build request: foo&#34;}&#xA;&lt; Exit [It] handles invalid request annotation - /tmp/tmp.VA2UVYReoU/tests/build/annotations.go:89 @ 04/20/26 19:15:35.953 (1m0.011s)&#xA;&gt; Enter [AfterAll] test build annotations - /tmp/tmp.VA2UVYReoU/tests/build/annotations.go:51 @ 04/20/26 19:15:35.953&#xA;&lt; Exit [AfterAll] test build annotations - /tmp/tmp.VA2UVYReoU/tests/build/annotations.go:51 @ 04/20/26 19:15:38.004 (2.051s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/annotations.go:24 @ 04/20/26 19:15:38.004&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/annotations.go:24 @ 04/20/26 19:15:38.004 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-push-to-redhat-io pipeline] Rh-push-to-redhat-io happy path Post-release verification verifies if the release CR is created [release-pipelines, rh-push-to-registry-redhat-io, PushToRedhatIO]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-push-to-redhat-io pipeline] Rh-push-to-redhat-io happy path Post-release verification verifies the rhio release pipelinerun is running and succeeds [release-pipelines, rh-push-to-registry-redhat-io, PushToRedhatIO]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-push-to-redhat-io pipeline] Rh-push-to-redhat-io happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, rh-push-to-registry-redhat-io, PushToRedhatIO]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-push-to-redhat-io pipeline] Rh-push-to-redhat-io happy path Post-release verification verifies if the MR URL is valid [release-pipelines, rh-push-to-registry-redhat-io, PushToRedhatIO]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for multi arch with rh-advisories pipeline] Multi arch test happy path Post-release verification verifies the release CR is created [release-pipelines, rh-advisories, multiarch-advisories, multiArchAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for multi arch with rh-advisories pipeline] Multi arch test happy path Post-release verification verifies the multiarch release pipelinerun is running and succeeds [release-pipelines, rh-advisories, multiarch-advisories, multiArchAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for multi arch with rh-advisories pipeline] Multi arch test happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, rh-advisories, multiarch-advisories, multiArchAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for multi arch with rh-advisories pipeline] Multi arch test happy path Post-release verification verifies if the repository URL is valid [release-pipelines, rh-advisories, multiarch-advisories, multiArchAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws host-pool allocation when the Component with multi-platform-build is created a PipelineRun is triggered [multi-platform, aws-host-pool]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws host-pool allocation when the Component with multi-platform-build is created the build-container task from component pipelinerun is buildah-remote [multi-platform, aws-host-pool]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws host-pool allocation when the Component with multi-platform-build is created The multi platform secret is populated [multi-platform, aws-host-pool]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws host-pool allocation when the Component with multi-platform-build is created that PipelineRun completes successfully [multi-platform, aws-host-pool]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws host-pool allocation when the Component with multi-platform-build is created test that cleanup happened successfully [multi-platform, aws-host-pool]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws dynamic allocation when the Component with multi-platform-build is created a PipelineRun is triggered [multi-platform, aws-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws dynamic allocation when the Component with multi-platform-build is created the build-container task from component pipelinerun is buildah-remote [multi-platform, aws-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws dynamic allocation when the Component with multi-platform-build is created The multi platform secret is populated [multi-platform, aws-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws dynamic allocation when the Component with multi-platform-build is created that PipelineRun completes successfully [multi-platform, aws-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws dynamic allocation when the Component with multi-platform-build is created check cleanup happened successfully [multi-platform, aws-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm system z dynamic allocation when the Component with multi-platform-build is created a PipelineRun is triggered [multi-platform, ibmz-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm system z dynamic allocation when the Component with multi-platform-build is created the build-container task from component pipelinerun is buildah-remote [multi-platform, ibmz-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm system z dynamic allocation when the Component with multi-platform-build is created The multi platform secret is populated [multi-platform, ibmz-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm system z dynamic allocation when the Component with multi-platform-build is created that PipelineRun completes successfully [multi-platform, ibmz-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm system z dynamic allocation when the Component with multi-platform-build is created check cleanup happened successfully [multi-platform, ibmz-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm power pc dynamic allocation when the Component with multi-platform-build is created a PipelineRun is triggered [multi-platform, ibmp-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm power pc dynamic allocation when the Component with multi-platform-build is created the build-container task from component pipelinerun is buildah-remote [multi-platform, ibmp-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm power pc dynamic allocation when the Component with multi-platform-build is created The multi platform secret is populated [multi-platform, ibmp-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm power pc dynamic allocation when the Component with multi-platform-build is created that PipelineRun completes successfully [multi-platform, ibmp-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm power pc dynamic allocation when the Component with multi-platform-build is created check cleanup happened successfully [multi-platform, ibmp-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] post-release verification. missing ReleasePlan makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. [release-service, release-neg, negMissingReleasePlan]" classname="Red Hat App Studio E2E tests" status="passed" time="56.87871171">
              <system-err>&gt; Enter [BeforeAll] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:34 @ 04/20/26 19:14:00.659&#xA;&lt; Exit [BeforeAll] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:34 @ 04/20/26 19:14:57.421 (56.762s)&#xA;&gt; Enter [It] missing ReleasePlan makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:66 @ 04/20/26 19:14:57.421&#xA;&lt; Exit [It] missing ReleasePlan makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:66 @ 04/20/26 19:14:57.537 (116ms)&#xA;&gt; Enter [AfterEach] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:32 @ 04/20/26 19:14:57.537&#xA;&lt; Exit [AfterEach] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:32 @ 04/20/26 19:14:57.537 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] post-release verification. missing ReleasePlanAdmission makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. [release-service, release-neg, negMissingReleasePlan]" classname="Red Hat App Studio E2E tests" status="passed" time="44.098126777">
              <system-err>&gt; Enter [It] missing ReleasePlanAdmission makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:76 @ 04/20/26 19:14:57.538&#xA;&lt; Exit [It] missing ReleasePlanAdmission makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:76 @ 04/20/26 19:14:57.558 (20ms)&#xA;&gt; Enter [AfterEach] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:32 @ 04/20/26 19:14:57.558&#xA;&lt; Exit [AfterEach] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:32 @ 04/20/26 19:14:57.558 (0s)&#xA;&gt; Enter [AfterAll] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:58 @ 04/20/26 19:14:57.558&#xA;&lt; Exit [AfterAll] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/missing_release_plan_and_admission.go:58 @ 04/20/26 19:15:41.636 (44.077s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite [RELEASE-2136] Release CR fails when block-releases true in ReleasePlanAdmission.] post-release verification. block-releases true in ReleasePlanAdmission makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. [release-service, release-neg, negBlockReleases]" classname="Red Hat App Studio E2E tests" status="passed" time="103.015350484">
              <system-err>&gt; Enter [BeforeAll] [release-service-suite [RELEASE-2136] Release CR fails when block-releases true in ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/block_releases_release_plan_admission.go:34 @ 04/20/26 19:14:00.659&#xA;&lt; Exit [BeforeAll] [release-service-suite [RELEASE-2136] Release CR fails when block-releases true in ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/block_releases_release_plan_admission.go:34 @ 04/20/26 19:15:02.384 (1m1.725s)&#xA;&gt; Enter [It] block-releases true in ReleasePlanAdmission makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. - /tmp/tmp.VA2UVYReoU/tests/release/service/block_releases_release_plan_admission.go:69 @ 04/20/26 19:15:02.384&#xA;&lt; Exit [It] block-releases true in ReleasePlanAdmission makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. - /tmp/tmp.VA2UVYReoU/tests/release/service/block_releases_release_plan_admission.go:69 @ 04/20/26 19:15:02.531 (147ms)&#xA;&gt; Enter [AfterEach] [release-service-suite [RELEASE-2136] Release CR fails when block-releases true in ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/block_releases_release_plan_admission.go:32 @ 04/20/26 19:15:02.532&#xA;&lt; Exit [AfterEach] [release-service-suite [RELEASE-2136] Release CR fails when block-releases true in ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/block_releases_release_plan_admission.go:32 @ 04/20/26 19:15:02.532 (0s)&#xA;&gt; Enter [AfterAll] [release-service-suite [RELEASE-2136] Release CR fails when block-releases true in ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/block_releases_release_plan_admission.go:61 @ 04/20/26 19:15:02.532&#xA;&lt; Exit [AfterAll] [release-service-suite [RELEASE-2136] Release CR fails when block-releases true in ReleasePlanAdmission.] - /tmp/tmp.VA2UVYReoU/tests/release/service/block_releases_release_plan_admission.go:61 @ 04/20/26 19:15:43.674 (41.142s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite Release service tenant pipeline] Post-release verification verifies that a Release CR should have been created in the dev namespace [release-service, tenant]" classname="Red Hat App Studio E2E tests" status="passed" time="25.770840994">
              <system-err>&gt; Enter [BeforeAll] [release-service-suite Release service tenant pipeline] - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:41 @ 04/20/26 19:14:00.456&#xA;snapshotPush.Name: %s snapshot-sample-eahb&#xA;&lt; Exit [BeforeAll] [release-service-suite Release service tenant pipeline] - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:41 @ 04/20/26 19:14:23.74 (23.284s)&#xA;&gt; Enter [It] verifies that a Release CR should have been created in the dev namespace - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:110 @ 04/20/26 19:14:23.741&#xA;&lt; Exit [It] verifies that a Release CR should have been created in the dev namespace - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:110 @ 04/20/26 19:14:26.226 (2.486s)&#xA;&gt; Enter [AfterEach] [release-service-suite Release service tenant pipeline] - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:28 @ 04/20/26 19:14:26.227&#xA;&lt; Exit [AfterEach] [release-service-suite Release service tenant pipeline] - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:28 @ 04/20/26 19:14:26.227 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite Release service tenant pipeline] Post-release verification verifies that Tenant PipelineRun is triggered [release-service, tenant]" classname="Red Hat App Studio E2E tests" status="passed" time="40.059329728">
              <system-err>&gt; Enter [It] verifies that Tenant PipelineRun is triggered - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:117 @ 04/20/26 19:14:26.227&#xA;PipelineRun has not been created yet for release %s/%s tenant-dev-wgey snapshot-sample-eahb-vhlds&#xA;PipelineRun tenant-2dn4t reason: Running&#xA;PipelineRun tenant-2dn4t reason: Succeeded&#xA;&lt; Exit [It] verifies that Tenant PipelineRun is triggered - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:117 @ 04/20/26 19:15:06.286 (40.059s)&#xA;&gt; Enter [AfterEach] [release-service-suite Release service tenant pipeline] - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:28 @ 04/20/26 19:15:06.286&#xA;&lt; Exit [AfterEach] [release-service-suite Release service tenant pipeline] - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:28 @ 04/20/26 19:15:06.286 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite Release service tenant pipeline] Post-release verification verifies that a Release is marked as succeeded. [release-service, tenant]" classname="Red Hat App Studio E2E tests" status="passed" time="57.088747882">
              <system-err>&gt; Enter [It] verifies that a Release is marked as succeeded. - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:121 @ 04/20/26 19:15:06.287&#xA;&lt; Exit [It] verifies that a Release is marked as succeeded. - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:121 @ 04/20/26 19:15:06.303 (16ms)&#xA;&gt; Enter [AfterEach] [release-service-suite Release service tenant pipeline] - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:28 @ 04/20/26 19:15:06.303&#xA;&lt; Exit [AfterEach] [release-service-suite Release service tenant pipeline] - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:28 @ 04/20/26 19:15:06.303 (0s)&#xA;&gt; Enter [AfterAll] [release-service-suite Release service tenant pipeline] - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:102 @ 04/20/26 19:15:06.304&#xA;&lt; Exit [AfterAll] [release-service-suite Release service tenant pipeline] - /tmp/tmp.VA2UVYReoU/tests/release/service/tenant_pipelines.go:102 @ 04/20/26 19:16:03.375 (57.072s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite Release service happy path] Post-release verification verifies that a Release CR should have been created in the dev namespace [release-service, happy-path]" classname="Red Hat App Studio E2E tests" status="passed" time="63.266809353">
              <system-err>&gt; Enter [BeforeAll] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:42 @ 04/20/26 19:14:00.557&#xA;snapshotPush.Name: %s snapshot-sample-ttef&#xA;&lt; Exit [BeforeAll] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:42 @ 04/20/26 19:15:03.607 (1m3.05s)&#xA;&gt; Enter [It] verifies that a Release CR should have been created in the dev namespace - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:151 @ 04/20/26 19:15:03.607&#xA;&lt; Exit [It] verifies that a Release CR should have been created in the dev namespace - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:151 @ 04/20/26 19:15:03.726 (119ms)&#xA;&gt; Enter [AfterEach] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:27 @ 04/20/26 19:15:03.726&#xA;&lt; Exit [AfterEach] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:27 @ 04/20/26 19:15:03.726 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite Release service happy path] Post-release verification verifies that Release PipelineRun is triggered [release-service, happy-path]" classname="Red Hat App Studio E2E tests" status="passed" time="80.01263518">
              <system-err>&gt; Enter [It] verifies that Release PipelineRun is triggered - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:158 @ 04/20/26 19:15:03.726&#xA;PipelineRun has not been created yet for release %s/%s happy-path-thok snapshot-sample-ttef-qnsmw&#xA;PipelineRun managed-qffj5 reason: Running&#xA;PipelineRun managed-qffj5 reason: Running&#xA;PipelineRun managed-qffj5 reason: Running&#xA;PipelineRun managed-qffj5 reason: Succeeded&#xA;&lt; Exit [It] verifies that Release PipelineRun is triggered - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:158 @ 04/20/26 19:16:23.739 (1m20.012s)&#xA;&gt; Enter [AfterEach] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:27 @ 04/20/26 19:16:23.739&#xA;&lt; Exit [AfterEach] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:27 @ 04/20/26 19:16:23.739 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite Release service happy path] Post-release verification verifies that Enterprise Contract Task has succeeded in the Release PipelineRun [release-service, happy-path]" classname="Red Hat App Studio E2E tests" status="passed" time="0.109300222">
              <system-err>&gt; Enter [It] verifies that Enterprise Contract Task has succeeded in the Release PipelineRun - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:162 @ 04/20/26 19:16:23.739&#xA;the status of the verify-conforma TaskRun on the release pipeline is: [{Succeeded True  {2026-04-20 19:16:12 +0000 UTC} Succeeded All Steps have completed executing}]&#xA;&lt; Exit [It] verifies that Enterprise Contract Task has succeeded in the Release PipelineRun - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:162 @ 04/20/26 19:16:23.848 (109ms)&#xA;&gt; Enter [AfterEach] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:27 @ 04/20/26 19:16:23.849&#xA;&lt; Exit [AfterEach] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:27 @ 04/20/26 19:16:23.849 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite Release service happy path] Post-release verification verifies that a Release is marked as succeeded. [release-service, happy-path]" classname="Red Hat App Studio E2E tests" status="passed" time="79.134712257">
              <system-err>&gt; Enter [It] verifies that a Release is marked as succeeded. - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:174 @ 04/20/26 19:16:23.849&#xA;&lt; Exit [It] verifies that a Release is marked as succeeded. - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:174 @ 04/20/26 19:16:23.856 (7ms)&#xA;&gt; Enter [AfterEach] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:27 @ 04/20/26 19:16:23.856&#xA;&lt; Exit [AfterEach] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:27 @ 04/20/26 19:16:23.856 (0s)&#xA;&gt; Enter [AfterAll] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:142 @ 04/20/26 19:16:23.856&#xA;&lt; Exit [AfterAll] [release-service-suite Release service happy path] - /tmp/tmp.VA2UVYReoU/tests/release/service/happy_path.go:142 @ 04/20/26 19:17:42.984 (1m19.128s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for release-to-github pipeline] Release-to-github happy path Post-release verification verifies if release CR is created [release-pipelines, release-to-github, releaseToGithub]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for release-to-github pipeline] Release-to-github happy path Post-release verification verifies the release pipelinerun is running and succeeds [release-pipelines, release-to-github, releaseToGithub]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for release-to-github pipeline] Release-to-github happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, release-to-github, releaseToGithub]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for release-to-github pipeline] Release-to-github happy path Post-release verification verifies if the Release exists in github repo [release-pipelines, release-to-github, releaseToGithub]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] infrastructure is running verifies if the chains controller is running [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="passed" time="40.155862239">
              <system-err>&gt; Enter [BeforeAll] [enterprise-contract-suite Conforma E2E tests] - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:31 @ 04/20/26 19:14:00.565&#xA;&lt; Exit [BeforeAll] [enterprise-contract-suite Conforma E2E tests] - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:31 @ 04/20/26 19:14:40.672 (40.107s)&#xA;&gt; Enter [It] verifies if the chains controller is running - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:43 @ 04/20/26 19:14:40.672&#xA;&lt; Exit [It] verifies if the chains controller is running - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:43 @ 04/20/26 19:14:40.721 (49ms)&#xA;&gt; Enter [AfterEach] [enterprise-contract-suite Conforma E2E tests] - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:29 @ 04/20/26 19:14:40.721&#xA;&lt; Exit [AfterEach] [enterprise-contract-suite Conforma E2E tests] - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:29 @ 04/20/26 19:14:40.721 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] infrastructure is running verifies the signing secret is present [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="passed" time="0.037082086">
              <system-err>&gt; Enter [It] verifies the signing secret is present - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:48 @ 04/20/26 19:14:40.722&#xA;&lt; Exit [It] verifies the signing secret is present - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:48 @ 04/20/26 19:14:40.759 (37ms)&#xA;&gt; Enter [AfterEach] [enterprise-contract-suite Conforma E2E tests] - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:29 @ 04/20/26 19:14:40.759&#xA;&lt; Exit [AfterEach] [enterprise-contract-suite Conforma E2E tests] - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:29 @ 04/20/26 19:14:40.759 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task creates signature and attestation [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="passed" time="226.921261647">
              <system-err>&gt; Enter [BeforeAll] test creating and signing an image and task - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:73 @ 04/20/26 19:14:40.759&#xA;Creating Pipeline &#34;buildah-demo-hfropftayf&#34;&#xA;Waiting for pipeline &#34;buildah-demo-hfropftayf&#34; to finish&#xA;The pipeline named &#34;buildah-demo-hfropftayf&#34; in namespace &#34;chains-e2e-mdkj&#34; succeeded&#xA;The image signed by Tekton Chains is quay.io/redhat-appstudio-qe/test-images:buildah-demo-hfropftayf@sha256:f7879ac0d584ab8a184e5d7f8bf7bdc39e48560c80bb0f2163e21be1c5f9227c&#xA;&lt; Exit [BeforeAll] test creating and signing an image and task - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:73 @ 04/20/26 19:18:26.204 (3m45.445s)&#xA;&gt; Enter [It] creates signature and attestation - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:115 @ 04/20/26 19:18:26.204&#xA;failed to get cosign result for image quay.io/redhat-appstudio-qe/test-images:buildah-demo-hfropftayf@sha256:f7879ac0d584ab8a184e5d7f8bf7bdc39e48560c80bb0f2163e21be1c5f9227c: failed to find cosign results for image quay.io/redhat-appstudio-qe/test-images:buildah-demo-hfropftayf@sha256:f7879ac0d584ab8a184e5d7f8bf7bdc39e48560c80bb0f2163e21be1c5f9227c: error when getting attestation tag: cannot get manifest digest from quay.io/redhat-appstudio-qe/test-images:sha256-f7879ac0d584ab8a184e5d7f8bf7bdc39e48560c80bb0f2163e21be1c5f9227c.att image. response body: {&#34;tags&#34;: [], &#34;page&#34;: 1, &#34;has_additional&#34;: false}&#xA;&#xA;&#xA;Cosign verify pass with .att and .sig ImageStreamTags found for quay.io/redhat-appstudio-qe/test-images:buildah-demo-hfropftayf@sha256:f7879ac0d584ab8a184e5d7f8bf7bdc39e48560c80bb0f2163e21be1c5f9227c&#xA;&lt; Exit [It] creates signature and attestation - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:115 @ 04/20/26 19:18:27.68 (1.476s)&#xA;&gt; Enter [AfterEach] [enterprise-contract-suite Conforma E2E tests] - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:29 @ 04/20/26 19:18:27.68&#xA;&lt; Exit [AfterEach] [enterprise-contract-suite Conforma E2E tests] - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:29 @ 04/20/26 19:18:27.68 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task succeeds when policy is met [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="failed" time="43.492522183">
              <failure message="Expected&#xA;    &lt;bool&gt;: false&#xA;to be true" type="failed">[FAILED] Expected&#xA;    &lt;bool&gt;: false&#xA;to be true&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:190 @ 04/20/26 19:19:10.973&#xA;</failure>
              <system-err>&gt; Enter [BeforeAll] verify-enterprise-contract task - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:133 @ 04/20/26 19:18:27.681&#xA;Copy public key from openshift-pipelines/signing-secrets to a new secret&#xA;Configured Rekor host: https://rekor.sigstore.dev&#xA;Using verify EC task bundle: quay.io/conforma/tekton-task:kf-cdfd9188f9352d7269ae1fe8c273a9e67f60ab8a@sha256:3801e78906a70b6dcf850a063cd90b8f5a785b3b54e39ba04630268b08703048&#xA;&lt; Exit [BeforeAll] verify-enterprise-contract task - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:133 @ 04/20/26 19:18:27.719 (39ms)&#xA;&gt; Enter [BeforeEach] verify-enterprise-contract task - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:154 @ 04/20/26 19:18:27.72&#xA;&lt; Exit [BeforeEach] verify-enterprise-contract task - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:154 @ 04/20/26 19:18:27.74 (20ms)&#xA;&gt; Enter [It] succeeds when policy is met - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:177 @ 04/20/26 19:18:27.74&#xA;Creating Pipeline &#34;verify-enterprise-contract-run-w2tln&#34;&#xA;Waiting for pipeline &#34;verify-enterprise-contract-run-w2tln&#34; to finish&#xA;*** TaskRun status:&#xA;artifacts: {}&#xA;completionTime: &#34;2026-04-20T19:19:10Z&#34;&#xA;conditions:&#xA;- lastTransitionTime: &#34;2026-04-20T19:19:10Z&#34;&#xA;  message: &#39;&#34;step-show-config&#34; exited with code 2: Error&#39;&#xA;  reason: Failed&#xA;  status: &#34;False&#34;&#xA;  type: Succeeded&#xA;podName: verify-enterprise-contract-ff10333682fc0172b279ea64b944c06b-pod&#xA;provenance:&#xA;  featureFlags:&#xA;    awaitSidecarReadiness: true&#xA;    coschedule: workspaces&#xA;    enableAPIFields: alpha&#xA;    enableParamEnum: true&#xA;    enableProvenanceInStatus: true&#xA;    enforceNonfalsifiability: none&#xA;    maxResultSize: 4096&#xA;    resultExtractionMethod: termination-message&#xA;    runningInEnvWithInjectedSidecars: true&#xA;    verificationNoMatchPolicy: ignore&#xA;  refSource:&#xA;    digest:&#xA;      sha256: 3801e78906a70b6dcf850a063cd90b8f5a785b3b54e39ba04630268b08703048&#xA;    entryPoint: verify-enterprise-contract&#xA;    uri: quay.io/conforma/tekton-task&#xA;spanContext:&#xA;  traceparent: 00-56648284d71d959fe24e226a1e3df9d0-752ed45df5394c41-01&#xA;startTime: &#34;2026-04-20T19:18:28Z&#34;&#xA;steps:&#xA;- container: step-initialize-tuf&#xA;  imageID: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;  name: initialize-tuf&#xA;  provenance: {}&#xA;  terminated:&#xA;    containerID: cri-o://5e836c6659f2734a6de486d0524a2baae1dd769c81b45bec3a3604296910b916&#xA;    exitCode: 0&#xA;    finishedAt: &#34;2026-04-20T19:19:03Z&#34;&#xA;    reason: Completed&#xA;    startedAt: &#34;2026-04-20T19:19:03Z&#34;&#xA;  terminationReason: Skipped&#xA;- container: step-reduce&#xA;  imageID: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;  name: reduce&#xA;  provenance: {}&#xA;  terminated:&#xA;    containerID: cri-o://e5a273d834203f5de88f0a538f64271d153e734703a0085c39522d85ec893e3c&#xA;    exitCode: 0&#xA;    finishedAt: &#34;2026-04-20T19:19:03Z&#34;&#xA;    reason: Completed&#xA;    startedAt: &#34;2026-04-20T19:19:03Z&#34;&#xA;  terminationReason: Completed&#xA;- container: step-validate&#xA;  imageID: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;  name: validate&#xA;  provenance: {}&#xA;  terminated:&#xA;    containerID: cri-o://62df43b7d40d2b2c10315af6914e7f45aea8e5318a9a934477862f2db0ff6489&#xA;    exitCode: 1&#xA;    finishedAt: &#34;2026-04-20T19:19:08Z&#34;&#xA;    reason: Completed&#xA;    startedAt: &#34;2026-04-20T19:19:04Z&#34;&#xA;  terminationReason: Continued&#xA;- container: step-report-json&#xA;  imageID: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;  name: report-json&#xA;  provenance: {}&#xA;  terminated:&#xA;    containerID: cri-o://84ad9c669f4d0254ca7d2b32e5d7c8821b93a1badb270909d67e0a698d7b7426&#xA;    exitCode: 0&#xA;    finishedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;    reason: Completed&#xA;    startedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;  terminationReason: Completed&#xA;- container: step-summary&#xA;  imageID: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;  name: summary&#xA;  provenance: {}&#xA;  terminated:&#xA;    containerID: cri-o://23c7226f71db1143c020675687a9cf61cf6dac886b5b32f1a02acf8a2cc0b248&#xA;    exitCode: 2&#xA;    finishedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;    reason: Completed&#xA;    startedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;  terminationReason: Continued&#xA;- container: step-info&#xA;  imageID: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;  name: info&#xA;  provenance: {}&#xA;  terminated:&#xA;    containerID: cri-o://514efe0ba3fd7ffb9ea2faab9503300a94599c68b663014884e8fc437d0e3445&#xA;    exitCode: 0&#xA;    finishedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;    reason: Completed&#xA;    startedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;  terminationReason: Completed&#xA;- container: step-version&#xA;  imageID: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;  name: version&#xA;  provenance: {}&#xA;  terminated:&#xA;    containerID: cri-o://7e255a68435e5825c1973c85c8a3553c90b5fea9504f3dead8b64f99cf06ba39&#xA;    exitCode: 0&#xA;    finishedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;    reason: Completed&#xA;    startedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;  terminationReason: Completed&#xA;- container: step-show-config&#xA;  imageID: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;  name: show-config&#xA;  provenance: {}&#xA;  terminated:&#xA;    containerID: cri-o://7806cf66728eb18729c319c10f587dec0b83c8d42bc01a83cd4cb6a54dc35139&#xA;    exitCode: 2&#xA;    finishedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;    reason: Error&#xA;    startedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;  terminationReason: Error&#xA;- container: step-assert&#xA;  imageID: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;  name: assert&#xA;  provenance: {}&#xA;  terminated:&#xA;    containerID: cri-o://01726e11d3293569b926c510a2cc546b4cf59180151374b1911053523215770f&#xA;    exitCode: 1&#xA;    finishedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;    reason: Error&#xA;    startedAt: &#34;2026-04-20T19:19:09Z&#34;&#xA;  terminationReason: Skipped&#xA;taskSpec:&#xA;  description: Verify the enterprise contract is met&#xA;  params:&#xA;  - description: |&#xA;      Spec section of an ApplicationSnapshot resource. Not all fields of the&#xA;      resource are required. A minimal example:&#xA;&#xA;      ```json&#xA;        {&#xA;          &#34;components&#34;: [&#xA;            {&#xA;              &#34;containerImage&#34;: &#34;quay.io/example/repo:latest&#34;&#xA;            }&#xA;          ]&#xA;        }&#xA;      ```&#xA;&#xA;      Each `containerImage` in the `components` array is validated.&#xA;    name: IMAGES&#xA;    type: string&#xA;  - default: enterprise-contract-service/default&#xA;    description: |&#xA;      Name of the policy configuration (EnterpriseContractPolicy&#xA;      resource) to use. `namespace/name` or `name` syntax supported. If&#xA;      namespace is omitted the namespace where the task runs is used.&#xA;      You can also specify a policy configuration using a git url, e.g.&#xA;      `github.com/conforma/config//slsa3`.&#xA;    name: POLICY_CONFIGURATION&#xA;    type: string&#xA;  - default: &#34;&#34;&#xA;    description: Public key used to verify signatures. Must be a valid k8s cosign&#xA;      reference, e.g. k8s://my-space/my-secret where my-secret contains the expected&#xA;      cosign.pub attribute.&#xA;    name: PUBLIC_KEY&#xA;    type: string&#xA;  - default: &#34;&#34;&#xA;    description: Rekor host for transparency log lookups&#xA;    name: REKOR_HOST&#xA;    type: string&#xA;  - default: &#34;false&#34;&#xA;    description: Skip Rekor transparency log checks during validation.&#xA;    name: IGNORE_REKOR&#xA;    type: string&#xA;  - default: &#34;&#34;&#xA;    description: TUF mirror URL. Provide a value when NOT using public sigstore deployment.&#xA;    name: TUF_MIRROR&#xA;    type: string&#xA;  - default: &#34;&#34;&#xA;    description: |&#xA;      Path to a directory containing SSL certs to be used when communicating&#xA;      with external services. This is useful when using the integrated registry&#xA;      and a local instance of Rekor on a development cluster which may use&#xA;      certificates issued by a not-commonly trusted root CA. In such cases,&#xA;      `/var/run/secrets/kubernetes.io/serviceaccount` is a good value. Multiple&#xA;      paths can be provided by using the `:` separator.&#xA;    name: SSL_CERT_DIR&#xA;    type: string&#xA;  - default: trusted-ca&#xA;    description: The name of the ConfigMap to read CA bundle data from.&#xA;    name: CA_TRUST_CONFIGMAP_NAME&#xA;    type: string&#xA;  - default: ca-bundle.crt&#xA;    description: The name of the key in the ConfigMap that contains the CA bundle&#xA;      data.&#xA;    name: CA_TRUST_CONFIG_MAP_KEY&#xA;    type: string&#xA;  - default: &#34;true&#34;&#xA;    description: Include rule titles and descriptions in the output. Set to `&#34;false&#34;`&#xA;      to disable it.&#xA;    name: INFO&#xA;    type: string&#xA;  - default: &#34;true&#34;&#xA;    description: Fail the task if policy fails. Set to `&#34;false&#34;` to disable it.&#xA;    name: STRICT&#xA;    type: string&#xA;  - default: /tekton/home&#xA;    description: Value for the HOME environment variable.&#xA;    name: HOMEDIR&#xA;    type: string&#xA;  - default: now&#xA;    description: Run policy checks with the provided time.&#xA;    name: EFFECTIVE_TIME&#xA;    type: string&#xA;  - default: &#34;&#34;&#xA;    description: Merge additional Rego variables into the policy data. Use syntax&#xA;      &#34;key=value,key2=value2...&#34;&#xA;    name: EXTRA_RULE_DATA&#xA;    type: string&#xA;  - default: &#34;&#34;&#xA;    description: |&#xA;      This param is deprecated and will be removed in future. Its value is ignored. EC will be run without a timeout. (If you do want to apply a timeout use the Tekton task timeout.)&#xA;    name: TIMEOUT&#xA;    type: string&#xA;  - default: &#34;1&#34;&#xA;    description: Number of parallel workers to use for policy evaluation.&#xA;    name: WORKERS&#xA;    type: string&#xA;  - default: &#34;false&#34;&#xA;    description: Reduce the Snapshot to only the component whose build caused the&#xA;      Snapshot to be created&#xA;    name: SINGLE_COMPONENT&#xA;    type: string&#xA;  - default: unknown&#xA;    description: |&#xA;      Name, including kind, of the Kubernetes resource to query for labels when single component mode is enabled, e.g. pr/somepipeline.&#xA;    name: SINGLE_COMPONENT_CUSTOM_RESOURCE&#xA;    type: string&#xA;  - default: &#34;&#34;&#xA;    description: |&#xA;      Kubernetes namespace where the SINGLE_COMPONENT_NAME is found. Only used when single component mode is enabled.&#xA;    name: SINGLE_COMPONENT_CUSTOM_RESOURCE_NS&#xA;    type: string&#xA;  results:&#xA;  - description: Short summary of the policy evaluation for each image&#xA;    name: TEST_OUTPUT&#xA;    type: string&#xA;  stepTemplate:&#xA;    computeResources: {}&#xA;    env:&#xA;    - name: HOME&#xA;      value: /tekton/home&#xA;  steps:&#xA;  - args:&#xA;    - sigstore&#xA;    - initialize&#xA;    - --mirror&#xA;    - &#34;&#34;&#xA;    - --root&#xA;    - /root.json&#xA;    command:&#xA;    - ec&#xA;    computeResources:&#xA;      limits:&#xA;        memory: 256Mi&#xA;      requests:&#xA;        cpu: 100m&#xA;        memory: 256Mi&#xA;    image: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;    name: initialize-tuf&#xA;    when:&#xA;    - operator: notin&#xA;      values:&#xA;      - &#34;&#34;&#xA;  - command:&#xA;    - reduce-snapshot.sh&#xA;    computeResources:&#xA;      limits:&#xA;        memory: 256Mi&#xA;      requests:&#xA;        cpu: 100m&#xA;        memory: 256Mi&#xA;    env:&#xA;    - name: SNAPSHOT&#xA;      value: &#39;{&#34;application&#34;:&#34;&#34;,&#34;components&#34;:[{&#34;name&#34;:&#34;&#34;,&#34;containerImage&#34;:&#34;quay.io/redhat-appstudio-qe/test-images:buildah-demo-hfropftayf@sha256:f7879ac0d584ab8a184e5d7f8bf7bdc39e48560c80bb0f2163e21be1c5f9227c&#34;,&#34;source&#34;:{}}],&#34;artifacts&#34;:{}}&#39;&#xA;    - name: SINGLE_COMPONENT&#xA;      value: &#34;false&#34;&#xA;    - name: CUSTOM_RESOURCE&#xA;      value: unknown&#xA;    - name: CUSTOM_RESOURCE_NAMESPACE&#xA;    - name: SNAPSHOT_PATH&#xA;      value: /tekton/home/snapshot.json&#xA;    image: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;    name: reduce&#xA;    onError: continue&#xA;  - args:&#xA;    - validate&#xA;    - image&#xA;    - --images&#xA;    - /tekton/home/snapshot.json&#xA;    - --policy&#xA;    - ec-policy&#xA;    - --public-key&#xA;    - k8s://chains-e2e-mdkj/cosign-public-key&#xA;    - --rekor-url&#xA;    - &#34;&#34;&#xA;    - --ignore-rekor=true&#xA;    - --workers&#xA;    - &#34;1&#34;&#xA;    - --info=true&#xA;    - --timeout=100h&#xA;    - --strict=false&#xA;    - --show-successes&#xA;    - --effective-time=now&#xA;    - --extra-rule-data=&#xA;    - --output&#xA;    - text?show-successes=false&#xA;    - --output&#xA;    - appstudio=/tekton/results/TEST_OUTPUT&#xA;    - --output&#xA;    - json=/tekton/home/report-json.json&#xA;    command:&#xA;    - ec&#xA;    computeResources:&#xA;      limits:&#xA;        memory: 2Gi&#xA;      requests:&#xA;        cpu: 1800m&#xA;        memory: 2Gi&#xA;    env:&#xA;    - name: SSL_CERT_DIR&#xA;      value: /tekton-custom-certs:/etc/ssl/certs:/etc/pki/tls/certs:/system/etc/security/cacerts:/var/run/secrets/kubernetes.io/serviceaccount&#xA;    - name: EC_CACHE&#xA;      value: &#34;false&#34;&#xA;    image: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;    name: validate&#xA;    onError: continue&#xA;    volumeMounts:&#xA;    - mountPath: /etc/pki/tls/certs/ca-custom-bundle.crt&#xA;      name: trusted-ca&#xA;      readOnly: true&#xA;      subPath: ca-bundle.crt&#xA;  - args:&#xA;    - jq . /tekton/home/report-json.json | awk &#39;{gsub(/^ +/, &#34;&#34;); acc += length; if&#xA;      (acc &gt;= 8000) { printf &#34;\n&#34;; acc=length } printf $0 }&#39;&#xA;    command:&#xA;    - sh&#xA;    - -c&#xA;    computeResources:&#xA;      limits:&#xA;        memory: 256Mi&#xA;      requests:&#xA;        cpu: 100m&#xA;        memory: 256Mi&#xA;    image: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;    name: report-json&#xA;    onError: continue&#xA;  - args:&#xA;    - .&#xA;    - /tekton/results/TEST_OUTPUT&#xA;    command:&#xA;    - jq&#xA;    computeResources:&#xA;      limits:&#xA;        memory: 256Mi&#xA;      requests:&#xA;        cpu: 100m&#xA;        memory: 256Mi&#xA;    image: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;    name: summary&#xA;    onError: continue&#xA;  - args:&#xA;    - |&#xA;      ----- DEBUG OUTPUT -----&#xA;    command:&#xA;    - printf&#xA;    computeResources:&#xA;      limits:&#xA;        memory: 256Mi&#xA;      requests:&#xA;        cpu: 100m&#xA;        memory: 256Mi&#xA;    image: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;    name: info&#xA;  - args:&#xA;    - version&#xA;    command:&#xA;    - ec&#xA;    computeResources:&#xA;      limits:&#xA;        memory: 256Mi&#xA;      requests:&#xA;        cpu: 100m&#xA;        memory: 256Mi&#xA;    image: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;    name: version&#xA;  - args:&#xA;    - &#39;{policy: .policy, key: .key, &#34;effective-time&#34;: .[&#34;effective-time&#34;]}&#39;&#xA;    - /tekton/home/report-json.json&#xA;    command:&#xA;    - jq&#xA;    computeResources:&#xA;      limits:&#xA;        memory: 256Mi&#xA;      requests:&#xA;        cpu: 100m&#xA;        memory: 256Mi&#xA;    image: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;    name: show-config&#xA;  - args:&#xA;    - --argjson&#xA;    - strict&#xA;    - &#34;true&#34;&#xA;    - -e&#xA;    - |&#xA;      .result == &#34;SUCCESS&#34; or .result == &#34;WARNING&#34; or ($strict | not)&#xA;    - /tekton/results/TEST_OUTPUT&#xA;    command:&#xA;    - jq&#xA;    computeResources:&#xA;      limits:&#xA;        memory: 256Mi&#xA;      requests:&#xA;        cpu: 100m&#xA;        memory: 256Mi&#xA;    image: quay.io/conforma/cli@sha256:9275ec5f062399135ecb3f54f520ee5f20e818a846c34250e0d417dce9221459&#xA;    name: assert&#xA;  volumes:&#xA;  - configMap:&#xA;      items:&#xA;      - key: ca-bundle.crt&#xA;        path: ca-bundle.crt&#xA;      name: trusted-ca&#xA;      optional: true&#xA;    name: trusted-ca&#xA;  workspaces:&#xA;  - description: The workspace where the snapshot spec json file resides&#xA;    name: data&#xA;    optional: true&#xA;&#xA;*** Logs from pod &#39;verify-enterprise-contract-ff10333682fc0172b279ea64b944c06b-pod&#39;, container &#39;step-initialize-tuf&#39;:&#xA;----- START -----2026/04/20 19:19:03 INFO Step was skipped due to when expressions were evaluated to false.&#xA;----- END -----&#xA;*** Logs from pod &#39;verify-enterprise-contract-ff10333682fc0172b279ea64b944c06b-pod&#39;, container &#39;step-reduce&#39;:&#xA;----- START -----Single Component mode? false&#xA;{&#xA;  &#34;application&#34;: &#34;&#34;,&#xA;  &#34;components&#34;: [&#xA;    {&#xA;      &#34;name&#34;: &#34;&#34;,&#xA;      &#34;containerImage&#34;: &#34;quay.io/redhat-appstudio-qe/test-images:buildah-demo-hfropftayf@sha256:f7879ac0d584ab8a184e5d7f8bf7bdc39e48560c80bb0f2163e21be1c5f9227c&#34;,&#xA;      &#34;source&#34;: {}&#xA;    }&#xA;  ],&#xA;  &#34;artifacts&#34;: {}&#xA;}&#xA;----- END -----&#xA;*** Logs from pod &#39;verify-enterprise-contract-ff10333682fc0172b279ea64b944c06b-pod&#39;, container &#39;step-validate&#39;:&#xA;----- START -----Error: error validating image quay.io/redhat-appstudio-qe/test-images:buildah-demo-hfropftayf@sha256:f7879ac0d584ab8a184e5d7f8bf7bdc39e48560c80bb0f2163e21be1c5f9227c of component : load: loading policies: get compiler: 5 errors occurred:&#xA;/tmp/ec-work-620744388/policy/ecc96998b/policy/lib/sbom/sbom.rego:88: rego_type_error: undefined function ec.oci.image_referrers&#xA;/tmp/ec-work-620744388/policy/ecc96998b/policy/lib/sbom/sbom.rego:98: rego_type_error: undefined function ec.oci.image_tag_refs&#xA;/tmp/ec-work-620744388/policy/ecc96998b/policy/release/slsa_build_scripted_build/slsa_build_scripted_build.rego:23: rego_type_error: undefined function ec.oci.image_manifests&#xA;/tmp/ec-work-620744388/policy/ecc96998b/policy/release/tasks/tasks.rego:37: rego_type_error: undefined function ec.oci.image_manifests&#xA;/tmp/ec-work-620744388/policy/ecc96998b/policy/release/trusted_task/trusted_task.rego:23: rego_type_error: undefined function ec.oci.image_manifests&#xA;----- END -----&#xA;*** Logs from pod &#39;verify-enterprise-contract-ff10333682fc0172b279ea64b944c06b-pod&#39;, container &#39;step-report-json&#39;:&#xA;----- START -----jq: error: Could not open file /tekton/home/report-json.json: No such file or directory&#xA;----- END -----&#xA;*** Logs from pod &#39;verify-enterprise-contract-ff10333682fc0172b279ea64b944c06b-pod&#39;, container &#39;step-summary&#39;:&#xA;----- START -----jq: error: Could not open file /tekton/results/TEST_OUTPUT: No such file or directory&#xA;----- END -----&#xA;*** Logs from pod &#39;verify-enterprise-contract-ff10333682fc0172b279ea64b944c06b-pod&#39;, container &#39;step-info&#39;:&#xA;----- START ---------- DEBUG OUTPUT -----&#xA;----- END -----&#xA;*** Logs from pod &#39;verify-enterprise-contract-ff10333682fc0172b279ea64b944c06b-pod&#39;, container &#39;step-version&#39;:&#xA;----- START -----Version            v0.7.111&#xA;Source ID          cdfd9188f9352d7269ae1fe8c273a9e67f60ab8a&#xA;Change date        2025-07-09 12:58:49 +0000 UTC (40 weeks ago)&#xA;ECC                v0.1.112&#xA;OPA                v0.70.0&#xA;Conftest           v0.55.0&#xA;Cosign             v2.4.1&#xA;Sigstore           v1.8.9&#xA;Rekor              v1.3.6&#xA;Tekton Pipeline    v0.63.0&#xA;Kubernetes Client  v0.31.0&#xA;----- END -----&#xA;*** Logs from pod &#39;verify-enterprise-contract-ff10333682fc0172b279ea64b944c06b-pod&#39;, container &#39;step-show-config&#39;:&#xA;----- START -----jq: error: Could not open file /tekton/home/report-json.json: No such file or directory&#xA;----- END -----&#xA;*** Logs from pod &#39;verify-enterprise-contract-ff10333682fc0172b279ea64b944c06b-pod&#39;, container &#39;step-assert&#39;:&#xA;----- START -----2026/04/20 19:19:09 Skipping step because a previous step failed&#xA;----- END -----&#xA;Make sure TaskRun verify-enterprise-contract of PipelineRun verify-enterprise-contract-run-w2tln succeeded&#xA;[FAILED] Expected&#xA;    &lt;bool&gt;: false&#xA;to be true&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:190 @ 04/20/26 19:19:10.973&#xA;&lt; Exit [It] succeeds when policy is met - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:177 @ 04/20/26 19:19:10.973 (43.233s)&#xA;&gt; Enter [AfterEach] [enterprise-contract-suite Conforma E2E tests] - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:29 @ 04/20/26 19:19:10.974&#xA;&lt; Exit [AfterEach] [enterprise-contract-suite Conforma E2E tests] - /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:29 @ 04/20/26 19:19:11.173 (200ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task does not pass when tests are not satisfied on non-strict mode [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:197 @ 04/20/26 19:19:11.174&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task fails when tests are not satisfied on strict mode [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:225 @ 04/20/26 19:19:11.174&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task fails when unexpected signature is used [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:251 @ 04/20/26 19:19:11.174&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task ec-cli command verifies ec cli has error handling [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:279 @ 04/20/26 19:19:11.175&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task ec-cli command verifies ec validate accepts a list of image references [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:301 @ 04/20/26 19:19:11.175&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task Release Policy verifies redhat products pass the redhat policy rule collection before release  [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:345 @ 04/20/26 19:19:11.175&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task Release Policy verifies the release policy: Task are trusted [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:382 @ 04/20/26 19:19:11.175&#xA;</system-err>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task Release Policy verifies the release policy: Task references are pinned [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/enterprise-contract/contract.go:422 @ 04/20/26 19:19:11.176&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-advisories pipeline] Rh-advisories happy path Post-release verification verifies if release CR is created [release-pipelines, rh-advisories, rhAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-advisories pipeline] Rh-advisories happy path Post-release verification verifies the advs release pipelinerun is running and succeeds [release-pipelines, rh-advisories, rhAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-advisories pipeline] Rh-advisories happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, rh-advisories, rhAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-advisories pipeline] Rh-advisories happy path Post-release verification verifies if the repository URL is valid [release-pipelines, rh-advisories, rhAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rhtap-service-push pipeline] Rhtap-service-push happy path Post-release verification verifies if the release CR is created [release-pipelines, rhtap-service-push, RhtapServicePush]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rhtap-service-push pipeline] Rhtap-service-push happy path Post-release verification verifies the rhtap release pipelinerun is running and succeeds [release-pipelines, rhtap-service-push, RhtapServicePush]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rhtap-service-push pipeline] Rhtap-service-push happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, rhtap-service-push, RhtapServicePush]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rhtap-service-push pipeline] Rhtap-service-push happy path Post-release verification verifies if the PR in infra-deployments repo is created/updated [release-pipelines, rhtap-service-push, RhtapServicePush]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params when context points to a file [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params creates Tekton bundles from specific context [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params when context is the root directory [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params creates Tekton bundles when context points to a file and a directory [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params creates Tekton bundles when using negation [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params allows overriding HOME environment variable [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params allows overriding STEP image [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite [HACBS-1571]test-release-e2e-push-image-to-pyxis] Post-release verification tests that Release CR is created for the Snapshot [release-pipelines, rh-push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite [HACBS-1571]test-release-e2e-push-image-to-pyxis] Post-release verification verifies a release PipelineRun is started and succeeded in managed namespace [release-pipelines, rh-push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite [HACBS-1571]test-release-e2e-push-image-to-pyxis] Post-release verification validate the result of task create-pyxis-image contains image ids [release-pipelines, rh-push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite [HACBS-1571]test-release-e2e-push-image-to-pyxis] Post-release verification tests that Release CR has completed [release-pipelines, rh-push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite [HACBS-1571]test-release-e2e-push-image-to-pyxis] Post-release verification validates that imageIds from task create-pyxis-image exist in Pyxis. [release-pipelines, rh-push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when a new Component with specified custom branch is created triggers a Build PipelineRun [integration-service, gitlab-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="failed" time="23.51903268">
              <failure message="Unexpected error:&#xA;    &lt;*errors.StatusError | 0xc0027df720&gt;: &#xA;    admission webhook &#34;dintegrationtestscenario.kb.io&#34; denied the request: could not find application &#39;integ-app-pluz&#39; in namespace &#39;gitlab-rep-hayq&#39;&#xA;    {&#xA;        ErrStatus: {&#xA;            TypeMeta: {Kind: &#34;&#34;, APIVersion: &#34;&#34;},&#xA;            ListMeta: {&#xA;                SelfLink: &#34;&#34;,&#xA;                ResourceVersion: &#34;&#34;,&#xA;                Continue: &#34;&#34;,&#xA;                RemainingItemCount: nil,&#xA;            },&#xA;            Status: &#34;Failure&#34;,&#xA;            Message: &#34;admission webhook \&#34;dintegrationtestscenario.kb.io\&#34; denied the request: could not find application &#39;integ-app-pluz&#39; in namespace &#39;gitlab-rep-hayq&#39;&#34;,&#xA;            Reason: &#34;Forbidden&#34;,&#xA;            Details: nil,&#xA;            Code: 403,&#xA;        },&#xA;    }&#xA;occurred" type="failed">[FAILED] Unexpected error:&#xA;    &lt;*errors.StatusError | 0xc0027df720&gt;: &#xA;    admission webhook &#34;dintegrationtestscenario.kb.io&#34; denied the request: could not find application &#39;integ-app-pluz&#39; in namespace &#39;gitlab-rep-hayq&#39;&#xA;    {&#xA;        ErrStatus: {&#xA;            TypeMeta: {Kind: &#34;&#34;, APIVersion: &#34;&#34;},&#xA;            ListMeta: {&#xA;                SelfLink: &#34;&#34;,&#xA;                ResourceVersion: &#34;&#34;,&#xA;                Continue: &#34;&#34;,&#xA;                RemainingItemCount: nil,&#xA;            },&#xA;            Status: &#34;Failure&#34;,&#xA;            Message: &#34;admission webhook \&#34;dintegrationtestscenario.kb.io\&#34; denied the request: could not find application &#39;integ-app-pluz&#39; in namespace &#39;gitlab-rep-hayq&#39;&#34;,&#xA;            Reason: &#34;Forbidden&#34;,&#xA;            Details: nil,&#xA;            Code: 403,&#xA;        },&#xA;    }&#xA;occurred&#xA;In [BeforeAll] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:68 @ 04/20/26 19:14:23.365&#xA;&#xA;There were additional failures detected after the initial failure. These are visible in the timeline&#xA;</failure>
              <system-err>&gt; Enter [BeforeAll] Gitlab with status reporting of Integration tests in the assosiated merge request - /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:45 @ 04/20/26 19:14:00.563&#xA;[FAILED] Unexpected error:&#xA;    &lt;*errors.StatusError | 0xc0027df720&gt;: &#xA;    admission webhook &#34;dintegrationtestscenario.kb.io&#34; denied the request: could not find application &#39;integ-app-pluz&#39; in namespace &#39;gitlab-rep-hayq&#39;&#xA;    {&#xA;        ErrStatus: {&#xA;            TypeMeta: {Kind: &#34;&#34;, APIVersion: &#34;&#34;},&#xA;            ListMeta: {&#xA;                SelfLink: &#34;&#34;,&#xA;                ResourceVersion: &#34;&#34;,&#xA;                Continue: &#34;&#34;,&#xA;                RemainingItemCount: nil,&#xA;            },&#xA;            Status: &#34;Failure&#34;,&#xA;            Message: &#34;admission webhook \&#34;dintegrationtestscenario.kb.io\&#34; denied the request: could not find application &#39;integ-app-pluz&#39; in namespace &#39;gitlab-rep-hayq&#39;&#34;,&#xA;            Reason: &#34;Forbidden&#34;,&#xA;            Details: nil,&#xA;            Code: 403,&#xA;        },&#xA;    }&#xA;occurred&#xA;In [BeforeAll] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:68 @ 04/20/26 19:14:23.365&#xA;&lt; Exit [BeforeAll] Gitlab with status reporting of Integration tests in the assosiated merge request - /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:45 @ 04/20/26 19:14:23.365 (22.802s)&#xA;&gt; Enter [AfterAll] Gitlab with status reporting of Integration tests in the assosiated merge request - /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:94 @ 04/20/26 19:14:23.366&#xA;[FAILED] Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc001e3cc30&gt;: &#xA;    failed to get MR of IID 0 in projectID , 404 Not Found&#xA;    {&#xA;        s: &#34;failed to get MR of IID 0 in projectID , 404 Not Found&#34;,&#xA;    }&#xA;In [AfterAll] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:97 @ 04/20/26 19:14:23.622&#xA;&lt; Exit [AfterAll] Gitlab with status reporting of Integration tests in the assosiated merge request - /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:94 @ 04/20/26 19:14:23.622 (257ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/20/26 19:14:23.623&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/20/26 19:14:24.082 (460ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when a new Component with specified custom branch is created does not contain an annotation with a Snapshot Name [integration-service, gitlab-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:144 @ 04/20/26 19:14:24.083&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when a new Component with specified custom branch is created should lead to build PipelineRun finishing successfully [integration-service, gitlab-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:148 @ 04/20/26 19:14:24.083&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when a new Component with specified custom branch is created should have a related PaC init MR is created [integration-service, gitlab-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:153 @ 04/20/26 19:14:24.083&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when a new Component with specified custom branch is created the PipelineRun should eventually finish successfully for component  [integration-service, gitlab-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:172 @ 04/20/26 19:14:24.084&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when the PaC build pipelineRun run succeeded checks if the BuildPipelineRun have the annotation of chains signed [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:179 @ 04/20/26 19:14:24.084&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when the PaC build pipelineRun run succeeded checks if the Snapshot is created [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:183 @ 04/20/26 19:14:24.084&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when the PaC build pipelineRun run succeeded checks if the Build PipelineRun got annotated with Snapshot name [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:188 @ 04/20/26 19:14:24.084&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when the Snapshot was created should find the Integration Test Scenario PipelineRun [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:194 @ 04/20/26 19:14:24.084&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created should eventually complete successfully [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:207 @ 04/20/26 19:14:24.085&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it pass [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:212 @ 04/20/26 19:14:24.085&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:229 @ 04/20/26 19:14:24.085&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it fails [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:233 @ 04/20/26 19:14:24.085&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created eventually leads to the integration test PipelineRun&#39;s Fail status reported at MR commit status [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:250 @ 04/20/26 19:14:24.086&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created validates at least one MR note contains the final integration test result [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:254 @ 04/20/26 19:14:24.086&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created merging the PR should be successful [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:278 @ 04/20/26 19:14:24.086&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created leads to triggering on push PipelineRun [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:288 @ 04/20/26 19:14:24.086&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Run integration tests after Merged MR should eventually complete successfully [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:303 @ 04/20/26 19:14:24.086&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Run integration tests after Merged MR validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it pass [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:308 @ 04/20/26 19:14:24.087&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Run integration tests after Merged MR eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:325 @ 04/20/26 19:14:24.087&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Run integration tests after Merged MR validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it fails [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:329 @ 04/20/26 19:14:24.087&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Run integration tests after Merged MR eventually leads to the integration test PipelineRun&#39;s Fail status reported at MR commit status [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/gitlab-integration-reporting.go:346 @ 04/20/26 19:14:24.087&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created creates first component [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="passed" time="52.894426603">
              <system-err>&gt; Enter [BeforeAll] test build secret lookup - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:32 @ 04/20/26 19:14:24.088&#xA;&lt; Exit [BeforeAll] test build secret lookup - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:32 @ 04/20/26 19:14:56.893 (32.805s)&#xA;&gt; Enter [BeforeAll] when two secrets are created - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:100 @ 04/20/26 19:14:56.893&#xA;&lt; Exit [BeforeAll] when two secrets are created - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:100 @ 04/20/26 19:14:56.922 (29ms)&#xA;&gt; Enter [It] creates first component - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:123 @ 04/20/26 19:14:56.923&#xA;Image repository for component component-one-qsok in namespace build-e2e-ukgr do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [It] creates first component - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:123 @ 04/20/26 19:15:16.982 (20.059s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:25 @ 04/20/26 19:15:16.982&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:25 @ 04/20/26 19:15:16.982 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created creates second component [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="passed" time="20.075127879">
              <system-err>&gt; Enter [It] creates second component - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:140 @ 04/20/26 19:15:16.983&#xA;Image repository for component component-two-dagh in namespace build-e2e-ukgr do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [It] creates second component - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:140 @ 04/20/26 19:15:37.057 (20.075s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:25 @ 04/20/26 19:15:37.057&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:25 @ 04/20/26 19:15:37.057 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created check first component annotation has errors [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="passed" time="45.181052843">
              <system-err>&gt; Enter [It] check first component annotation has errors - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:158 @ 04/20/26 19:15:37.058&#xA;build status annotation value: {&#34;message&#34;:&#34;waiting for spec.containerImage to be set by ImageRepository with annotation image-controller.appstudio.redhat.com/update-component-image&#34;}&#xA;build status annotation value: {&#34;message&#34;:&#34;waiting for spec.containerImage to be set by ImageRepository with annotation image-controller.appstudio.redhat.com/update-component-image&#34;}&#xA;build status annotation value: {&#34;message&#34;:&#34;waiting for spec.containerImage to be set by ImageRepository with annotation image-controller.appstudio.redhat.com/update-component-image&#34;}&#xA;build status annotation value: {&#34;message&#34;:&#34;waiting for spec.containerImage to be set by ImageRepository with annotation image-controller.appstudio.redhat.com/update-component-image&#34;}&#xA;build status annotation value: {&#34;message&#34;:&#34;waiting for spec.containerImage to be set by ImageRepository with annotation image-controller.appstudio.redhat.com/update-component-image&#34;}&#xA;build status annotation value: {&#34;message&#34;:&#34;waiting for spec.containerImage to be set by ImageRepository with annotation image-controller.appstudio.redhat.com/update-component-image&#34;}&#xA;build status annotation value: {&#34;message&#34;:&#34;waiting for spec.containerImage to be set by ImageRepository with annotation image-controller.appstudio.redhat.com/update-component-image&#34;}&#xA;build status annotation value: {&#34;message&#34;:&#34;waiting for spec.containerImage to be set by ImageRepository with annotation image-controller.appstudio.redhat.com/update-component-image&#34;}&#xA;build status annotation value: {&#34;message&#34;:&#34;waiting for spec.containerImage to be set by ImageRepository with annotation image-controller.appstudio.redhat.com/update-component-image&#34;}&#xA;build status annotation value: {&#34;pac&#34;:{&#34;state&#34;:&#34;error&#34;,&#34;error-id&#34;:74,&#34;error-message&#34;:&#34;74: Access token is unrecognizable by GitHub&#34;},&#34;message&#34;:&#34;done&#34;}&#xA;&lt; Exit [It] check first component annotation has errors - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:158 @ 04/20/26 19:16:22.239 (45.181s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:25 @ 04/20/26 19:16:22.239&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:25 @ 04/20/26 19:16:22.239 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created triggered PipelineRun is for component  [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="passed" time="60.092072945">
              <system-err>&gt; Enter [It] triggered PipelineRun is for component  - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:178 @ 04/20/26 19:16:22.239&#xA;PipelineRun has not been created yet for the component build-e2e-ukgr/component-two-dagh&#xA;PipelineRun has not been created yet for the component build-e2e-ukgr/component-two-dagh&#xA;PipelineRun has not been created yet for the component build-e2e-ukgr/component-two-dagh&#xA;&lt; Exit [It] triggered PipelineRun is for component  - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:178 @ 04/20/26 19:17:22.331 (1m0.092s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:25 @ 04/20/26 19:17:22.331&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:25 @ 04/20/26 19:17:22.331 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created check only one pipelinerun should be triggered [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="passed" time="123.368996426">
              <system-err>&gt; Enter [It] check only one pipelinerun should be triggered - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:193 @ 04/20/26 19:17:22.332&#xA;&lt; Exit [It] check only one pipelinerun should be triggered - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:193 @ 04/20/26 19:19:22.333 (2m0.001s)&#xA;&gt; Enter [AfterAll] test build secret lookup - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:61 @ 04/20/26 19:19:22.333&#xA;&lt; Exit [AfterAll] test build secret lookup - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:61 @ 04/20/26 19:19:25.7 (3.367s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:25 @ 04/20/26 19:19:25.701&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/secret_lookup.go:25 @ 04/20/26 19:19:25.701 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created when second component is deleted, pac pr branch should not exist in the repo [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build creates an application [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="passed" time="47.649499905">
              <system-err>&gt; Enter [BeforeAll] Maven project - Default build - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:84 @ 04/20/26 19:14:00.26&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo BeforeAll: initializing framework for appappMaven project - Default build&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo BeforeAll: namespacesuserNamespacekonflux-mdypmanagedNamespacekonflux-mdyp-managed&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo BeforeAll: component configcomponentNamekonflux-demo-component-cetnpacBranchNamekonflux-konflux-demo-component-cetncomponentRepositoryNamehacbs-test-project-konflux-demo&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo BeforeAll: creating release configmanagedNamespacekonflux-mdyp-manageduserNamespacekonflux-mdyp&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo createReleaseConfig: creating managed namespacemanagedNamespacekonflux-mdyp-managed&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo createReleaseConfig: creating release-service-accountmanagedNamespacekonflux-mdyp-managed&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo createReleaseConfig: finishedmanagedNamespacekonflux-mdyp-manageduserNamespacekonflux-mdyp&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo BeforeAll: created and linked release-catalog-trusted-artifacts-quay-secretmanagedNamespacekonflux-mdyp-managed&#34;&#xA;created and linked release-catalog-trusted-artifacts-quay-secret in namespace &#34;konflux-mdyp-managed&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo BeforeAll: setup completeappMaven project - Default buildcomponentNamekonflux-demo-component-cetn&#34;&#xA;&lt; Exit [BeforeAll] Maven project - Default build - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:84 @ 04/20/26 19:14:47.884 (47.624s)&#xA;&gt; Enter [It] creates an application - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:189 @ 04/20/26 19:14:47.884&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo: creating applicationapplicationNamekonflux-demo-appnamespacekonflux-mdyp&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo: application createdapplicationNamekonflux-demo-app&#34;&#xA;&lt; Exit [It] creates an application - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:189 @ 04/20/26 19:14:47.908 (24ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build creates an IntegrationTestScenario for the app [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="passed" time="0.020795937">
              <system-err>&gt; Enter [It] creates an IntegrationTestScenario for the app - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:202 @ 04/20/26 19:14:47.909&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo: creating IntegrationTestScenarioapplicationNamekonflux-demo-appnamespacekonflux-mdyp&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo: IntegrationTestScenario createdscenariomy-integration-test-bvtu&#34;&#xA;&lt; Exit [It] creates an IntegrationTestScenario for the app - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:202 @ 04/20/26 19:14:47.929 (21ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build creates new branch for the build [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="passed" time="0.695677271">
              <system-err>&gt; Enter [It] creates new branch for the build - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:218 @ 04/20/26 19:14:47.93&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo: creating branch for buildrepohacbs-test-project-konflux-demobranchbase-impsrsfrommain&#34;&#xA;&lt; Exit [It] creates new branch for the build - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:218 @ 04/20/26 19:14:48.625 (696ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build creates component konflux-demo-component (private: false) from git source https://github.com/redhat-appstudio-qe/hacbs-test-project-konflux-demo [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="passed" time="20.045578847">
              <system-err>&gt; Enter [It] creates component konflux-demo-component (private: false) from git source https://github.com/redhat-appstudio-qe/hacbs-test-project-konflux-demo - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:233 @ 04/20/26 19:14:48.626&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo: creating componentcomponentNamekonflux-demo-component-cetnapplicationNamekonflux-demo-appnamespacekonflux-mdyprevisionbase-impsrs&#34;&#xA;Image repository for component konflux-demo-component-cetn in namespace konflux-mdyp do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo: component createdcomponentNamekonflux-demo-component-cetn&#34;&#xA;&lt; Exit [It] creates component konflux-demo-component (private: false) from git source https://github.com/redhat-appstudio-qe/hacbs-test-project-konflux-demo - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:233 @ 04/20/26 19:15:08.671 (20.045s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Component is created triggers creation of a PR in the sample repo [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="failed" time="355.075546986">
              <failure message="Timed out after 300.001s.&#xA;timed out when waiting for `pull-request` event type PaC PipelineRun to be present in the user namespace &#34;konflux-mdyp&#34; for component &#34;konflux-demo-component-cetn&#34; with a label pointing to &#34;konflux-demo-app&#34;&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc001b98a60&gt;: &#xA;    no pipelinerun found for component konflux-demo-component-cetn&#xA;    {&#xA;        s: &#34;no pipelinerun found for component konflux-demo-component-cetn&#34;,&#xA;    }" type="failed">[FAILED] Timed out after 300.001s.&#xA;timed out when waiting for `pull-request` event type PaC PipelineRun to be present in the user namespace &#34;konflux-mdyp&#34; for component &#34;konflux-demo-component-cetn&#34; with a label pointing to &#34;konflux-demo-app&#34;&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc001b98a60&gt;: &#xA;    no pipelinerun found for component konflux-demo-component-cetn&#xA;    {&#xA;        s: &#34;no pipelinerun found for component konflux-demo-component-cetn&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:294 @ 04/20/26 19:21:03.747&#xA;</failure>
              <system-err>&gt; Enter [It] triggers creation of a PR in the sample repo - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:259 @ 04/20/26 19:15:08.672&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo: waiting for PaC PRrepohacbs-test-project-konflux-demopacBranchNamekonflux-konflux-demo-component-cetn&#34;&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;msg&#34;=&#34;Konflux demo: could not get the expected PaC branch name konflux-konflux-demo-component-cetn (found 14 PRs)&#34; &#34;error&#34;=null&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo: PaC PR createdprNumber29098prSHAa53086642bd14d49e0aef569838a1c1525e9a348&#34;&#xA;&#34;level&#34;=0 &#34;msg&#34;=&#34;Konflux demo: waiting for pull-request PipelineRun to appear (will delete it)componentkonflux-demo-component-cetnprSHAa53086642bd14d49e0aef569838a1c1525e9a348&#34;&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;PipelineRun not found yet for component konflux-mdyp/konflux-demo-component-cetn prSHA a53086642bd14d49e0aef569838a1c1525e9a348: no pipelinerun found for component konflux-demo-component-cetn&#xA;[FAILED] Timed out after 300.001s.&#xA;timed out when waiting for `pull-request` event type PaC PipelineRun to be present in the user namespace &#34;konflux-mdyp&#34; for component &#34;konflux-demo-component-cetn&#34; with a label pointing to &#34;konflux-demo-app&#34;&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc001b98a60&gt;: &#xA;    no pipelinerun found for component konflux-demo-component-cetn&#xA;    {&#xA;        s: &#34;no pipelinerun found for component konflux-demo-component-cetn&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:294 @ 04/20/26 19:21:03.747&#xA;&lt; Exit [It] triggers creation of a PR in the sample repo - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:259 @ 04/20/26 19:21:03.747 (5m55.075s)&#xA;&gt; Enter [AfterAll] Maven project - Default build - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:154 @ 04/20/26 19:21:03.747&#xA;&lt; Exit [AfterAll] Maven project - Default build - /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:154 @ 04/20/26 19:21:03.748 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Component is created verifies component build status [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:297 @ 04/20/26 19:21:03.748&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Component is created should eventually lead to triggering a &#39;push&#39; event type PipelineRun after merging the PaC init branch  [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:335 @ 04/20/26 19:21:03.748&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun is created does not contain an annotation with a Snapshot Name [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:369 @ 04/20/26 19:21:03.749&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun is created should eventually complete successfully [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:373 @ 04/20/26 19:21:03.749&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun completes successfully should validate Tekton TaskRun test results successfully [konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:389 @ 04/20/26 19:21:03.749&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun completes successfully should validate that the build pipelineRun is signed [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:403 @ 04/20/26 19:21:03.749&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun completes successfully should find the related Snapshot CR [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:419 @ 04/20/26 19:21:03.749&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun completes successfully should validate that the build pipelineRun is annotated with the name of the Snapshot [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:432 @ 04/20/26 19:21:03.75&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun completes successfully should find the related Integration Test PipelineRun [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:441 @ 04/20/26 19:21:03.75&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when push pipelinerun is retriggered should eventually succeed [konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:462 @ 04/20/26 19:21:03.75&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Integration Test PipelineRun is created should eventually complete successfully [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:493 @ 04/20/26 19:21:03.75&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Integration Test PipelineRun completes successfully should lead to Snapshot CR being marked as passed [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:505 @ 04/20/26 19:21:03.75&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Integration Test PipelineRun completes successfully should trigger creation of Release CR [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:518 @ 04/20/26 19:21:03.751&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Release CR is created triggers creation of Release PipelineRun [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:533 @ 04/20/26 19:21:03.751&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Release PipelineRun is triggered should eventually succeed [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:552 @ 04/20/26 19:21:03.751&#xA;</system-err>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Release PipelineRun is completed should lead to Release CR being marked as succeeded [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/konflux-demo/konflux-demo.go:578 @ 04/20/26 19:21:03.751&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component A creates the Component A successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="28.684908597">
              <system-err>&gt; Enter [BeforeAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:60 @ 04/20/26 19:14:00.661&#xA;Successfully acquired repository lock for namespace group-rtpt&#xA;&lt; Exit [BeforeAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:60 @ 04/20/26 19:14:19.305 (18.645s)&#xA;&gt; Enter [It] creates the Component A successfully - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:205 @ 04/20/26 19:14:19.306&#xA;&lt; Exit [It] creates the Component A successfully - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:205 @ 04/20/26 19:14:29.345 (10.039s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:50 @ 04/20/26 19:14:29.345&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:50 @ 04/20/26 19:14:29.345 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component A triggers a Build PipelineRun for componentA go-component [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="failed" time="901.744641521">
              <failure message="Timed out after 900.001s.&#xA;timed out when waiting for the build PipelineRun to start for the componentA group-rtpt/go-component-ceunjn&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00174c530&gt;: &#xA;    no pipelinerun found for component go-component-ceunjn&#xA;    {&#xA;        s: &#34;no pipelinerun found for component go-component-ceunjn&#34;,&#xA;    }" type="failed">[FAILED] Timed out after 900.001s.&#xA;timed out when waiting for the build PipelineRun to start for the componentA group-rtpt/go-component-ceunjn&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00174c530&gt;: &#xA;    no pipelinerun found for component go-component-ceunjn&#xA;    {&#xA;        s: &#34;no pipelinerun found for component go-component-ceunjn&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:224 @ 04/20/26 19:29:29.347&#xA;</failure>
              <system-err>&gt; Enter [It] triggers a Build PipelineRun for componentA go-component - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:213 @ 04/20/26 19:14:29.346&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;Build PipelineRun has not been created yet for the componentA group-rtpt/go-component-ceunjn&#xA;[FAILED] Timed out after 900.001s.&#xA;timed out when waiting for the build PipelineRun to start for the componentA group-rtpt/go-component-ceunjn&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00174c530&gt;: &#xA;    no pipelinerun found for component go-component-ceunjn&#xA;    {&#xA;        s: &#34;no pipelinerun found for component go-component-ceunjn&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:224 @ 04/20/26 19:29:29.347&#xA;&lt; Exit [It] triggers a Build PipelineRun for componentA go-component - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:213 @ 04/20/26 19:29:29.347 (15m0.001s)&#xA;&gt; Enter [AfterAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:149 @ 04/20/26 19:29:29.348&#xA;&lt; Exit [AfterAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:149 @ 04/20/26 19:29:30.884 (1.537s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:50 @ 04/20/26 19:29:30.885&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:50 @ 04/20/26 19:29:31.091 (206ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component A does not contain an annotation with a Snapshot Name [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:227 @ 04/20/26 19:29:31.091&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component A should lead to build PipelineRunA finishing successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:231 @ 04/20/26 19:29:31.091&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component A should lead to a PaC PR creation for componentA go-component [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:236 @ 04/20/26 19:29:31.092&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLRA is finished successfully checks if the Snapshot is created [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:258 @ 04/20/26 19:29:31.092&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLRA is finished successfully should find the related Integration PipelineRuns [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:263 @ 04/20/26 19:29:31.092&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLRA is finished successfully integration pipeline should end up with success [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:270 @ 04/20/26 19:29:31.092&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Snapshot testing is completed successfully should merge the init PaC PR successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:277 @ 04/20/26 19:29:31.093&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component B creates the Component B successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:296 @ 04/20/26 19:29:31.093&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component B triggers a Build PipelineRun for component python-component [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:304 @ 04/20/26 19:29:31.093&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component B does not contain an annotation with a Snapshot Name [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:318 @ 04/20/26 19:29:31.093&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component B should lead to build PipelineRun finishing successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:322 @ 04/20/26 19:29:31.094&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component B should lead to a PaC PR creation for component python-component [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:327 @ 04/20/26 19:29:31.094&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully checks if the Snapshot is created [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:349 @ 04/20/26 19:29:31.094&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully should find the related Integration PipelineRuns [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:354 @ 04/20/26 19:29:31.094&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully integration pipeline should end up with success [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:361 @ 04/20/26 19:29:31.094&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Snapshot testing is completed successfully should merge the init PaC PR successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:368 @ 04/20/26 19:29:31.095&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component C creates the Component C successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:387 @ 04/20/26 19:29:31.095&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component C triggers a Build PipelineRun for componentC konflux-test-integration-clone [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:395 @ 04/20/26 19:29:31.095&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component C does not contain an annotation with a Snapshot Name [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:409 @ 04/20/26 19:29:31.095&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component C should lead to build PipelineRun finishing successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:413 @ 04/20/26 19:29:31.095&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component C should lead to a PaC PR creation for componentC konflux-test-integration-clone [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:418 @ 04/20/26 19:29:31.096&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully checks if the Snapshot is created [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:440 @ 04/20/26 19:29:31.096&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully should find the related Integration PipelineRuns [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:445 @ 04/20/26 19:29:31.096&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully integration pipeline should end up with success [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:452 @ 04/20/26 19:29:31.096&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Snapshot testing is completed successfully should merge the init PaC PR successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:459 @ 04/20/26 19:29:31.096&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged should make change to the root folder [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:479 @ 04/20/26 19:29:31.097&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged should make change to the multiple-repo [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:497 @ 04/20/26 19:29:31.097&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged wait for the last components build to finish [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:513 @ 04/20/26 19:29:31.097&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged wait for all component snapshots to be created with proper PR group annotations [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:521 @ 04/20/26 19:29:31.097&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged get all group snapshots and check if pr-group annotation contains all components [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:556 @ 04/20/26 19:29:31.098&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged make sure that group snapshot contains last build pipelinerun for each component [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:635 @ 04/20/26 19:29:31.098&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when Older snapshot and integration pipelinerun should be cancelled once new snapshot is created make change to the multiple-repo to trigger a new cycle of testing [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:648 @ 04/20/26 19:29:31.098&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when Older snapshot and integration pipelinerun should be cancelled once new snapshot is created wait for the components A and B build to finish [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:654 @ 04/20/26 19:29:31.098&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when Older snapshot and integration pipelinerun should be cancelled once new snapshot is created get all component snapshots for component A and check if older snapshot has been cancelled [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:663 @ 04/20/26 19:29:31.098&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when Older snapshot and integration pipelinerun should be cancelled once new snapshot is created get all group snapshots and check if older group snapshot is cancelled [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:690 @ 04/20/26 19:29:31.099&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when ResolutionRequest is deleted after pipeline completes verifies that ResolutionRequest is deleted after pipeline resolution [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:720 @ 04/20/26 19:29:31.099&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when ResolutionRequest is deleted after pipeline completes verifies that no orphaned ResolutionRequests remain in namespace after test completion [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:740 @ 04/20/26 19:29:31.099&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when IntegrationTestScenario reference to task as pipelinerun resolution trigger pipelinerun for invalid integrationTestScenario by annotating snapshot and verify failing to create integration pipelinerun [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/group-snapshots-tests.go:780 @ 04/20/26 19:29:31.099&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when a new Component with specified custom branch is created does not contain an annotation with a Snapshot Name [integration-service, github-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="failed" time="953.437701183">
              <failure message="Timed out after 900.001s.&#xA;timed out when waiting for the build PipelineRun to start for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00170c910&gt;: &#xA;    no pipelinerun found for component test-component-pac-tupjqc&#xA;    {&#xA;        s: &#34;no pipelinerun found for component test-component-pac-tupjqc&#34;,&#xA;    }" type="failed">[FAILED] Timed out after 900.001s.&#xA;timed out when waiting for the build PipelineRun to start for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00170c910&gt;: &#xA;    no pipelinerun found for component test-component-pac-tupjqc&#xA;    {&#xA;        s: &#34;no pipelinerun found for component test-component-pac-tupjqc&#34;,&#xA;    }&#xA;In [BeforeAll] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:86 @ 04/20/26 19:29:53.03&#xA;</failure>
              <system-err>&gt; Enter [BeforeAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:45 @ 04/20/26 19:14:00.559&#xA;Image repository for component test-component-pac-tupjqc in namespace stat-rep-qmrx do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Image repository for component test-component-pac-tupjqc in namespace stat-rep-qmrx do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Build PipelineRun has not been created yet for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;[FAILED] Timed out after 900.001s.&#xA;timed out when waiting for the build PipelineRun to start for the component stat-rep-qmrx/test-component-pac-tupjqc&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00170c910&gt;: &#xA;    no pipelinerun found for component test-component-pac-tupjqc&#xA;    {&#xA;        s: &#34;no pipelinerun found for component test-component-pac-tupjqc&#34;,&#xA;    }&#xA;In [BeforeAll] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:86 @ 04/20/26 19:29:53.03&#xA;&lt; Exit [BeforeAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:45 @ 04/20/26 19:29:53.03 (15m52.471s)&#xA;&gt; Enter [AfterAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:92 @ 04/20/26 19:29:53.03&#xA;&lt; Exit [AfterAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:92 @ 04/20/26 19:29:53.794 (764ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Status Reporting of Integration tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:42 @ 04/20/26 19:29:53.794&#xA;&lt; Exit [AfterEach] [integration-service-suite Status Reporting of Integration tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:42 @ 04/20/26 19:29:53.996 (202ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when a new Component with specified custom branch is created should have a related PaC init PR created [integration-service, github-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:113 @ 04/20/26 19:29:53.997&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when a new Component with specified custom branch is created initialized integration test status is reported to github [integration-service, github-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:132 @ 04/20/26 19:29:53.998&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when a new Component with specified custom branch is created should lead to build PipelineRun finishing successfully [integration-service, github-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:142 @ 04/20/26 19:29:53.998&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when the PaC build pipelineRun run succeeded checks if the BuildPipelineRun have the annotation of chains signed [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:149 @ 04/20/26 19:29:53.998&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when the PaC build pipelineRun run succeeded checks if the Snapshot is created [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:153 @ 04/20/26 19:29:53.998&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when the PaC build pipelineRun run succeeded checks if the Build PipelineRun got annotated with Snapshot name [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:158 @ 04/20/26 19:29:53.999&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when the Snapshot was created should find both the related Integration PipelineRuns [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:164 @ 04/20/26 19:29:53.999&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns are created should eventually complete successfully [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:183 @ 04/20/26 19:29:53.999&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully should lead to Snapshot CR being marked as failed [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:191 @ 04/20/26 19:29:53.999&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully eventually leads to the status reported at Checks tab for the successful Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:205 @ 04/20/26 19:29:54&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully eventually leads to the status reported at Checks tab for the failed Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:209 @ 04/20/26 19:29:54&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully eventually leads to the status reported at Checks tab for the optional Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:213 @ 04/20/26 19:29:54&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully checks if the optional Integration Test Scenario status is reported in the Snapshot [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:217 @ 04/20/26 19:29:54&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully checks if the finalizer was removed from the optional Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:232 @ 04/20/26 19:29:54.001&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully merging the PR, expected to succeed  [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:236 @ 04/20/26 19:29:54.001&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully leads to triggering a push PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:245 @ 04/20/26 19:29:54.001&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully verifies that Push PipelineRuns completed [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:260 @ 04/20/26 19:29:54.001&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully validates the Integration test scenario PipelineRun is reported to merge request CheckRuns, and it pass [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:265 @ 04/20/26 19:29:54.001&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully eventually leads to the status reported at Checks tab for the failed Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:270 @ 04/20/26 19:29:54.002&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when The git-provider annotation is missing should set the git-reporting-failure annotation correctly [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:276 @ 04/20/26 19:29:54.002&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when build pipelinerun fails build pipelinerun is created but fails [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:323 @ 04/20/26 19:29:54.002&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when build pipelinerun fails build pipelinerun failure is reported to integration test checkRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/status-reporting-to-pullrequest.go:368 @ 04/20/26 19:29:54.002&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when a new Component with specified custom branch is created triggers a Build PipelineRun [integration-service, forgejo-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="52.280020082">
              <system-err>&gt; Enter [BeforeAll] Forgejo with status reporting of Integration tests in the associated merge request - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:44 @ 04/20/26 19:14:00.357&#xA;&lt; Exit [BeforeAll] Forgejo with status reporting of Integration tests in the associated merge request - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:44 @ 04/20/26 19:14:09.897 (9.54s)&#xA;&gt; Enter [BeforeAll] when a new Component with specified custom branch is created - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:128 @ 04/20/26 19:14:09.897&#xA;Image repository for component test-comp-pac-forgejo-utvouv in namespace forgejo-rep-ccja do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [BeforeAll] when a new Component with specified custom branch is created - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:128 @ 04/20/26 19:14:52.61 (42.713s)&#xA;&gt; Enter [It] triggers a Build PipelineRun - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:211 @ 04/20/26 19:14:52.61&#xA;&lt; Exit [It] triggers a Build PipelineRun - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:211 @ 04/20/26 19:14:52.636 (26ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:41 @ 04/20/26 19:14:52.637&#xA;&lt; Exit [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:41 @ 04/20/26 19:14:52.637 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when a new Component with specified custom branch is created does not contain an annotation with a Snapshot Name [integration-service, forgejo-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.000306228">
              <system-err>&gt; Enter [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:225 @ 04/20/26 19:14:52.637&#xA;&lt; Exit [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:225 @ 04/20/26 19:14:52.637 (0s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:41 @ 04/20/26 19:14:52.637&#xA;&lt; Exit [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:41 @ 04/20/26 19:14:52.637 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when a new Component with specified custom branch is created should lead to build PipelineRun finishing successfully [integration-service, forgejo-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="failed" time="1005.628390913">
              <failure message="Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc0003bf9a0&gt;: &#xA;    unable to retrigger pipelinerun for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv: timed out waiting for new PipelineRun to appear after retriggering it for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv&#xA;    {&#xA;        s: &#34;unable to retrigger pipelinerun for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv: timed out waiting for new PipelineRun to appear after retriggering it for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv&#34;,&#xA;    }" type="failed">[FAILED] Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc0003bf9a0&gt;: &#xA;    unable to retrigger pipelinerun for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv: timed out waiting for new PipelineRun to appear after retriggering it for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv&#xA;    {&#xA;        s: &#34;unable to retrigger pipelinerun for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv: timed out waiting for new PipelineRun to appear after retriggering it for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:231 @ 04/20/26 19:31:33.646&#xA;</failure>
              <system-err>&gt; Enter [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:229 @ 04/20/26 19:14:52.638&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-zb4tg found for Component forgejo-rep-ccja/test-comp-pac-forgejo-utvouv&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-zb4tg reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-zb4tg reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun test-comp-pac-forgejo-utvouv-on-pull-request-48gpr reason: Running&#xA;PipelineRun my-integration-test-cckl-v9cr8 reason: Running&#xA;PipelineRun my-integration-test-cckl-v9cr8 reason: Running&#xA;PipelineRun my-integration-test-cckl-v9cr8 reason: Running&#xA;PipelineRun my-integration-test-cckl-v9cr8 reason: Failed&#xA;attempt 1/3: PipelineRun &#34;my-integration-test-cckl-v9cr8&#34; failed: &#xA; pod: test-comp-pac-forgejo-utvouv-on-pull-request-48gpr-init-pod | init container: prepare&#xA;2026/04/20 19:15:18 Entrypoint initialization&#xA;&#xA;pod: test-comp-pac-forgejo-utvouv-on-pull-request-48gpr-init-pod | container step-init: &#xA;time=&#34;2026-04-20T19:15:20Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-20T19:15:20Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-20T19:15:20Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-20T19:15:20Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-20T19:15:20Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-20T19:15:20Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-20T19:15:20Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-20T19:15:20Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-20T19:15:20Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;&#xA; pod: test-comp-pac-forgejo-utvouv-on-pull-request-48gpr-tpa-scan-pod | init container: prepare&#xA;2026/04/20 19:22:04 Entrypoint initialization&#xA;&#xA; pod: test-comp-pac-forgejo-utvouv-on-pull-request-48gpr-tpa-scan-pod | init container: place-scripts&#xA;2026/04/20 19:22:05 Decoded script /tekton/scripts/script-0-b5sgb&#xA;2026/04/20 19:22:05 Decoded script /tekton/scripts/script-1-r4t5h&#xA;2026/04/20 19:22:05 Decoded script /tekton/scripts/script-2-25kkm&#xA;&#xA;pod: test-comp-pac-forgejo-utvouv-on-pull-request-48gpr-tpa-scan-pod | container step-get-vulnerabilities: &#xA;Inspecting raw image manifest quay.io/redhat-appstudio-qe/forgejo-rep-ccja/test-comp-pac-forgejo-utvouv@sha256:1f9c2afcd1335d6e969ddc78b60565f7f5207d8b2e581461d596e85cda2840a1.&#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/forgejo-rep-ccja/test-comp-pac-forgejo-utvouv&#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/forgejo-rep-ccja/test-comp-pac-forgejo-utvouv&#xA;WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations.&#xA;WARNING: Downloading SBOMs this way does not ensure its authenticity. If you want to ensure a tamper-proof SBOM, download it using &#39;cosign download attestation &lt;image uri&gt;&#39;.&#xA;Found SBOM of media type: text/spdx+json&#xA;Running TPA scan on amd64 image manifest...&#xA;  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current&#xA;                                 Dload  Upload   Total   Spent    Left  Speed&#xA;&#xD;  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0{&#xA;  &#34;scanned&#34; : {&#xA;    &#34;total&#34; : 152,&#xA;    &#34;direct&#34; : 25,&#xA;    &#34;transitive&#34; : 127&#xA;  },&#xA;  &#34;providers&#34; : {&#xA;    &#34;rhtpa&#34; : {&#xA;      &#34;status&#34; : {&#xA;        &#34;ok&#34; : true,&#xA;        &#34;name&#34; : &#34;rhtpa&#34;,&#xA;        &#34;code&#34; : 200,&#xA;        &#34;message&#34; : &#34;OK&#34;,&#xA;        &#34;warnings&#34; : {&#xA;          &#34;pkg:maven/io.github.stuartwdouglas.hacbstest.Main/hacbs-test&#34; : [ &#34;Unable to process: missing version component&#34; ]&#xA;        }&#xA;      },&#xA;      &#34;sources&#34; : {&#xA;        &#34;osv-github&#34; : {&#xA;          &#34;summary&#34; : {&#xA;            &#34;direct&#34; : 2,&#xA;            &#34;transitive&#34; : 0,&#xA;            &#34;total&#34; : 2,&#xA;            &#34;dependencies&#34; : 1,&#xA;            &#34;critical&#34; : 0,&#xA;            &#34;high&#34; : 2,&#xA;            &#34;medium&#34; : 0,&#xA;            &#34;low&#34; : 0,&#xA;            &#34;remediations&#34; : 0,&#xA;            &#34;recommendations&#34; : 0,&#xA;            &#34;unscanned&#34; : 0&#xA;          },&#xA;          &#34;dependencies&#34; : [ {&#xA;            &#34;ref&#34; : &#34;pkg:pypi/setuptools@39.2.0&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;              &#34;source&#34; : &#34;osv-github&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-40897&#34;,&#xA;              &#34;source&#34; : &#34;osv-github&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-40897&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;              &#34;source&#34; : &#34;osv-github&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          } ]&#xA;        },&#xA;        &#34;redhat-csaf&#34; : {&#xA;          &#34;summary&#34; : {&#xA;            &#34;direct&#34; : 50,&#xA;            &#34;transitive&#34; : 338,&#xA;            &#34;total&#34; : 388,&#xA;            &#34;dependencies&#34; : 57,&#xA;            &#34;critical&#34; : 7,&#xA;            &#34;high&#34; : 134,&#xA;            &#34;medium&#34; : 228,&#xA;            &#34;low&#34; : 19,&#xA;            &#34;remediations&#34; : 0,&#xA;            &#34;recommendations&#34; : 0,&#xA;            &#34;unscanned&#34; : 0&#xA;          },&#xA;          &#34;dependencies&#34; : [ {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-42919&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-42919&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2023-6597&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-6597&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2015-20107&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2015-20107&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-12718&#34;,&#xA;              &#34;title&#34; : &#34;Bypass extraction filter to modify file metadata outside extraction directory&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-12718&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4517&#34;,&#xA;              &#34;title&#34; : &#34;Arbitrary writes via tarfile realpath overflow&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4517&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2020-10735&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2020-10735&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-45061&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-45061&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2023-24329&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-24329&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-6232&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6232&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-12084&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-12084&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4138&#34;,&#xA;              &#34;title&#34; : &#34;Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4138&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4435&#34;,&#xA;              &#34;title&#34; : &#34;Tarfile extracts filtered members when errorlevel=0&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4435&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-8194&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-8194&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2021-28861&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.4,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-28861&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4330&#34;,&#xA;              &#34;title&#34; : &#34;Extraction filter bypass for linking outside extraction directory&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.3,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4330&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-15366&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15366&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-15367&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15367&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-1299&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-1299&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-4519&#34;,&#xA;              &#34;title&#34; : &#34;webbrowser.open() allows leading dashes in URLs&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-4519&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-6923&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6923&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-0938&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-0938&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-13836&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-13836&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-9287&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-9287&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-0450&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.2,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-0450&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;              &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2023-27043&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-27043&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-8088&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-8088&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-0397&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.0,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-0397&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-7592&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-7592&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-0865&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-0865&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-6069&#34;,&#xA;              &#34;title&#34; : &#34;HTMLParser quadratic complexity when processing malformed inputs&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-6069&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-8291&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-8291&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-6075&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.0,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-6075&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-11168&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 3.7,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-11168&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-4032&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 3.7,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-4032&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-5642&#34;,&#xA;              &#34;title&#34; : &#34;Buffer overread when using an empty list with SSLContext.set_npn_protocols()&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 2.7,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-5642&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-47273&#34;,&#xA;                &#34;title&#34; : &#34;setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-47273&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40897&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40897&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42919&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42919&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6597&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6597&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2015-20107&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2015-20107&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12718&#34;,&#xA;                &#34;title&#34; : &#34;Bypass extraction filter to modify file metadata outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12718&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4517&#34;,&#xA;                &#34;title&#34; : &#34;Arbitrary writes via tarfile realpath overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4517&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-10735&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-10735&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45061&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45061&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-24329&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-24329&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6232&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6232&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-12084&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-12084&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4138&#34;,&#xA;                &#34;title&#34; : &#34;Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4138&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4435&#34;,&#xA;                &#34;title&#34; : &#34;Tarfile extracts filtered members when errorlevel=0&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4435&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8194&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8194&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-28861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-28861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4330&#34;,&#xA;                &#34;title&#34; : &#34;Extraction filter bypass for linking outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4330&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15366&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15366&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15367&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15367&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1299&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1299&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4519&#34;,&#xA;                &#34;title&#34; : &#34;webbrowser.open() allows leading dashes in URLs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6923&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6923&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0938&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13836&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13836&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-9287&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-9287&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8088&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8088&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0397&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0397&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-7592&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-7592&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0865&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0865&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6069&#34;,&#xA;                &#34;title&#34; : &#34;HTMLParser quadratic complexity when processing malformed inputs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6069&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8291&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8291&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6075&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6075&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-11168&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-11168&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4032&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5642&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overread when using an empty list with SSLContext.set_npn_protocols()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5642&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=expat-2.5.0-1.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28757&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28757&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45490&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45490&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8176&#34;,&#xA;                &#34;title&#34; : &#34;Libexpat: expat: improper restriction of xml entity expansion depth in libexpat&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45492&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45492&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-50602&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-50602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-59375&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-59375&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtirpc-1.1.4-12.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-pip-9.0.3-24.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;              &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2026-21945&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-21945&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-64720&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-64720&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-65018&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-65018&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-21933&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.1,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-21933&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-21925&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-21925&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-47273&#34;,&#xA;                &#34;title&#34; : &#34;setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-47273&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40897&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40897&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/javapackages-filesystem@5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6?arch=noarch&amp;distro=rhel-8.10&amp;upstream=javapackages-tools-5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-48734&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-48734&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2019-10086&#34;,&#xA;                &#34;title&#34; : &#34;In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-10086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-48734&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-48734&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42919&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42919&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6597&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6597&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2015-20107&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2015-20107&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12718&#34;,&#xA;                &#34;title&#34; : &#34;Bypass extraction filter to modify file metadata outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12718&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4517&#34;,&#xA;                &#34;title&#34; : &#34;Arbitrary writes via tarfile realpath overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4517&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-10735&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-10735&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45061&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45061&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-24329&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-24329&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6232&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6232&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-12084&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-12084&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4138&#34;,&#xA;                &#34;title&#34; : &#34;Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4138&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4435&#34;,&#xA;                &#34;title&#34; : &#34;Tarfile extracts filtered members when errorlevel=0&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4435&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8194&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8194&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-28861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-28861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4330&#34;,&#xA;                &#34;title&#34; : &#34;Extraction filter bypass for linking outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4330&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15366&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15366&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15367&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15367&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1299&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1299&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4519&#34;,&#xA;                &#34;title&#34; : &#34;webbrowser.open() allows leading dashes in URLs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6923&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6923&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0938&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13836&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13836&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-9287&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-9287&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8088&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8088&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0397&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0397&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-7592&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-7592&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0865&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0865&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6069&#34;,&#xA;                &#34;title&#34; : &#34;HTMLParser quadratic complexity when processing malformed inputs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6069&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8291&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8291&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6075&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6075&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-11168&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-11168&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4032&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5642&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overread when using an empty list with SSLContext.set_npn_protocols()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5642&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/cups-libs@2.2.6-67.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=cups-2.2.6-67.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-58060&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58060&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-47175&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-47175&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-34241&#34;,&#xA;                &#34;title&#34; : &#34;CUPS vulnerable to use-after-free in cupsdAcceptClient()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-34241&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-26691&#34;,&#xA;                &#34;title&#34; : &#34;A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-26691&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32360&#34;,&#xA;                &#34;title&#34; : &#34;An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32360&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-58364&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58364&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32324&#34;,&#xA;                &#34;title&#34; : &#34;OpenPrinting CUPS vulnerable to heap buffer overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32324&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-58436&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58436&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-35235&#34;,&#xA;                &#34;title&#34; : &#34;Cupsd Listen arbitrary chmod 0140777&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-35235&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-58060&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58060&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=expat-2.5.0-1.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28757&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28757&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45490&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45490&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8176&#34;,&#xA;                &#34;title&#34; : &#34;Libexpat: expat: improper restriction of xml entity expansion depth in libexpat&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45492&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45492&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-50602&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-50602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-59375&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-59375&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnutls-3.6.16-8.el8_10.5.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0553&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: incomplete fix for cve-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0553&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0567&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0567&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0361&#34;,&#xA;                &#34;title&#34; : &#34;A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0361&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32988&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls othername san export&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32988&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32990&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls certtool template parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32990&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6395&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5981&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12243&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12243&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28834&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28834&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14831&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14831&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32989&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls sct extension parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32989&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28835&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28835&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9820&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9820&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtirpc-1.1.4-12.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/dbus-libs@1.12.8-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=dbus-1.12.8-27.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-42010&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42010&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42011&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42011&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42012&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42012&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-34969&#34;,&#xA;                &#34;title&#34; : &#34;D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-34969&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-42010&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42010&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/avahi-libs@0.7-27.el8_10.1?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=avahi-0.7-27.el8_10.1.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-3468&#34;,&#xA;                &#34;title&#34; : &#34;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1981&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38470&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38470&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38471&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38471&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38472&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38472&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38473&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-3502&#34;,&#xA;                &#34;title&#34; : &#34;A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3502&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-52615&#34;,&#xA;                &#34;title&#34; : &#34;Avahi: avahi wide-area dns uses constant source port&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-52615&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-52616&#34;,&#xA;                &#34;title&#34; : &#34;Avahi: avahi wide-area dns predictable transaction ids&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-52616&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-3468&#34;,&#xA;                &#34;title&#34; : &#34;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27456&#34;,&#xA;                &#34;title&#34; : &#34;util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27456&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=systemd-239-82.el8_10.15.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3821&#34;,&#xA;                &#34;title&#34; : &#34;An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3821&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45873&#34;,&#xA;                &#34;title&#34; : &#34;systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45873&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4598&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4598&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgcrypt-1.8.5-7.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-pip-9.0.3-24.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=alsa-lib-1.2.10-2.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2026-25068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-25068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2026-25068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-25068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;              &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;              &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;              &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15079&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15079&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13034&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13034&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14819&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14819&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1965&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14524&#34;,&#xA;                &#34;title&#34; : &#34;bearer token leak on cross-protocol redirect&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14524&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3784&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3784&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3805&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10966&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10966&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3783&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3783&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10148&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10148&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14017&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14017&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15224&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15224&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxml2-2.9.7-21.el8_10.3.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49794&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: heap use after free (uaf) leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49794&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49796&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: type confusion leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-56171&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-56171&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40304&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24928&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7425&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40303&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40303&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-25062&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-25062&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49795&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: null pointer dereference leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6021&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6021&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7424&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29824&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don&#39;t check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2&#39;s buffer functions, for example libxslt through 1.1.35, is affected as well.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29824&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39615&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39615&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9714&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9714&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-49043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-49043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28484&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28484&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-29469&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the &#39;\\0&#39; value).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32414&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32414&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6170&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: stack buffer overflow in xmllint interactive shell command handling&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.5,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6170&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libarchive-3.3.3-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4111&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4111&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4424&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-5121&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-5121&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-26280&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-26280&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-36227&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-36227&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-57970&#34;,&#xA;                &#34;title&#34; : &#34;libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-57970&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-25724&#34;,&#xA;                &#34;title&#34; : &#34;list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-25724&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27135&#34;,&#xA;                &#34;title&#34; : &#34;nghttp2 Denial of service: Assertion failure due to the missing state validation&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27135&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28182&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28182&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=brotli-1.0.6-4.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=microdnf-3.8.0-2.el8.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15079&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15079&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13034&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13034&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14819&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14819&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1965&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14524&#34;,&#xA;                &#34;title&#34; : &#34;bearer token leak on cross-protocol redirect&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14524&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3784&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3784&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3805&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10966&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10966&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3783&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3783&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10148&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10148&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14017&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14017&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15224&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15224&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxml2-2.9.7-21.el8_10.3.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49794&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: heap use after free (uaf) leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49794&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49796&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: type confusion leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-56171&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-56171&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40304&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24928&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7425&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40303&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40303&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-25062&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-25062&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49795&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: null pointer dereference leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6021&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6021&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7424&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29824&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don&#39;t check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2&#39;s buffer functions, for example libxslt through 1.1.35, is affected as well.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29824&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39615&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39615&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9714&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9714&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-49043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-49043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28484&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28484&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-29469&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the &#39;\\0&#39; value).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32414&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32414&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6170&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: stack buffer overflow in xmllint interactive shell command handling&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.5,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6170&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libksba@1.3.5-9.el8_7?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libksba-1.3.5-9.el8_7.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3515&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3515&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-47629&#34;,&#xA;                &#34;title&#34; : &#34;Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-47629&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3515&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3515&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnupg2-2.2.20-4.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2026-24882&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-24882&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68973&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68973&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-34903&#34;,&#xA;                &#34;title&#34; : &#34;GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&#39;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-34903&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2026-24882&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-24882&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libarchive-3.3.3-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4111&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4111&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4424&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-5121&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-5121&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-26280&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-26280&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-36227&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-36227&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-57970&#34;,&#xA;                &#34;title&#34; : &#34;libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-57970&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-25724&#34;,&#xA;                &#34;title&#34; : &#34;list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-25724&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glib2-2.56.4-168.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-13601&#34;,&#xA;                &#34;title&#34; : &#34;Glib: integer overflow in in g_escape_uri_string()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-52533&#34;,&#xA;                &#34;title&#34; : &#34;gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing &#39;\\0&#39; character.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-52533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32611&#34;,&#xA;                &#34;title&#34; : &#34;G_variant_byteswap() can take a long time with some non-normal inputs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32611&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32665&#34;,&#xA;                &#34;title&#34; : &#34;Gvariant deserialisation does not match spec for non-normal data&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32665&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14512&#34;,&#xA;                &#34;title&#34; : &#34;Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14512&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-29499&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29499&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14087&#34;,&#xA;                &#34;title&#34; : &#34;Glib: glib: buffer underflow in gvariant parser leads to heap corruption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14087&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4373&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4373&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-34397&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.8,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-34397&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-13601&#34;,&#xA;                &#34;title&#34; : &#34;Glib: integer overflow in in g_escape_uri_string()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsolv-0.7.20-6.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-33928&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-33929&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33929&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-33930&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33930&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-33938&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-46877&#34;,&#xA;                &#34;title&#34; : &#34;jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46877&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28863&#34;,&#xA;                &#34;title&#34; : &#34;node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28863&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-44568&#34;,&#xA;                &#34;title&#34; : &#34;Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 &amp; line 1995), which could cause a remote Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44568&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-3200&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3200&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-33928&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=brotli-1.0.6-4.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnutls-3.6.16-8.el8_10.5.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0553&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: incomplete fix for cve-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0553&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0567&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0567&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0361&#34;,&#xA;                &#34;title&#34; : &#34;A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0361&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32988&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls othername san export&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32988&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32990&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls certtool template parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32990&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6395&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5981&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12243&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12243&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28834&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28834&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14831&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14831&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32989&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls sct extension parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32989&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28835&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28835&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9820&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9820&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27135&#34;,&#xA;                &#34;title&#34; : &#34;nghttp2 Denial of service: Assertion failure due to the missing state validation&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27135&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28182&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28182&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27456&#34;,&#xA;                &#34;title&#34; : &#34;util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27456&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgcrypt-1.8.5-7.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=systemd-239-82.el8_10.15.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3821&#34;,&#xA;                &#34;title&#34; : &#34;An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3821&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45873&#34;,&#xA;                &#34;title&#34; : &#34;systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45873&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4598&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4598&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=file-5.33-27.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-48554&#34;,&#xA;                &#34;title&#34; : &#34;File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: \&#34;File\&#34; is the name of an Open Source project.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-48554&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-48554&#34;,&#xA;                &#34;title&#34; : &#34;File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: \&#34;File\&#34; is the name of an Open Source project.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-48554&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=tar-1.30-11.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2025-45582&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.6,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-45582&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-48303&#34;,&#xA;              &#34;title&#34; : &#34;GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-48303&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lz4-1.8.3-5.el8_10.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=rootfiles-8.1-22.el8.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsemanage-2.9-12.el8_10.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=shadow-utils-4.6-23.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2023-4641&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.7,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-4641&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-56433&#34;,&#xA;              &#34;title&#34; : &#34;shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 3.6,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-56433&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          } ]&#xA;        }&#xA;      }&#xA;    }&#xA;  },&#xA;  &#34;licenses&#34; : [ {&#xA;    &#34;status&#34; : {&#xA;      &#34;ok&#34; : false,&#xA;      &#34;name&#34; : &#34;deps.dev&#34;,&#xA;      &#34;code&#34; : 400,&#xA;      &#34;message&#34; : &#34;Bad Request: invalid purl \&#34;pkg:maven/io.github.stuartwdouglas.hacbstest.Main/hacbs-test\&#34; at request index 25&#34;,&#xA;      &#34;warnings&#34; : { }&#xA;    },&#xA;    &#34;summary&#34; : {&#xA;      &#34;total&#34; : 1,&#xA;      &#34;concluded&#34; : 119,&#xA;      &#34;permissive&#34; : 1,&#xA;      &#34;weakCopyleft&#34; : 0,&#xA;      &#34;strongCopyleft&#34; : 0,&#xA;      &#34;unknown&#34; : 0,&#xA;      &#34;deprecated&#34; : 0,&#xA;      &#34;osiApproved&#34; : 1,&#xA;      &#34;fsfLibre&#34; : 1&#xA;    },&#xA;    &#34;packages&#34; : {&#xA;      &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=p11-kit-0.23.22-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libxcrypt@4.1.1-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxcrypt-4.1.1-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sed-4.5-5.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/filesystem@3.8-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=filesystem-3.8-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsolv-0.7.20-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsemanage-2.9-12.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/nettle@3.4.1-7.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nettle-3.4.1-7.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libverto@0.3.2-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libverto-0.3.2-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gdbm-libs@1.18-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gdbm-1.18-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libunistring@0.9.9-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libunistring-0.9.9-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/platform-python@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=shadow-utils-4.6-23.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/json-c@0.13.1-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=json-c-0.13.1-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libyaml@0.1.7-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libyaml-0.1.7-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libksba@1.3.5-9.el8_7?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libksba-1.3.5-9.el8_7.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=file-5.33-27.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gpgme@1.13.1-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gpgme-1.13.1-12.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libacl@2.2.53-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=acl-2.2.53-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libmodulemd@2.13.0-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libmodulemd-2.13.0-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gpg-pubkey@fd431d51-4ae0493b?distro=rhel-9.2&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=p11-kit-0.23.22-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zstd-1.4.4-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtirpc-1.1.4-12.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-pip-9.0.3-24.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/langpacks-en@1.0-12.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=langpacks-1.0-12.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/keyutils-libs@1.5.10-9.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=keyutils-1.5.10-9.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnutls-3.6.16-8.el8_10.5.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:github/beatlabs/delete-old-branches-action@v0.0.10&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/findutils@4.6.0-24.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=findutils-4.6.0-24.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=attr-2.4.48-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/npth@1.5-4.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=npth-1.5-4.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/librepo@1.14.2-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=librepo-1.14.2-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/dbus-libs@1.12.8-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=dbus-1.12.8-27.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glib2-2.56.4-168.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/chkconfig@1.19.2-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=chkconfig-1.19.2-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=tar-1.30-11.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libdb@5.3.28-42.el8_4?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libdb-5.3.28-42.el8_4.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/platform-python-setuptools@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/librhsm@0.0.3-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=librhsm-0.0.3-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/publicsuffix-list-dafsa@20180723-1.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=publicsuffix-list-20180723-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gpg-pubkey@d4082792-5b32db75?distro=rhel-8.10&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/readline@7.0-10.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=readline-7.0-10.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libdnf@0.63.0-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libdnf-0.63.0-21.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libusbx@1.0.23-4.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libusbx-1.0.23-4.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsigsegv@2.11-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsigsegv-2.11-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/ca-certificates@2025.2.80_v9.0.304-80.2.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ca-certificates-2025.2.80_v9.0.304-80.2.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gawk-4.2.1-4.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libnsl2@1.2.0-2.20180605git4a062cf.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libnsl2-1.2.0-2.20180605git4a062cf.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=brotli-1.0.6-4.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/crypto-policies-scripts@20230731-1.git3177e06.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=crypto-policies-20230731-1.git3177e06.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/basesystem@11-5.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=basesystem-11-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=popt-1.18-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libidn2@2.2.0-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libidn2-2.2.0-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/setup@2.12.2-9.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=setup-2.12.2-9.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/tzdata@2026a-1.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=tzdata-2026a-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=systemd-239-82.el8_10.15.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxml2-2.9.7-21.el8_10.3.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/grep@3.1-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=grep-3.1-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/mpfr@3.1.6-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=mpfr-3.1.6-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/redhat-release@8.10-0.3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=redhat-release-8.10-0.3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pk&#xD;100 1002k    0  641k  100  360k   860k   483k --:--:-- --:--:-- --:--:-- 1344k&#xA;g:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libassuan@2.5.1-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libassuan-2.5.1-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=elfutils-0.190-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgcrypt-1.8.5-7.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/json-glib@1.4.4-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=json-glib-1.4.4-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gobject-introspection@1.56.1-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gobject-introspection-1.56.1-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnupg2-2.2.20-4.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libselinux@2.9-11.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libselinux-2.9-11.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsepol@2.9-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsepol-2.9-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:github/actions/checkout@v4&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libgpg-error@1.31-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgpg-error-1.31-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=rootfiles-8.1-22.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/info@6.5-7.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=texinfo-6.5-7.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libdb-utils@5.3.28-42.el8_4?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libdb-5.3.28-42.el8_4.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libpsl@0.20.2-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libpsl-0.20.2-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=coreutils-8.30-17.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcap-ng@0.7.11-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-ng-0.7.11-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=cyrus-sasl-2.1.27-6.el8_5.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/crypto-policies@20230731-1.git3177e06.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=crypto-policies-20230731-1.git3177e06.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libffi@3.1-24.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libffi-3.1-24.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/pcre@8.42-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre-8.42-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gdbm@1.18-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gdbm-1.18-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/audit-libs@3.1.2-1.el8_10.1?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=audit-3.1.2-1.el8_10.1.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lz4-1.8.3-5.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:pypi/setuptools@39.2.0&#34; : {&#xA;        &#34;concluded&#34; : {&#xA;          &#34;identifiers&#34; : [ {&#xA;            &#34;id&#34; : &#34;MIT&#34;,&#xA;            &#34;name&#34; : &#34;MIT License&#34;,&#xA;            &#34;isDeprecated&#34; : false,&#xA;            &#34;isOsiApproved&#34; : true,&#xA;            &#34;isFsfLibre&#34; : true,&#xA;            &#34;category&#34; : &#34;PERMISSIVE&#34;&#xA;          } ],&#xA;          &#34;expression&#34; : &#34;MIT&#34;,&#xA;          &#34;name&#34; : &#34;MIT License&#34;,&#xA;          &#34;category&#34; : &#34;PERMISSIVE&#34;,&#xA;          &#34;source&#34; : &#34;deps.dev&#34;,&#xA;          &#34;sourceUrl&#34; : &#34;https://api.deps.dev&#34;&#xA;        },&#xA;        &#34;evidence&#34; : [ {&#xA;          &#34;identifiers&#34; : [ {&#xA;            &#34;id&#34; : &#34;MIT&#34;,&#xA;            &#34;name&#34; : &#34;MIT License&#34;,&#xA;            &#34;isDeprecated&#34; : false,&#xA;            &#34;isOsiApproved&#34; : true,&#xA;            &#34;isFsfLibre&#34; : true,&#xA;            &#34;category&#34; : &#34;PERMISSIVE&#34;&#xA;          } ],&#xA;          &#34;expression&#34; : &#34;MIT&#34;,&#xA;          &#34;name&#34; : &#34;MIT License&#34;,&#xA;          &#34;category&#34; : &#34;PERMISSIVE&#34;,&#xA;          &#34;source&#34; : &#34;deps.dev&#34;,&#xA;          &#34;sourceUrl&#34; : &#34;https://api.deps.dev&#34;&#xA;        } ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=expat-2.5.0-1.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      }&#xA;    }&#xA;  } ]&#xA;}&#xA;pod: test-comp-pac-forgejo-utvouv-on-pull-request-48gpr-tpa-scan-pod | container step-oci-attach-report: &#xA;Using token for quay.io/redhat-appstudio-qe/forgejo-rep-ccja/test-comp-pac-forgejo-utvouv&#xA;Attaching tpa-report-amd64.json to quay.io/redhat-appstudio-qe/forgejo-rep-ccja/test-comp-pac-forgejo-utvouv@sha256:1f9c2afcd1335d6e969ddc78b60565f7f5207d8b2e581461d596e85cda2840a1&#xA;[retry] executing: oras attach --no-tty --format go-template=\{\{.digest\}\} --registry-config /tmp/auth/config.json --artifact-type application/vnd.redhat.tpa-report+json quay.io/redhat-appstudio-qe/forgejo-rep-ccja/test-comp-pac-forgejo-utvouv@sha256:1f9c2afcd1335d6e969ddc78b60565f7f5207d8b2e581461d596e85cda2840a1 tpa-report-amd64.json:application/vnd.redhat.tpa-report+json&#xA;&#xA;pod: test-comp-pac-forgejo-utvouv-on-pull-request-48gpr-tpa-scan-pod | container step-conftest-vulnerabilities: &#xA;[&#xA;&#x9;{&#xA;&#x9;&#x9;&#34;filename&#34;: &#34;/tekton/home/tpa-report-amd64.json&#34;,&#xA;&#x9;&#x9;&#34;namespace&#34;: &#34;required_checks&#34;,&#xA;&#x9;&#x9;&#34;successes&#34;: 4,&#xA;&#x9;&#x9;&#34;warnings&#34;: [&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 6 critical vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-40896, CVE-2025-49794, CVE-2025-49796), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-40896, CVE-2025-49794, CVE-2025-49796), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-3596)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_critical_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 6&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 115 high vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: osv-github. Affected dependencies: pkg:pypi/setuptools@39.2.0 [direct] (CVE-2024-6345, CVE-2022-40897); Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [direct] (CVE-2023-40217, CVE-2022-42919, CVE-2023-6597, CVE-2015-20107, CVE-2024-12718, CVE-2025-4517, CVE-2020-10735, CVE-2022-45061, CVE-2023-24329, CVE-2024-6232, CVE-2025-12084, CVE-2025-4138, CVE-2025-4435, CVE-2025-8194, CVE-2021-28861, CVE-2025-4330, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299, CVE-2026-4519), pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm [direct] (CVE-2023-2953), pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm [direct] (CVE-2026-21945, CVE-2025-64720, CVE-2025-65018), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-6345, CVE-2025-47273), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-40217, CVE-2022-42919, CVE-2023-6597, CVE-2015-20107, CVE-2024-12718, CVE-2025-4517, CVE-2020-10735, CVE-2022-45061, CVE-2023-24329, CVE-2024-6232, CVE-2025-12084, CVE-2025-4138, CVE-2025-4435, CVE-2025-8194, CVE-2021-28861, CVE-2025-4330, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299, CVE-2026-4519), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-52425, CVE-2024-28757, CVE-2024-45490, CVE-2024-45491, CVE-2024-8176), pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtirpc-1.1.4-12.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2021-46828), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-6345, CVE-2025-47273), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/javapackages-filesystem@5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6?arch=noarch\u0026distro=rhel-8.10\u0026upstream=javapackages-tools-5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-48734, CVE-2019-10086), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-40217, CVE-2022-42919, CVE-2023-6597, CVE-2015-20107, CVE-2024-12718, CVE-2025-4517, CVE-2020-10735, CVE-2022-45061, CVE-2023-24329, CVE-2024-6232, CVE-2025-12084, CVE-2025-4138, CVE-2025-4435, CVE-2025-8194, CVE-2021-28861, CVE-2025-4330, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299, CVE-2026-4519), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/cups-libs@2.2.6-67.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=cups-2.2.6-67.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-58060, CVE-2024-47175, CVE-2023-34241), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-52425, CVE-2024-28757, CVE-2024-45490, CVE-2024-45491, CVE-2024-8176), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-2509, CVE-2024-0553, CVE-2024-0567, CVE-2023-0361), pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtirpc-1.1.4-12.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-46828), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/lua@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-44964), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-44964), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2025-15079, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-56171, CVE-2022-40304, CVE-2025-24928, CVE-2025-7425, CVE-2022-40303, CVE-2024-25062, CVE-2025-32415, CVE-2025-49795, CVE-2025-6021, CVE-2025-7424, CVE-2022-29824), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-5914, CVE-2026-4111, CVE-2026-4424, CVE-2026-5121), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-44487, CVE-2026-27135), pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=brotli-1.0.6-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-6176), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-2953), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-44964), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2025-15079, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-56171, CVE-2022-40304, CVE-2025-24928, CVE-2025-7425, CVE-2022-40303, CVE-2024-25062, CVE-2025-32415, CVE-2025-49795, CVE-2025-6021, CVE-2025-7424, CVE-2022-29824), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/libksba@1.3.5-9.el8_7?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libksba-1.3.5-9.el8_7.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-3515, CVE-2022-47629), pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnupg2-2.2.20-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2026-24882, CVE-2025-68973), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-5914, CVE-2026-4111, CVE-2026-4424, CVE-2026-5121), pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glib2-2.56.4-168.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-13601, CVE-2024-52533), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsolv-0.7.20-6.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-33928, CVE-2021-33929, CVE-2021-33930, CVE-2021-33938, CVE-2021-46877), pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=brotli-1.0.6-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-6176), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-2509, CVE-2024-0553, CVE-2024-0567, CVE-2023-0361), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-44487, CVE-2026-27135), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-2953), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-44964), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_high_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 115&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 178 medium vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [direct] (CVE-2024-6923, CVE-2025-0938, CVE-2025-13836, CVE-2024-9287, CVE-2024-0450, CVE-2007-4559, CVE-2023-27043, CVE-2024-8088, CVE-2024-0397, CVE-2024-7592, CVE-2026-0865, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075), pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm [direct] (CVE-2026-21933, CVE-2026-21925), pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [direct] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm [direct] (CVE-2025-45582, CVE-2022-48303), pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm [direct] (CVE-2023-4641), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-40897), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-6923, CVE-2025-0938, CVE-2025-13836, CVE-2024-9287, CVE-2024-0450, CVE-2007-4559, CVE-2023-27043, CVE-2024-8088, CVE-2024-0397, CVE-2024-7592, CVE-2026-0865, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-45492, CVE-2024-50602, CVE-2025-59375), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2021-46848, CVE-2024-12133), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-pip-9.0.3-24.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2007-4559), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2021-46848, CVE-2024-12133), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-40897), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-6923, CVE-2025-0938, CVE-2025-13836, CVE-2024-9287, CVE-2024-0450, CVE-2007-4559, CVE-2023-27043, CVE-2024-8088, CVE-2024-0397, CVE-2024-7592, CVE-2026-0865, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075), pkg:rpm/redhat/cups-libs@2.2.6-67.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=cups-2.2.6-67.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-26691, CVE-2023-32360, CVE-2025-58364, CVE-2023-32324, CVE-2025-58436, CVE-2024-35235), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-45492, CVE-2024-50602, CVE-2025-59375), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-32988, CVE-2025-32990, CVE-2025-6395, CVE-2023-5981, CVE-2024-12243, CVE-2024-28834, CVE-2025-14831, CVE-2025-32989, CVE-2024-28835, CVE-2025-9820), pkg:rpm/redhat/lua@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/dbus-libs@1.12.8-27.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=dbus-1.12.8-27.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-42010, CVE-2022-42011, CVE-2022-42012, CVE-2023-34969), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/avahi-libs@0.7-27.el8_10.1?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=avahi-0.7-27.el8_10.1.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-3468, CVE-2023-1981, CVE-2023-38469, CVE-2023-38470, CVE-2023-38471, CVE-2023-38472, CVE-2023-38473, CVE-2021-3502, CVE-2024-52615, CVE-2024-52616), pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-14104, CVE-2026-27456), pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=systemd-239-82.el8_10.15.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-7008, CVE-2022-3821, CVE-2022-4415, CVE-2022-45873, CVE-2025-4598), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-46848, CVE-2024-12133), pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libgcrypt-1.8.5-7.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2236), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-pip-9.0.3-24.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2007-4559), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=alsa-lib-1.2.10-2.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2026-25068), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-32206, CVE-2023-23916, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-13034, CVE-2025-14819, CVE-2026-1965, CVE-2022-32206, CVE-2023-23916, CVE-2025-14524, CVE-2026-3784, CVE-2026-3805, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2025-10966, CVE-2026-3783, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2025-10148, CVE-2025-14017, CVE-2025-15224, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-39615, CVE-2025-9714, CVE-2022-49043, CVE-2023-28484, CVE-2023-29469, CVE-2025-32414), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-48795, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-48795, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-26280, CVE-2022-36227, CVE-2024-57970, CVE-2025-25724), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-28182), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-46848, CVE-2024-12133), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-32206, CVE-2023-23916, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-13034, CVE-2025-14819, CVE-2026-1965, CVE-2022-32206, CVE-2023-23916, CVE-2025-14524, CVE-2026-3784, CVE-2026-3805, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2025-10966, CVE-2026-3783, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2025-10148, CVE-2025-14017, CVE-2025-15224, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-39615, CVE-2025-9714, CVE-2022-49043, CVE-2023-28484, CVE-2023-29469, CVE-2025-32414), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnupg2-2.2.20-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-34903), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-48795, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-48795, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-26280, CVE-2022-36227, CVE-2024-57970, CVE-2025-25724), pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glib2-2.56.4-168.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-32611, CVE-2023-32665, CVE-2025-14512, CVE-2023-29499, CVE-2025-14087, CVE-2025-4373), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsolv-0.7.20-6.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-28863, CVE-2021-44568), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-32988, CVE-2025-32990, CVE-2025-6395, CVE-2023-5981, CVE-2024-12243, CVE-2024-28834, CVE-2025-14831, CVE-2025-32989, CVE-2024-28835, CVE-2025-9820), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-28182), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104, CVE-2026-27456), pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-46848, CVE-2024-12133), pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libgcrypt-1.8.5-7.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2236), pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=systemd-239-82.el8_10.15.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-7008, CVE-2022-3821, CVE-2022-4415, CVE-2022-45873, CVE-2025-4598), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=file-5.33-27.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-48554), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2019-12900)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_medium_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 178&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 14 low vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [direct] (CVE-2024-11168, CVE-2024-4032, CVE-2024-5642), pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm [direct] (CVE-2024-56433), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-11168, CVE-2024-4032, CVE-2024-5642), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-11168, CVE-2024-4032, CVE-2024-5642), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-6170), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-6170), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glib2-2.56.4-168.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-34397), pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsolv-0.7.20-6.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-3200), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-2602)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_low_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 14&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;]&#xA;&#x9;}&#xA;]&#xA;{&#34;vulnerabilities&#34;:{&#34;critical&#34;:6,&#34;high&#34;:115,&#34;medium&#34;:178,&#34;low&#34;:14,&#34;unknown&#34;:0},&#34;unpatched_vulnerabilities&#34;:{&#34;critical&#34;:0,&#34;high&#34;:0,&#34;medium&#34;:0,&#34;low&#34;:0,&#34;unknown&#34;:0}}&#xA;{&#34;image&#34;: {&#34;pullspec&#34;: &#34;quay.io/redhat-appstudio-qe/forgejo-rep-ccja/test-comp-pac-forgejo-utvouv:on-pr-d7e89c78f26f798f59b7f9ebb0aec5ddd78095b1&#34;, &#34;digests&#34;: [&#34;sha256:1f9c2afcd1335d6e969ddc78b60565f7f5207d8b2e581461d596e85cda2840a1&#34;]}}&#xA;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-20T19:22:19+00:00&#34;,&#34;note&#34;:&#34;Task tpa-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by TPA.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#xA;&#xA; pod: test-comp-pac-forgejo-utvouv-on-pull-request-zb4tg-init-pod | init container: prepare&#xA;2026/04/20 19:14:52 Entrypoint initialization&#xA;&#xA;pod: test-comp-pac-forgejo-utvouv-on-pull-request-zb4tg-init-pod | container step-init: &#xA;time=&#34;2026-04-20T19:15:08Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-20T19:15:08Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-20T19:15:08Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-20T19:15:08Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-20T19:15:08Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-20T19:15:08Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-20T19:15:08Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-20T19:15:08Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-20T19:15:08Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;[FAILED] Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc0003bf9a0&gt;: &#xA;    unable to retrigger pipelinerun for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv: timed out waiting for new PipelineRun to appear after retriggering it for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv&#xA;    {&#xA;        s: &#34;unable to retrigger pipelinerun for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv: timed out waiting for new PipelineRun to appear after retriggering it for component forgejo-rep-ccja:test-comp-pac-forgejo-utvouv&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:231 @ 04/20/26 19:31:33.646&#xA;&lt; Exit [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:229 @ 04/20/26 19:31:33.646 (16m41.009s)&#xA;&gt; Enter [AfterAll] Forgejo with status reporting of Integration tests in the associated merge request - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:105 @ 04/20/26 19:31:33.647&#xA;&lt; Exit [AfterAll] Forgejo with status reporting of Integration tests in the associated merge request - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:105 @ 04/20/26 19:31:38.009 (4.362s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:41 @ 04/20/26 19:31:38.009&#xA;&lt; Exit [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:41 @ 04/20/26 19:31:38.266 (257ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when a new Component with specified custom branch is created should have a related PaC init MR created [integration-service, forgejo-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:234 @ 04/20/26 19:31:38.275&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when a new Component with specified custom branch is created the PipelineRun should eventually finish successfully for component  [integration-service, forgejo-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:254 @ 04/20/26 19:31:38.275&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when the PaC build pipelineRun run succeeded checks if the BuildPipelineRun has the annotation of chains signed [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:261 @ 04/20/26 19:31:38.276&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when the PaC build pipelineRun run succeeded checks if the Snapshot is created [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:265 @ 04/20/26 19:31:38.276&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when the PaC build pipelineRun run succeeded checks if the Build PipelineRun got annotated with Snapshot name [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:270 @ 04/20/26 19:31:38.276&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when the Snapshot was created should find the Integration Test Scenario PipelineRun [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:276 @ 04/20/26 19:31:38.276&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Integration PipelineRun is created should eventually complete successfully [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:285 @ 04/20/26 19:31:38.276&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Integration PipelineRun is created eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:290 @ 04/20/26 19:31:38.277&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Integration PipelineRun is created validates at least one MR comment contains the final integration test result [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:296 @ 04/20/26 19:31:38.277&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Integration PipelineRun is created merging the PR should be successful [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:325 @ 04/20/26 19:31:38.277&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Integration PipelineRun is created leads to triggering a push PipelineRun [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:340 @ 04/20/26 19:31:38.277&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Run integration tests after Merged MR should eventually complete successfully [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:357 @ 04/20/26 19:31:38.277&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Run integration tests after Merged MR eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/forgejo-integration-reporting.go:362 @ 04/20/26 19:31:38.278&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC happy path Post-release verification creates component from git source https://github.com/redhat-appstudio-qe/fbc-sample-repo-test [release-pipelines, fbc-release, fbcHappyPath]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC happy path Post-release verification Creates a push snapshot for a release [release-pipelines, fbc-release, fbcHappyPath]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC happy path Post-release verification verifies the fbc release pipelinerun is running and succeeds [release-pipelines, fbc-release, fbcHappyPath]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, fbc-release, fbcHappyPath]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC Staged Index Post-release verification creates component from git source https://github.com/redhat-appstudio-qe/fbc-sample-repo-test [release-pipelines, fbc-release, fbcStagedIndex]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC Staged Index Post-release verification Creates a push snapshot for a release [release-pipelines, fbc-release, fbcStagedIndex]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC Staged Index Post-release verification verifies the fbc release pipelinerun is running and succeeds [release-pipelines, fbc-release, fbcStagedIndex]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC Staged Index Post-release verification verifies release CR completed and set succeeded. [release-pipelines, fbc-release, fbcStagedIndex]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC hotfix process FBC hotfix post-release verification creates component from git source https://github.com/redhat-appstudio-qe/fbc-sample-repo-test [release-pipelines, fbc-release, fbcHotfix]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC hotfix process FBC hotfix post-release verification Creates a push snapshot for a release [release-pipelines, fbc-release, fbcHotfix]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC hotfix process FBC hotfix post-release verification verifies the fbc release pipelinerun is running and succeeds [release-pipelines, fbc-release, fbcHotfix]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC hotfix process FBC hotfix post-release verification verifies release CR completed and set succeeded. [release-pipelines, fbc-release, fbcHotfix]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC pre-GA process FBC pre-GA post-release verification creates component from git source https://github.com/redhat-appstudio-qe/fbc-sample-repo-test [release-pipelines, fbc-release, fbcPreGA]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC pre-GA process FBC pre-GA post-release verification Creates a push snapshot for a release [release-pipelines, fbc-release, fbcPreGA]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC pre-GA process FBC pre-GA post-release verification verifies the fbc release pipelinerun is running and succeeds [release-pipelines, fbc-release, fbcPreGA]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC pre-GA process FBC pre-GA post-release verification verifies release CR completed and set succeeded. [release-pipelines, fbc-release, fbcPreGA]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when a new Component is created triggers a build PipelineRun [integration-service]" classname="Red Hat App Studio E2E tests" status="failed" time="1241.275780741">
              <failure message="Unexpected error:&#xA;    &lt;context.deadlineExceededError&gt;: &#xA;    context deadline exceeded&#xA;    {}&#xA;occurred" type="failed">[FAILED] Unexpected error:&#xA;    &lt;context.deadlineExceededError&gt;: &#xA;    context deadline exceeded&#xA;    {}&#xA;occurred&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:87 @ 04/20/26 19:34:41.008&#xA;</failure>
              <system-err>&gt; Enter [BeforeAll] with happy path for general flow of Integration service - /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:52 @ 04/20/26 19:14:00.664&#xA;Image repository for component test-component-pac-eyzzms in namespace integration1-hpfx do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [BeforeAll] with happy path for general flow of Integration service - /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:52 @ 04/20/26 19:14:40.999 (40.335s)&#xA;&gt; Enter [It] triggers a build PipelineRun - /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:85 @ 04/20/26 19:14:40.999&#xA;no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)no pipelinerun found for component test-component-pac-eyzzms (application: integ-app-ksne, namespace: integration1-hpfx)&#xA;[FAILED] Unexpected error:&#xA;    &lt;context.deadlineExceededError&gt;: &#xA;    context deadline exceeded&#xA;    {}&#xA;occurred&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:87 @ 04/20/26 19:34:41.008&#xA;&lt; Exit [It] triggers a build PipelineRun - /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:85 @ 04/20/26 19:34:41.008 (20m0.009s)&#xA;&gt; Enter [AfterAll] with happy path for general flow of Integration service - /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:68 @ 04/20/26 19:34:41.009&#xA;&lt; Exit [AfterAll] with happy path for general flow of Integration service - /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:68 @ 04/20/26 19:34:41.761 (752ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:49 @ 04/20/26 19:34:41.761&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:49 @ 04/20/26 19:34:41.939 (179ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when a new Component is created verifies if the build PipelineRun contains the finalizer [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:90 @ 04/20/26 19:34:41.94&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when a new Component is created waits for build PipelineRun to succeed [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:101 @ 04/20/26 19:34:41.941&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when a new Component is created should have a related PaC init PR created [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:107 @ 04/20/26 19:34:41.941&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the BuildPipelineRun have the annotation of chains signed [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:128 @ 04/20/26 19:34:41.941&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the Snapshot is created [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:132 @ 04/20/26 19:34:41.942&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the Build PipelineRun got annotated with Snapshot name [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:137 @ 04/20/26 19:34:41.942&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded verifies that the finalizer has been removed from the build pipelinerun [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:141 @ 04/20/26 19:34:41.942&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if all of the integrationPipelineRuns passed [integration-service, slow]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:154 @ 04/20/26 19:34:41.942&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the passed status of integration test is reported in the Snapshot [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:158 @ 04/20/26 19:34:41.942&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the skipped integration test is absent from the Snapshot&#39;s status annotation [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:173 @ 04/20/26 19:34:41.942&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the finalizer was removed from all of the related Integration pipelineRuns [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:183 @ 04/20/26 19:34:41.943&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service creates a ReleasePlan [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:188 @ 04/20/26 19:34:41.943&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service creates an snapshot of push event [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:198 @ 04/20/26 19:34:41.943&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when An snapshot of push event is created checks if the global candidate is updated after push event [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:205 @ 04/20/26 19:34:41.943&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when An snapshot of push event is created checks if all of the integrationPipelineRuns created by push event passed [integration-service, slow]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:218 @ 04/20/26 19:34:41.943&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when An snapshot of push event is created checks if a Release is created successfully [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:222 @ 04/20/26 19:34:41.944&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail triggers a build PipelineRun [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:266 @ 04/20/26 19:34:41.944&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail should have a related PaC init PR created [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:273 @ 04/20/26 19:34:41.944&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the BuildPipelineRun have the annotation of chains signed [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:292 @ 04/20/26 19:34:41.944&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the Snapshot is created [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:296 @ 04/20/26 19:34:41.944&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the Build PipelineRun got annotated with Snapshot name [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:301 @ 04/20/26 19:34:41.945&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if all of the integrationPipelineRuns finished [integration-service, slow]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:305 @ 04/20/26 19:34:41.945&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the failed status of integration test is reported in the Snapshot [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:309 @ 04/20/26 19:34:41.945&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the skipped integration test is absent from the Snapshot&#39;s status annotation [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:324 @ 04/20/26 19:34:41.945&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if snapshot is marked as failed [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:334 @ 04/20/26 19:34:41.945&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the finalizer was removed from all of the related Integration pipelineRuns [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:340 @ 04/20/26 19:34:41.946&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail creates a new IntegrationTestScenario [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:344 @ 04/20/26 19:34:41.946&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail updates the Snapshot with the re-run label for the new scenario [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:349 @ 04/20/26 19:34:41.946&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot is updated with a re-run label for a given scenario checks if the new integration pipelineRun started [integration-service, slow]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:358 @ 04/20/26 19:34:41.946&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot is updated with a re-run label for a given scenario checks if the re-run label was removed from the Snapshot [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:364 @ 04/20/26 19:34:41.946&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot is updated with a re-run label for a given scenario checks if all integration pipelineRuns finished successfully [integration-service, slow]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:378 @ 04/20/26 19:34:41.947&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot is updated with a re-run label for a given scenario checks if the name of the re-triggered pipelinerun is reported in the Snapshot [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:382 @ 04/20/26 19:34:41.947&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot is updated with a re-run label for a given scenario checks if snapshot is still marked as failed [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:399 @ 04/20/26 19:34:41.947&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail creates an snapshot of push event [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:406 @ 04/20/26 19:34:41.947&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot of push event is created checks no Release CRs are created [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/integration-service/integration.go:413 @ 04/20/26 19:34:41.947&#xA;</system-err>
          </testcase>
          <testcase name="[It] [upgrade-suite Create users and check their state] Verify AppStudioProvisionedUser [upgrade-verify]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [upgrade-suite Create users and check their state] creates AppStudioDeactivatedUser [upgrade-verify]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [upgrade-suite Create users and check their state] creates AppStudioBannedUser [upgrade-verify]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite Push to external registry] Post-release verification verifies that a Release CR should have been created in the dev namespace [release-pipelines, push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite Push to external registry] Post-release verification verifies that Release PipelineRun should eventually succeed [release-pipelines, push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite Push to external registry] Post-release verification tests if the image was pushed to quay [release-pipelines, push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite Push to external registry] Post-release verification verifies that a Release is marked as succeeded. [release-pipelines, push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private correctly targets the default branch (that is not named &#39;main&#39;) with PaC [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="119.79929611">
              <system-err>&gt; Enter [BeforeAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:54 @ 04/20/26 19:14:00.66&#xA;&lt; Exit [BeforeAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:54 @ 04/20/26 19:14:43.396 (42.736s)&#xA;&gt; Enter [BeforeAll] when a new component without specified branch is created and with visibility private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:117 @ 04/20/26 19:14:43.396&#xA;Image repository for component gl-test-custom-default-omaknf in namespace build-e2e-lvjp do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Image repository for component gl-test-custom-default-omaknf in namespace build-e2e-lvjp do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [BeforeAll] when a new component without specified branch is created and with visibility private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:117 @ 04/20/26 19:15:03.5 (20.104s)&#xA;&gt; Enter [It] correctly targets the default branch (that is not named &#39;main&#39;) with PaC - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:136 @ 04/20/26 19:15:03.5&#xA;&lt; Exit [It] correctly targets the default branch (that is not named &#39;main&#39;) with PaC - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:136 @ 04/20/26 19:16:00.459 (56.959s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:00.459&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:00.459 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private workspace parameter is set correctly in PaC repository CR [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.016184225">
              <system-err>&gt; Enter [It] workspace parameter is set correctly in PaC repository CR - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:153 @ 04/20/26 19:16:00.46&#xA;&lt; Exit [It] workspace parameter is set correctly in PaC repository CR - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:153 @ 04/20/26 19:16:00.476 (16ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:00.476&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:00.476 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="20.026501434">
              <system-err>&gt; Enter [It] triggers a PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:176 @ 04/20/26 19:16:00.476&#xA;PipelineRun has not been created yet for the component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;&lt; Exit [It] triggers a PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:176 @ 04/20/26 19:16:20.502 (20.026s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:20.503&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:20.503 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private build pipeline uses the correct serviceAccount [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.000292658">
              <system-err>&gt; Enter [It] build pipeline uses the correct serviceAccount - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:191 @ 04/20/26 19:16:20.503&#xA;&lt; Exit [It] build pipeline uses the correct serviceAccount - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:191 @ 04/20/26 19:16:20.503 (0s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:20.503&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:20.503 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private component build status is set correctly [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.00701451">
              <system-err>&gt; Enter [It] component build status is set correctly - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:195 @ 04/20/26 19:16:20.504&#xA;build status annotation value: {&#34;pac&#34;:{&#34;state&#34;:&#34;enabled&#34;,&#34;merge-url&#34;:&#34;https://gitlab.com/konflux-qe/devfile-sample-hello-world-ozjtpc/-/merge_requests/1&#34;,&#34;configuration-time&#34;:&#34;Mon, 20 Apr 2026 19:15:58 UTC&#34;},&#34;message&#34;:&#34;done&#34;}&#xA;state: enabled&#xA;mergeUrl: https://gitlab.com/konflux-qe/devfile-sample-hello-world-ozjtpc/-/merge_requests/1&#xA;errId: 0&#xA;errMessage: &#xA;configurationTime: Mon, 20 Apr 2026 19:15:58 UTC&#xA;&lt; Exit [It] component build status is set correctly - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:195 @ 04/20/26 19:16:20.511 (7ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:20.511&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:20.511 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.993622874">
              <system-err>&gt; Enter [It] image repo and robot account created successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:225 @ 04/20/26 19:16:20.511&#xA;&lt; Exit [It] image repo and robot account created successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:225 @ 04/20/26 19:16:21.504 (993ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:21.505&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:21.505 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private created image repo is private [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.912533546">
              <system-err>&gt; Enter [It] created image repo is private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:243 @ 04/20/26 19:16:21.505&#xA;&lt; Exit [It] created image repo is private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:243 @ 04/20/26 19:16:22.417 (912ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:22.418&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:22.418 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private a related PipelineRun should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="30.069525392">
              <system-err>&gt; Enter [It] a related PipelineRun should be deleted after deleting the component - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:249 @ 04/20/26 19:16:22.418&#xA;&lt; Exit [It] a related PipelineRun should be deleted after deleting the component - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:249 @ 04/20/26 19:16:52.487 (30.069s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:52.487&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:52.488 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private PR branch should not exist in the repo [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="1.343346234">
              <system-err>&gt; Enter [It] PR branch should not exist in the repo - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:265 @ 04/20/26 19:16:52.488&#xA;&lt; Exit [It] PR branch should not exist in the repo - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:265 @ 04/20/26 19:16:53.831 (1.343s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:53.831&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:53.831 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private related image repo and the robot account should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.882871962">
              <system-err>&gt; Enter [It] related image repo and the robot account should be deleted after deleting the component - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:278 @ 04/20/26 19:16:53.832&#xA;&lt; Exit [It] related image repo and the robot account should be deleted after deleting the component - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:278 @ 04/20/26 19:16:54.714 (882ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:54.714&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:54.715 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="70.089505878">
              <system-err>&gt; Enter [BeforeAll] when a new Component with specified custom branch is created - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:306 @ 04/20/26 19:16:54.715&#xA;&lt; Exit [BeforeAll] when a new Component with specified custom branch is created - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:306 @ 04/20/26 19:17:04.744 (10.029s)&#xA;&gt; Enter [It] triggers a PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:332 @ 04/20/26 19:17:04.744&#xA;PipelineRun has not been created yet for the component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;PipelineRun has not been created yet for the component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;PipelineRun has not been created yet for the component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;&lt; Exit [It] triggers a PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:332 @ 04/20/26 19:18:04.804 (1m0.06s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:18:04.804&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:18:04.804 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created should lead to a PaC init PR creation [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.275355778">
              <system-err>&gt; Enter [It] should lead to a PaC init PR creation - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:347 @ 04/20/26 19:18:04.805&#xA;&lt; Exit [It] should lead to a PaC init PR creation - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:347 @ 04/20/26 19:18:05.08 (275ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:18:05.08&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:18:05.08 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created the PipelineRun should eventually finish successfully [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="571.180932864">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:365 @ 04/20/26 19:18:05.081&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k found for Component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k reason: Failed&#xA;attempt 1/3: PipelineRun &#34;gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k&#34; failed: &#xA; pod: gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k-init-pod | init container: prepare&#xA;2026/04/20 19:17:52 Entrypoint initialization&#xA;&#xA;pod: gl-test-custom-branch-jcwtxn-on-pull-request-t9p9k-init-pod | container step-init: &#xA;time=&#34;2026-04-20T19:17:55Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-20T19:17:55Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-20T19:17:55Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-20T19:17:55Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-20T19:17:55Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-20T19:17:55Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-20T19:17:55Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-20T19:17:55Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-20T19:17:55Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;New PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 found after retrigger for component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 found for Component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-q5c82 reason: Succeeded&#xA;&lt; Exit [It] the PipelineRun should eventually finish successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:365 @ 04/20/26 19:27:36.261 (9m31.18s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:36.261&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:36.262 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="1.195898323">
              <system-err>&gt; Enter [It] image repo and robot account created successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:371 @ 04/20/26 19:27:36.262&#xA;&lt; Exit [It] image repo and robot account created successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:371 @ 04/20/26 19:27:37.458 (1.195s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:37.458&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:37.458 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created created image repo is public [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.275185767">
              <system-err>&gt; Enter [It] created image repo is public - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:390 @ 04/20/26 19:27:37.459&#xA;&lt; Exit [It] created image repo is public - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:390 @ 04/20/26 19:27:37.733 (275ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:37.734&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:37.734 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created image tag is updated successfully [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.382275239">
              <system-err>&gt; Enter [It] image tag is updated successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:396 @ 04/20/26 19:27:37.734&#xA;Image tag quay.io/redhat-appstudio-qe/build-e2e-lvjp/gl-test-custom-branch-jcwtxn:on-pr-4893c73e4d9e04a2f505df1adfa32b3f0d26cb76 successfully found in Quay&#xA;&lt; Exit [It] image tag is updated successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:396 @ 04/20/26 19:27:38.116 (382ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:38.116&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:38.116 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created should ensure pruning labels are set [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.489377022">
              <system-err>&gt; Enter [It] should ensure pruning labels are set - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:425 @ 04/20/26 19:27:38.117&#xA;&lt; Exit [It] should ensure pruning labels are set - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:425 @ 04/20/26 19:27:38.606 (489ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:38.606&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:38.606 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created eventually leads to the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.520415815">
              <system-err>&gt; Enter [It] eventually leads to the PipelineRun status report at Checks tab - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:439 @ 04/20/26 19:27:38.607&#xA;&lt; Exit [It] eventually leads to the PipelineRun status report at Checks tab - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:439 @ 04/20/26 19:27:39.007 (401ms)&#xA;&gt; Enter [AfterAll] when a new Component with specified custom branch is created - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:324 @ 04/20/26 19:27:39.008&#xA;&lt; Exit [AfterAll] when a new Component with specified custom branch is created - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:324 @ 04/20/26 19:27:39.126 (119ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:39.127&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:39.127 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is updated eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="21.280612003">
              <system-err>&gt; Enter [BeforeAll] when the PaC init branch is updated - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:454 @ 04/20/26 19:27:39.128&#xA;created file sha: 8786917755e0b8d0616c879eec15fe36b8ea152a&#xA;&lt; Exit [BeforeAll] when the PaC init branch is updated - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:454 @ 04/20/26 19:27:40.37 (1.242s)&#xA;&gt; Enter [It] eventually leads to triggering another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:464 @ 04/20/26 19:27:40.37&#xA;PipelineRun has not been created yet for the component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;&lt; Exit [It] eventually leads to triggering another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:464 @ 04/20/26 19:28:00.408 (20.037s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:28:00.408&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:28:00.408 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is updated should lead to a PaC init PR update [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.200410417">
              <system-err>&gt; Enter [It] should lead to a PaC init PR update - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:479 @ 04/20/26 19:28:00.409&#xA;&lt; Exit [It] should lead to a PaC init PR update - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:479 @ 04/20/26 19:28:00.609 (200ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:28:00.609&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:28:00.609 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is updated PipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="260.015396256">
              <system-err>&gt; Enter [It] PipelineRun should eventually finish - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:498 @ 04/20/26 19:28:00.61&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk found for Component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-pull-request-nn8vk reason: Succeeded&#xA;&lt; Exit [It] PipelineRun should eventually finish - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:498 @ 04/20/26 19:32:20.625 (4m20.015s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:32:20.625&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:32:20.625 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is updated eventually leads to another update of a PR about the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.345617951">
              <system-err>&gt; Enter [It] eventually leads to another update of a PR about the PipelineRun status report at Checks tab - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:504 @ 04/20/26 19:32:20.625&#xA;&lt; Exit [It] eventually leads to another update of a PR about the PipelineRun status report at Checks tab - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:504 @ 04/20/26 19:32:20.971 (345ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:32:20.971&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:32:20.971 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="21.398888592">
              <system-err>&gt; Enter [BeforeAll] when the PaC init branch is merged - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:520 @ 04/20/26 19:32:20.971&#xA;merged result sha: ae0125589d19cf5f8f445cd7d29de64fa2f3638b&#xA;&lt; Exit [BeforeAll] when the PaC init branch is merged - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:520 @ 04/20/26 19:32:22.344 (1.373s)&#xA;&gt; Enter [It] eventually leads to triggering another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:530 @ 04/20/26 19:32:22.344&#xA;PipelineRun has not been created yet for the component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;&lt; Exit [It] eventually leads to triggering another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:530 @ 04/20/26 19:32:42.37 (20.026s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:32:42.37&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:32:42.37 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="260.016696758">
              <system-err>&gt; Enter [It] pipelineRun should eventually finish - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:546 @ 04/20/26 19:32:42.371&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 found for Component build-e2e-lvjp/gl-test-custom-branch-jcwtxn&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Running&#xA;PipelineRun gl-test-custom-branch-jcwtxn-on-push-phq97 reason: Succeeded&#xA;&lt; Exit [It] pipelineRun should eventually finish - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:546 @ 04/20/26 19:37:02.387 (4m20.016s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:37:02.387&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:37:02.387 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged does not have expiration set [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.380118685">
              <system-err>&gt; Enter [It] does not have expiration set - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:552 @ 04/20/26 19:37:02.388&#xA;&lt; Exit [It] does not have expiration set - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:552 @ 04/20/26 19:37:02.767 (380ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:37:02.768&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:37:02.768 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged After updating image visibility to private, it should not trigger another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="121.473532661">
              <system-err>&gt; Enter [It] After updating image visibility to private, it should not trigger another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:564 @ 04/20/26 19:37:02.769&#xA;waiting for one minute and expecting to not trigger a PipelineRun&#xA;&lt; Exit [It] After updating image visibility to private, it should not trigger another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:564 @ 04/20/26 19:39:04.242 (2m1.473s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:39:04.242&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:39:04.242 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged image repo is updated to private [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.406876149">
              <system-err>&gt; Enter [It] image repo is updated to private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:595 @ 04/20/26 19:39:04.242&#xA;&lt; Exit [It] image repo is updated to private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:595 @ 04/20/26 19:39:04.649 (406ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:39:04.649&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:39:04.649 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged retrigger the pipeline manually [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged retriggered pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the component is removed and recreated (with the same name in the same namespace) should no longer lead to a creation of a PaC PR [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="27.097811978">
              <system-err>&gt; Enter [BeforeAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:650 @ 04/20/26 19:39:04.65&#xA;&lt; Exit [BeforeAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:650 @ 04/20/26 19:39:08.361 (3.71s)&#xA;&gt; Enter [BeforeAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:679 @ 04/20/26 19:39:08.361&#xA;&lt; Exit [BeforeAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:679 @ 04/20/26 19:39:18.389 (10.028s)&#xA;&gt; Enter [It] should no longer lead to a creation of a PaC PR - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:715 @ 04/20/26 19:39:18.389&#xA;&lt; Exit [It] should no longer lead to a creation of a PaC PR - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:715 @ 04/20/26 19:39:28.389 (10s)&#xA;&gt; Enter [AfterAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:697 @ 04/20/26 19:39:28.39&#xA;Found purge PR with id: 3&#xA;&lt; Exit [AfterAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:697 @ 04/20/26 19:39:28.541 (151ms)&#xA;&gt; Enter [AfterAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:101 @ 04/20/26 19:39:28.541&#xA;&lt; Exit [AfterAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:101 @ 04/20/26 19:39:31.747 (3.206s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:39:31.748&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:39:31.748 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private correctly targets the default branch (that is not named &#39;main&#39;) with PaC [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="111.244516799">
              <system-err>&gt; Enter [BeforeAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:54 @ 04/20/26 19:14:00.66&#xA;&lt; Exit [BeforeAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:54 @ 04/20/26 19:14:33.219 (32.559s)&#xA;&gt; Enter [BeforeAll] when a new component without specified branch is created and with visibility private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:117 @ 04/20/26 19:14:33.219&#xA;Image repository for component fj-test-custom-default-jyiskv in namespace build-e2e-kpuj do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [BeforeAll] when a new component without specified branch is created and with visibility private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:117 @ 04/20/26 19:14:53.294 (20.075s)&#xA;&gt; Enter [It] correctly targets the default branch (that is not named &#39;main&#39;) with PaC - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:136 @ 04/20/26 19:14:53.294&#xA;&lt; Exit [It] correctly targets the default branch (that is not named &#39;main&#39;) with PaC - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:136 @ 04/20/26 19:15:51.904 (58.61s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:15:51.904&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:15:51.904 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private workspace parameter is set correctly in PaC repository CR [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.027903819">
              <system-err>&gt; Enter [It] workspace parameter is set correctly in PaC repository CR - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:153 @ 04/20/26 19:15:51.905&#xA;&lt; Exit [It] workspace parameter is set correctly in PaC repository CR - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:153 @ 04/20/26 19:15:51.932 (28ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:15:51.933&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:15:51.933 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="20.032940102">
              <system-err>&gt; Enter [It] triggers a PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:176 @ 04/20/26 19:15:51.933&#xA;&lt; Exit [It] triggers a PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:176 @ 04/20/26 19:16:11.966 (20.033s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:11.966&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:11.966 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private build pipeline uses the correct serviceAccount [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.000355088">
              <system-err>&gt; Enter [It] build pipeline uses the correct serviceAccount - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:191 @ 04/20/26 19:16:11.967&#xA;&lt; Exit [It] build pipeline uses the correct serviceAccount - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:191 @ 04/20/26 19:16:11.967 (0s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:11.967&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:11.967 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private component build status is set correctly [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.008273437">
              <system-err>&gt; Enter [It] component build status is set correctly - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:195 @ 04/20/26 19:16:11.968&#xA;build status annotation value: {&#34;pac&#34;:{&#34;state&#34;:&#34;enabled&#34;,&#34;merge-url&#34;:&#34;https://codeberg.org/konflux-qe/devfile-sample-hello-world-mgewvh/pulls/1&#34;,&#34;configuration-time&#34;:&#34;Mon, 20 Apr 2026 19:15:49 UTC&#34;},&#34;message&#34;:&#34;done&#34;}&#xA;state: enabled&#xA;mergeUrl: https://codeberg.org/konflux-qe/devfile-sample-hello-world-mgewvh/pulls/1&#xA;errId: 0&#xA;errMessage: &#xA;configurationTime: Mon, 20 Apr 2026 19:15:49 UTC&#xA;&lt; Exit [It] component build status is set correctly - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:195 @ 04/20/26 19:16:11.976 (8ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:11.976&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:11.976 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.9006199">
              <system-err>&gt; Enter [It] image repo and robot account created successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:225 @ 04/20/26 19:16:11.977&#xA;&lt; Exit [It] image repo and robot account created successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:225 @ 04/20/26 19:16:12.877 (900ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:12.877&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:12.877 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private created image repo is private [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.286462966">
              <system-err>&gt; Enter [It] created image repo is private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:243 @ 04/20/26 19:16:12.878&#xA;&lt; Exit [It] created image repo is private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:243 @ 04/20/26 19:16:13.164 (286ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:13.164&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:13.164 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private a related PipelineRun should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="14.097572338">
              <system-err>&gt; Enter [It] a related PipelineRun should be deleted after deleting the component - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:249 @ 04/20/26 19:16:13.164&#xA;&lt; Exit [It] a related PipelineRun should be deleted after deleting the component - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:249 @ 04/20/26 19:16:27.262 (14.097s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:27.262&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:27.262 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private PR branch should not exist in the repo [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.30203487">
              <system-err>&gt; Enter [It] PR branch should not exist in the repo - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:265 @ 04/20/26 19:16:27.262&#xA;&lt; Exit [It] PR branch should not exist in the repo - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:265 @ 04/20/26 19:16:27.564 (302ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:27.564&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:27.564 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private related image repo and the robot account should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="1.212837812">
              <system-err>&gt; Enter [It] related image repo and the robot account should be deleted after deleting the component - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:278 @ 04/20/26 19:16:27.565&#xA;&lt; Exit [It] related image repo and the robot account should be deleted after deleting the component - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:278 @ 04/20/26 19:16:28.777 (1.212s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:28.777&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:16:28.777 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="90.104092159">
              <system-err>&gt; Enter [BeforeAll] when a new Component with specified custom branch is created - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:306 @ 04/20/26 19:16:28.778&#xA;&lt; Exit [BeforeAll] when a new Component with specified custom branch is created - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:306 @ 04/20/26 19:16:38.81 (10.032s)&#xA;&gt; Enter [It] triggers a PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:332 @ 04/20/26 19:16:38.81&#xA;PipelineRun has not been created yet for the component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;PipelineRun has not been created yet for the component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;PipelineRun has not been created yet for the component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;PipelineRun has not been created yet for the component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;&lt; Exit [It] triggers a PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:332 @ 04/20/26 19:17:58.882 (1m20.071s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:17:58.882&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:17:58.882 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created should lead to a PaC init PR creation [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.450974773">
              <system-err>&gt; Enter [It] should lead to a PaC init PR creation - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:347 @ 04/20/26 19:17:58.883&#xA;&lt; Exit [It] should lead to a PaC init PR creation - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:347 @ 04/20/26 19:17:59.333 (450ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:17:59.334&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:17:59.334 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created the PipelineRun should eventually finish successfully [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="594.033115556">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:365 @ 04/20/26 19:17:59.334&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 found for Component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: PipelineRunStopping&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: PipelineRunStopping&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: PipelineRunStopping&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-vll69 reason: Failed&#xA;attempt 1/3: PipelineRun &#34;fj-test-custom-branch-zywqqd-on-pull-request-vll69&#34; failed: &#xA; pod: fj-test-custom-branch-zywqqd-on-pull-request-vll69-init-pod | init container: prepare&#xA;2026/04/20 19:17:46 Entrypoint initialization&#xA;&#xA;pod: fj-test-custom-branch-zywqqd-on-pull-request-vll69-init-pod | container step-init: &#xA;time=&#34;2026-04-20T19:17:48Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-20T19:17:48Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-20T19:17:48Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-20T19:17:48Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-20T19:17:48Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-20T19:17:48Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-20T19:17:48Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-20T19:17:48Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-20T19:17:48Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;&#xA; pod: fj-test-custom-branch-zywqqd-on-pull-request-vll69-tpa-scan-pod | init container: prepare&#xA;2026/04/20 19:20:59 Entrypoint initialization&#xA;&#xA; pod: fj-test-custom-branch-zywqqd-on-pull-request-vll69-tpa-scan-pod | init container: place-scripts&#xA;2026/04/20 19:20:59 Decoded script /tekton/scripts/script-0-h8b7w&#xA;2026/04/20 19:20:59 Decoded script /tekton/scripts/script-1-xpmr4&#xA;2026/04/20 19:20:59 Decoded script /tekton/scripts/script-2-gff65&#xA;&#xA;pod: fj-test-custom-branch-zywqqd-on-pull-request-vll69-tpa-scan-pod | container step-get-vulnerabilities: &#xA;Inspecting raw image manifest quay.io/redhat-appstudio-qe/build-e2e-kpuj/fj-test-custom-branch-zywqqd@sha256:e39deddca0f115006a08f66cee66b88ff41b06a9d7e8ec44eeb025d0996f1553.&#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations.&#xA;WARNING: Downloading SBOMs this way does not ensure its authenticity. If you want to ensure a tamper-proof SBOM, download it using &#39;cosign download attestation &lt;image uri&gt;&#39;.&#xA;Found SBOM of media type: text/spdx+json&#xA;Running TPA scan on amd64 image manifest...&#xA;  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current&#xA;                                 Dload  Upload   Total   Spent    Left  Speed&#xA;&#xD;  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0&#xD;100  112k    0     0  100  112k      0  95561  0:00:01  0:00:01 --:--:-- 95561{&#xA;  &#34;scanned&#34; : {&#xA;    &#34;total&#34; : 83,&#xA;    &#34;direct&#34; : 32,&#xA;    &#34;transitive&#34; : 51&#xA;  },&#xA;  &#34;providers&#34; : {&#xA;    &#34;rhtpa&#34; : {&#xA;      &#34;status&#34; : {&#xA;        &#34;ok&#34; : true,&#xA;        &#34;name&#34; : &#34;rhtpa&#34;,&#xA;        &#34;code&#34; : 200,&#xA;        &#34;message&#34; : &#34;OK&#34;,&#xA;        &#34;warnings&#34; : { }&#xA;      },&#xA;      &#34;sources&#34; : { }&#xA;    }&#xA;  },&#xA;  &#34;licenses&#34; : [ {&#xA;    &#34;status&#34; : {&#xA;      &#34;ok&#34; : true,&#xA;      &#34;name&#34; : &#34;deps.dev&#34;,&#xA;      &#34;code&#34; : 200,&#xA;      &#34;message&#34; : &#34;OK&#34;,&#xA;      &#34;warnings&#34; : { }&#xA;    },&#xA;    &#34;summary&#34; : {&#xA;      &#34;total&#34; : 0,&#xA;      &#34;concluded&#34; : 61,&#xA;      &#34;permissive&#34; : 0,&#xA;      &#34;weakCopyleft&#34; : 0,&#xA;      &#34;strongCopyleft&#34; : 0,&#xA;      &#34;unknown&#34; : 0,&#xA;      &#34;deprecated&#34; : 0,&#xA;      &#34;osiApproved&#34; : 0,&#xA;      &#34;fsfLibre&#34; : 0&#xA;    },&#xA;    &#34;packages&#34; : {&#xA;      &#34;pkg:apk/alpine/libmd@1.1.0-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libxdmcp@1.1.5-r1?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=openssl&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libsm@1.2.6-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/alpine-baselayout-data@3.7.1-r8?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=alpine-baselayout&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/zstd-libs@1.5.7-r2?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=zstd&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libbz2@1.0.8-r6?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=bzip2&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:oci/nginx@sha256%3Ab6f74d18d53ff23b0aa833041c9515de914f4c0e7498ffd566862033cd9b9289?repository_url=quay.io%2Fjitesoft%2Fnginx&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libjpeg-turbo@3.1.2-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:generic/nginx@1.29.8&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/zlib@1.3.1-r2?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libstdc%2B%2B@15.2.0-r2?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=gcc&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=openssl&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/brotli-libs@1.2.0-r0?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=brotli&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libapk@3.0.3-r1?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=apk-tools&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/scanelf@1.3.8-r2?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=pax-utils&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libice@1.1.2-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/pcre@8.45-r4?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libsharpyuv@1.6.0-r0?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=libwebp&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libxpm@3.5.17-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/.runtime-deps@20260407.201713?arch=noarch&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/gd@2.3.3-r10?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/alpine-keys@2.6-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libxml2@2.13.9-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libwebp@1.6.0-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libavif@1.3.0-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libdav1d@1.5.2-r0?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=dav1d&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/xz-libs@5.8.2-r0?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=xz&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:a&#xD;100  120k    0  8007  100  112k   5172  74510  0:00:01  0:00:01 --:--:-- 79632&#xD;100  120k    0  8007  100  112k   5172  74510  0:00:01  0:00:01 --:--:-- 79632&#xA;pk/alpine/libxt@1.3.1-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/ca-certificates-bundle@20251003-r0?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=ca-certificates&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/ca-certificates@20251003-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:oci/fj-test-custom-branch-zywqqd@sha256%3Ae39deddca0f115006a08f66cee66b88ff41b06a9d7e8ec44eeb025d0996f1553&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libgd@2.3.3-r10?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=gd&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libx11@1.8.12-r1?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/ssl_client@1.37.0-r30?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=busybox&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=util-linux&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libgcc@15.2.0-r2?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=gcc&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/busybox-binsh@1.37.0-r30?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=busybox&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/fontconfig@2.17.1-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:github/actions/checkout@v4&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libexpat@2.7.5-r0?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=expat&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:github/beatlabs/delete-old-branches-action@v0.0.10&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libxslt@1.1.43-r3?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libxau@1.0.12-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libpng@1.6.56-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/busybox@1.37.0-r30?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/geoip@1.6.12-r6?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/alpine-release@3.23.3-r0?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=alpine-base&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/openssl@3.5.5-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/apk-tools@3.0.3-r1?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/aom-libs@3.13.1-r1?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=aom&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/freetype@2.14.1-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/alpine-baselayout@3.7.1-r8?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/musl-utils@1.2.5-r21?arch=x86_64&amp;distro=alpine-3.23.3&amp;upstream=musl&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/musl@1.2.5-r21?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libxext@1.3.6-r2?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libyuv@0.0.1887.20251502-r1?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libbsd@0.12.2-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/libxcb@1.17.0-r1?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:apk/alpine/perl@5.42.2-r0?arch=x86_64&amp;distro=alpine-3.23.3&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      }&#xA;    }&#xA;  } ]&#xA;}&#xA;pod: fj-test-custom-branch-zywqqd-on-pull-request-vll69-tpa-scan-pod | container step-oci-attach-report: &#xA;Using token for quay.io/redhat-appstudio-qe/build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;Attaching tpa-report-amd64.json to quay.io/redhat-appstudio-qe/build-e2e-kpuj/fj-test-custom-branch-zywqqd@sha256:e39deddca0f115006a08f66cee66b88ff41b06a9d7e8ec44eeb025d0996f1553&#xA;[retry] executing: oras attach --no-tty --format go-template=\{\{.digest\}\} --registry-config /tmp/auth/config.json --artifact-type application/vnd.redhat.tpa-report+json quay.io/redhat-appstudio-qe/build-e2e-kpuj/fj-test-custom-branch-zywqqd@sha256:e39deddca0f115006a08f66cee66b88ff41b06a9d7e8ec44eeb025d0996f1553 tpa-report-amd64.json:application/vnd.redhat.tpa-report+json&#xA;&#xA;pod: fj-test-custom-branch-zywqqd-on-pull-request-vll69-tpa-scan-pod | container step-conftest-vulnerabilities: &#xA;[&#xA;&#x9;{&#xA;&#x9;&#x9;&#34;filename&#34;: &#34;/tekton/home/tpa-report-amd64.json&#34;,&#xA;&#x9;&#x9;&#34;namespace&#34;: &#34;required_checks&#34;,&#xA;&#x9;&#x9;&#34;successes&#34;: 8&#xA;&#x9;}&#xA;]&#xA;{&#34;vulnerabilities&#34;:{&#34;critical&#34;:0,&#34;high&#34;:0,&#34;medium&#34;:0,&#34;low&#34;:0,&#34;unknown&#34;:0},&#34;unpatched_vulnerabilities&#34;:{&#34;critical&#34;:0,&#34;high&#34;:0,&#34;medium&#34;:0,&#34;low&#34;:0,&#34;unknown&#34;:0}}&#xA;{&#34;image&#34;: {&#34;pullspec&#34;: &#34;quay.io/redhat-appstudio-qe/build-e2e-kpuj/fj-test-custom-branch-zywqqd:on-pr-27c1779a825298697ddb9a2aa545b13336968d6b&#34;, &#34;digests&#34;: [&#34;sha256:e39deddca0f115006a08f66cee66b88ff41b06a9d7e8ec44eeb025d0996f1553&#34;]}}&#xA;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-20T19:22:39+00:00&#34;,&#34;note&#34;:&#34;Task tpa-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by TPA.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#xA;New PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw found after retrigger for component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw found for Component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: ResolvingTaskRef&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-6dpxw reason: Succeeded&#xA;&lt; Exit [It] the PipelineRun should eventually finish successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:365 @ 04/20/26 19:27:53.367 (9m54.033s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:53.367&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:53.367 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="1.038580552">
              <system-err>&gt; Enter [It] image repo and robot account created successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:371 @ 04/20/26 19:27:53.368&#xA;&lt; Exit [It] image repo and robot account created successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:371 @ 04/20/26 19:27:54.406 (1.038s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:54.406&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:54.406 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created created image repo is public [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.52215655">
              <system-err>&gt; Enter [It] created image repo is public - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:390 @ 04/20/26 19:27:54.407&#xA;&lt; Exit [It] created image repo is public - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:390 @ 04/20/26 19:27:54.929 (522ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:54.929&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:54.929 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created image tag is updated successfully [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.411999301">
              <system-err>&gt; Enter [It] image tag is updated successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:396 @ 04/20/26 19:27:54.929&#xA;Image tag quay.io/redhat-appstudio-qe/build-e2e-kpuj/fj-test-custom-branch-zywqqd:on-pr-79bd2203f973c87bd40904210259ccf7747cbbdf successfully found in Quay&#xA;&lt; Exit [It] image tag is updated successfully - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:396 @ 04/20/26 19:27:55.341 (411ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:55.341&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:55.341 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created should ensure pruning labels are set [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.5416492">
              <system-err>&gt; Enter [It] should ensure pruning labels are set - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:425 @ 04/20/26 19:27:55.342&#xA;&lt; Exit [It] should ensure pruning labels are set - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:425 @ 04/20/26 19:27:55.883 (541ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:55.883&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:55.883 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created eventually leads to the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.607878261">
              <system-err>&gt; Enter [It] eventually leads to the PipelineRun status report at Checks tab - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:439 @ 04/20/26 19:27:55.884&#xA;&lt; Exit [It] eventually leads to the PipelineRun status report at Checks tab - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:439 @ 04/20/26 19:27:55.884 (0s)&#xA;&gt; Enter [AfterAll] when a new Component with specified custom branch is created - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:324 @ 04/20/26 19:27:55.884&#xA;&lt; Exit [AfterAll] when a new Component with specified custom branch is created - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:324 @ 04/20/26 19:27:56.491 (607ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:56.492&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:27:56.492 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is updated eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="21.375428701">
              <system-err>&gt; Enter [BeforeAll] when the PaC init branch is updated - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:454 @ 04/20/26 19:27:56.492&#xA;created file sha: da5e8877cdbe7c9ce2ad1dacb8b2d7f5bdcf32c5&#xA;&lt; Exit [BeforeAll] when the PaC init branch is updated - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:454 @ 04/20/26 19:27:57.837 (1.345s)&#xA;&gt; Enter [It] eventually leads to triggering another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:464 @ 04/20/26 19:27:57.837&#xA;PipelineRun has not been created yet for the component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;&lt; Exit [It] eventually leads to triggering another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:464 @ 04/20/26 19:28:17.867 (20.03s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:28:17.867&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:28:17.867 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is updated should lead to a PaC init PR update [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.268629249">
              <system-err>&gt; Enter [It] should lead to a PaC init PR update - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:479 @ 04/20/26 19:28:17.868&#xA;&lt; Exit [It] should lead to a PaC init PR update - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:479 @ 04/20/26 19:28:18.136 (268ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:28:18.136&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:28:18.136 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is updated PipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="260.020343309">
              <system-err>&gt; Enter [It] PipelineRun should eventually finish - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:498 @ 04/20/26 19:28:18.137&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 found for Component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-pull-request-d9t46 reason: Succeeded&#xA;&lt; Exit [It] PipelineRun should eventually finish - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:498 @ 04/20/26 19:32:38.157 (4m20.02s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:32:38.157&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:32:38.157 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is updated eventually leads to another update of a PR about the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.00040094">
              <system-err>&gt; Enter [It] eventually leads to another update of a PR about the PipelineRun status report at Checks tab - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:504 @ 04/20/26 19:32:38.158&#xA;&lt; Exit [It] eventually leads to another update of a PR about the PipelineRun status report at Checks tab - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:504 @ 04/20/26 19:32:38.158 (0s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:32:38.158&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:32:38.158 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="25.654217732">
              <system-err>&gt; Enter [BeforeAll] when the PaC init branch is merged - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:520 @ 04/20/26 19:32:38.159&#xA;merged result sha: 5dc5195657846a380a159f1d48709d26f88cb777&#xA;&lt; Exit [BeforeAll] when the PaC init branch is merged - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:520 @ 04/20/26 19:32:43.787 (5.629s)&#xA;&gt; Enter [It] eventually leads to triggering another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:530 @ 04/20/26 19:32:43.788&#xA;PipelineRun has not been created yet for the component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;&lt; Exit [It] eventually leads to triggering another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:530 @ 04/20/26 19:33:03.812 (20.025s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:33:03.813&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:33:03.813 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="280.024776712">
              <system-err>&gt; Enter [It] pipelineRun should eventually finish - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:546 @ 04/20/26 19:33:03.813&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q found for Component build-e2e-kpuj/fj-test-custom-branch-zywqqd&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Running&#xA;PipelineRun fj-test-custom-branch-zywqqd-on-push-v982q reason: Succeeded&#xA;&lt; Exit [It] pipelineRun should eventually finish - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:546 @ 04/20/26 19:37:43.837 (4m40.024s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:37:43.838&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:37:43.838 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged does not have expiration set [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.434656547">
              <system-err>&gt; Enter [It] does not have expiration set - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:552 @ 04/20/26 19:37:43.838&#xA;&lt; Exit [It] does not have expiration set - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:552 @ 04/20/26 19:37:44.273 (434ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:37:44.273&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:37:44.273 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged After updating image visibility to private, it should not trigger another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="122.173546785">
              <system-err>&gt; Enter [It] After updating image visibility to private, it should not trigger another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:564 @ 04/20/26 19:37:44.273&#xA;waiting for one minute and expecting to not trigger a PipelineRun&#xA;&lt; Exit [It] After updating image visibility to private, it should not trigger another PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:564 @ 04/20/26 19:39:46.446 (2m2.173s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:39:46.447&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:39:46.447 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged image repo is updated to private [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.305111917">
              <system-err>&gt; Enter [It] image repo is updated to private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:595 @ 04/20/26 19:39:46.447&#xA;&lt; Exit [It] image repo is updated to private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:595 @ 04/20/26 19:39:46.752 (305ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:39:46.752&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:39:46.752 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged retrigger the pipeline manually [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged retriggered pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the component is removed and recreated (with the same name in the same namespace) should no longer lead to a creation of a PaC PR [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="28.363304251">
              <system-err>&gt; Enter [BeforeAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:650 @ 04/20/26 19:39:46.753&#xA;&lt; Exit [BeforeAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:650 @ 04/20/26 19:39:49.934 (3.18s)&#xA;&gt; Enter [BeforeAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:679 @ 04/20/26 19:39:49.934&#xA;&lt; Exit [BeforeAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:679 @ 04/20/26 19:39:59.965 (10.031s)&#xA;&gt; Enter [It] should no longer lead to a creation of a PaC PR - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:715 @ 04/20/26 19:39:59.965&#xA;&lt; Exit [It] should no longer lead to a creation of a PaC PR - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:715 @ 04/20/26 19:40:10.093 (10.127s)&#xA;&gt; Enter [AfterAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:697 @ 04/20/26 19:40:10.093&#xA;Found purge PR with id: 3&#xA;&lt; Exit [AfterAll] when the component is removed and recreated (with the same name in the same namespace) - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:697 @ 04/20/26 19:40:11.024 (931ms)&#xA;&gt; Enter [AfterAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:101 @ 04/20/26 19:40:11.024&#xA;&lt; Exit [AfterAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:101 @ 04/20/26 19:40:15.116 (4.092s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:40:15.116&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:40:15.117 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace creates component with nudges [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="111.035947131">
              <system-err>&gt; Enter [BeforeAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:72 @ 04/20/26 19:14:00.557&#xA;ReleaseAdmissionPlan data: {&#34;Mapping&#34;:{&#34;Components&#34;:[{&#34;Name&#34;:&#34;fj-multi-component-parent-fcau&#34;,&#34;Repository&#34;:&#34;quay.io/redhat-appstudio-qe/release-repository&#34;}]}}&#xA;&lt; Exit [BeforeAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:72 @ 04/20/26 19:15:01.422 (1m0.865s)&#xA;&gt; Enter [It] creates component with nudges - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:235 @ 04/20/26 19:15:01.422&#xA;Image repository for component fj-multi-component-child-fcau in namespace build-e2e-yvmr do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Image repository for component fj-multi-component-child-fcau in namespace build-e2e-yvmr do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Image repository for component fj-multi-component-parent-fcau in namespace build-e2e-yvmr do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Image repository for component fj-multi-component-parent-fcau in namespace build-e2e-yvmr do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [It] creates component with nudges - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:235 @ 04/20/26 19:15:51.592 (50.171s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:15:51.593&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:15:51.593 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace triggers a PipelineRun for parent component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="100.085444822">
              <system-err>&gt; Enter [It] triggers a PipelineRun for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:259 @ 04/20/26 19:15:51.593&#xA;PipelineRun has not been created yet for the component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;PipelineRun has not been created yet for the component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;PipelineRun has not been created yet for the component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;PipelineRun has not been created yet for the component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;PipelineRun has not been created yet for the component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;&lt; Exit [It] triggers a PipelineRun for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:259 @ 04/20/26 19:17:31.678 (1m40.085s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:17:31.679&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:17:31.679 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for parent component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="865.182089417">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish successfully for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:274 @ 04/20/26 19:17:31.679&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv found for Component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: PipelineRunStopping&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-c74qv reason: Failed&#xA;attempt 1/3: PipelineRun &#34;fj-multi-component-parent-fcau-on-pull-request-c74qv&#34; failed: &#xA; pod: fj-multi-component-parent-fcau-on-pull-request-c74qv-init-pod | init container: prepare&#xA;2026/04/20 19:17:24 Entrypoint initialization&#xA;&#xA;pod: fj-multi-component-parent-fcau-on-pull-request-c74qv-init-pod | container step-init: &#xA;time=&#34;2026-04-20T19:17:27Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-20T19:17:27Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-20T19:17:27Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-20T19:17:27Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-20T19:17:27Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-20T19:17:27Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-20T19:17:27Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-20T19:17:27Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-20T19:17:27Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;New PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms found after retrigger for component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms found for Component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: PipelineRunStopping&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-s86ms reason: Failed&#xA;attempt 2/3: PipelineRun &#34;fj-multi-component-parent-fcau-on-pull-request-s86ms&#34; failed: &#xA; pod: fj-multi-component-parent-fcau-on-pull-request-s86ms-init-pod | init container: prepare&#xA;2026/04/20 19:23:04 Entrypoint initialization&#xA;&#xA;pod: fj-multi-component-parent-fcau-on-pull-request-s86ms-init-pod | container step-init: &#xA;time=&#34;2026-04-20T19:23:07Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-20T19:23:07Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-20T19:23:07Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-20T19:23:07Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-20T19:23:07Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-20T19:23:07Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-20T19:23:07Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-20T19:23:07Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-20T19:23:07Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;New PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz found after retrigger for component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz found for Component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-pull-request-h62zz reason: Succeeded&#xA;&lt; Exit [It] the PipelineRun should eventually finish successfully for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:274 @ 04/20/26 19:31:56.861 (14m25.182s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:31:56.861&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:31:56.861 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for child component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="272.728258259">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish successfully for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:285 @ 04/20/26 19:31:56.862&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-96mmg found for Component build-e2e-yvmr/fj-multi-component-child-fcau&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-96mmg reason: Failed&#xA;attempt 1/3: PipelineRun &#34;fj-multi-component-child-fcau-on-pull-request-96mmg&#34; failed: &#xA; pod: fj-multi-component-child-fcau-on-pull-request-96mmg-init-pod | init container: prepare&#xA;2026/04/20 19:16:52 Entrypoint initialization&#xA;&#xA;pod: fj-multi-component-child-fcau-on-pull-request-96mmg-init-pod | container step-init: &#xA;time=&#34;2026-04-20T19:16:54Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-20T19:16:54Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-20T19:16:54Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-20T19:16:54Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-20T19:16:54Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-20T19:16:54Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-20T19:16:54Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-20T19:16:54Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-20T19:16:54Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;New PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft found after retrigger for component build-e2e-yvmr/fj-multi-component-child-fcau&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft found for Component build-e2e-yvmr/fj-multi-component-child-fcau&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: ResolvingTaskRef&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Running&#xA;PipelineRun fj-multi-component-child-fcau-on-pull-request-mjsft reason: Succeeded&#xA;&lt; Exit [It] the PipelineRun should eventually finish successfully for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:285 @ 04/20/26 19:36:29.59 (4m32.728s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:36:29.59&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:36:29.59 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace should lead to a PaC PR creation for child component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="2.144049046">
              <system-err>&gt; Enter [It] should lead to a PaC PR creation for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:289 @ 04/20/26 19:36:29.59&#xA;&lt; Exit [It] should lead to a PaC PR creation for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:289 @ 04/20/26 19:36:31.734 (2.144s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:36:31.734&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:36:31.734 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace Merging the PaC PR should be successful for child component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="12.903548598">
              <system-err>&gt; Enter [It] Merging the PaC PR should be successful for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:307 @ 04/20/26 19:36:31.735&#xA;merged result sha: fe332a874935427d95a4da7636f6b374c8f911c2 for PR #1&#xA;&lt; Exit [It] Merging the PaC PR should be successful for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:307 @ 04/20/26 19:36:44.638 (12.903s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:36:44.638&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:36:44.638 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace create dockerfile and yaml manifest that references build and distribution repositories [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="24.662740408">
              <system-err>&gt; Enter [It] create dockerfile and yaml manifest that references build and distribution repositories - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:318 @ 04/20/26 19:36:44.639&#xA;&lt; Exit [It] create dockerfile and yaml manifest that references build and distribution repositories - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:318 @ 04/20/26 19:37:09.301 (24.662s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:37:09.301&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:37:09.301 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace should lead to a PaC PR creation for parent component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="0.519466907">
              <system-err>&gt; Enter [It] should lead to a PaC PR creation for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:358 @ 04/20/26 19:37:09.302&#xA;&lt; Exit [It] should lead to a PaC PR creation for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:358 @ 04/20/26 19:37:09.821 (519ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:37:09.821&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:37:09.821 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace Merging the PaC PR should be successful for parent component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="5.277571311">
              <system-err>&gt; Enter [It] Merging the PaC PR should be successful for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:375 @ 04/20/26 19:37:09.822&#xA;merged result sha: 3eebecdd1e99baea3c205a5b097ebd301fbc4a2d for PR #1&#xA;&lt; Exit [It] Merging the PaC PR should be successful for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:375 @ 04/20/26 19:37:15.099 (5.277s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:37:15.099&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:37:15.099 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace PR merge triggers PAC PipelineRun for parent component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="20.033701876">
              <system-err>&gt; Enter [It] PR merge triggers PAC PipelineRun for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:385 @ 04/20/26 19:37:15.1&#xA;Push PipelineRun has not been created yet for the component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;&lt; Exit [It] PR merge triggers PAC PipelineRun for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:385 @ 04/20/26 19:37:35.133 (20.033s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:37:35.133&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:37:35.133 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace PAC PipelineRun for parent component  is successful [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="260.018190617">
              <system-err>&gt; Enter [It] PAC PipelineRun for parent component  is successful - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:401 @ 04/20/26 19:37:35.134&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s found for Component build-e2e-yvmr/fj-multi-component-parent-fcau&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Running&#xA;PipelineRun fj-multi-component-parent-fcau-on-push-6zl9s reason: Succeeded&#xA;&lt; Exit [It] PAC PipelineRun for parent component  is successful - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:401 @ 04/20/26 19:41:55.152 (4m20.018s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:41:55.152&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:41:55.152 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace should lead to a nudge PR creation for child component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="0.920537177">
              <system-err>&gt; Enter [It] should lead to a nudge PR creation for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:412 @ 04/20/26 19:41:55.152&#xA;&lt; Exit [It] should lead to a nudge PR creation for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:412 @ 04/20/26 19:41:56.073 (920ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:41:56.073&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:41:56.073 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace merging the PR should be successful for child component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="4.157911582">
              <system-err>&gt; Enter [It] merging the PR should be successful for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:429 @ 04/20/26 19:41:56.073&#xA;merged result sha: 2485ebe6a6de8e1aa5040ea2c3d02e58e75c14ba for PR #3&#xA;&lt; Exit [It] merging the PR should be successful for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:429 @ 04/20/26 19:42:00.231 (4.157s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:42:00.231&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:42:00.231 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace Verify the nudge updated the contents [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="passed" time="50.534014951">
              <system-err>&gt; Enter [It] Verify the nudge updated the contents - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:440 @ 04/20/26 19:42:00.232&#xA;Verifying Dockerfile.tmp updated to sha sha256:7efcb92024ec63254307f642e287d942252073f3e2b033f32123b00cf556bad9content: FROM quay.io/redhat-appstudio-qe/build-e2e-yvmr/fj-multi-component-parent-fcau@sha256:7efcb92024ec63254307f642e287d942252073f3e2b033f32123b00cf556bad9&#xA;RUN echo hello&#xA;&#xA;&lt; Exit [It] Verify the nudge updated the contents - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:440 @ 04/20/26 19:42:00.821 (589ms)&#xA;&gt; Enter [AfterAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:214 @ 04/20/26 19:42:00.821&#xA;&lt; Exit [AfterAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:214 @ 04/20/26 19:42:50.765 (49.944s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:42:50.765&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:42:50.766 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private correctly targets the default branch (that is not named &#39;main&#39;) with PaC [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="80.458675099">
              <system-err>&gt; Enter [BeforeAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:54 @ 04/20/26 19:14:00.66&#xA;&lt; Exit [BeforeAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:54 @ 04/20/26 19:14:24.66 (24s)&#xA;&gt; Enter [BeforeAll] when a new component without specified branch is created and with visibility private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:117 @ 04/20/26 19:14:24.66&#xA;&lt; Exit [BeforeAll] when a new component without specified branch is created and with visibility private - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:117 @ 04/20/26 19:14:34.73 (10.07s)&#xA;&gt; Enter [It] correctly targets the default branch (that is not named &#39;main&#39;) with PaC - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:136 @ 04/20/26 19:14:34.73&#xA;&lt; Exit [It] correctly targets the default branch (that is not named &#39;main&#39;) with PaC - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:136 @ 04/20/26 19:15:21.119 (46.389s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:15:21.119&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:15:21.119 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private workspace parameter is set correctly in PaC repository CR [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.017711056">
              <system-err>&gt; Enter [It] workspace parameter is set correctly in PaC repository CR - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:153 @ 04/20/26 19:15:21.119&#xA;&lt; Exit [It] workspace parameter is set correctly in PaC repository CR - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:153 @ 04/20/26 19:15:21.137 (17ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:15:21.137&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:15:21.137 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="failed" time="1800.225079087">
              <failure message="Timed out after 1800.000s.&#xA;timed out when waiting for the PipelineRun to start for the component gh-test-custom-branch-mreblu/build-e2e-jlth&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc000a6e5f0&gt;: &#xA;    no pipelinerun found for component gh-test-custom-default-pdwjen&#xA;    {&#xA;        s: &#34;no pipelinerun found for component gh-test-custom-default-pdwjen&#34;,&#xA;    }" type="failed">[FAILED] Timed out after 1800.000s.&#xA;timed out when waiting for the PipelineRun to start for the component gh-test-custom-branch-mreblu/build-e2e-jlth&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc000a6e5f0&gt;: &#xA;    no pipelinerun found for component gh-test-custom-default-pdwjen&#xA;    {&#xA;        s: &#34;no pipelinerun found for component gh-test-custom-default-pdwjen&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:188 @ 04/20/26 19:45:21.138&#xA;</failure>
              <system-err>&gt; Enter [It] triggers a PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:176 @ 04/20/26 19:15:21.137&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;PipelineRun has not been created yet for the component build-e2e-jlth/gh-test-custom-branch-mreblu&#xA;[FAILED] Timed out after 1800.000s.&#xA;timed out when waiting for the PipelineRun to start for the component gh-test-custom-branch-mreblu/build-e2e-jlth&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc000a6e5f0&gt;: &#xA;    no pipelinerun found for component gh-test-custom-default-pdwjen&#xA;    {&#xA;        s: &#34;no pipelinerun found for component gh-test-custom-default-pdwjen&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:188 @ 04/20/26 19:45:21.138&#xA;&lt; Exit [It] triggers a PipelineRun - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:176 @ 04/20/26 19:45:21.138 (30m0.001s)&#xA;&gt; Enter [AfterAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:101 @ 04/20/26 19:45:21.138&#xA;&lt; Exit [AfterAll] PaC component build - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:101 @ 04/20/26 19:45:21.138 (0s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:45:21.138&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:28 @ 04/20/26 19:45:21.362 (224ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private build pipeline uses the correct serviceAccount [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:191 @ 04/20/26 19:45:21.363&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private component build status is set correctly [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:195 @ 04/20/26 19:45:21.363&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:225 @ 04/20/26 19:45:21.363&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private created image repo is private [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:243 @ 04/20/26 19:45:21.364&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private a related PipelineRun should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:249 @ 04/20/26 19:45:21.364&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private PR branch should not exist in the repo [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:265 @ 04/20/26 19:45:21.364&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private related image repo and the robot account should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:278 @ 04/20/26 19:45:21.364&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:332 @ 04/20/26 19:45:21.364&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created should lead to a PaC init PR creation [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:347 @ 04/20/26 19:45:21.365&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created the PipelineRun should eventually finish successfully [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:365 @ 04/20/26 19:45:21.365&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:371 @ 04/20/26 19:45:21.365&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created created image repo is public [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:390 @ 04/20/26 19:45:21.365&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created image tag is updated successfully [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:396 @ 04/20/26 19:45:21.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created should ensure pruning labels are set [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:425 @ 04/20/26 19:45:21.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created eventually leads to the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:439 @ 04/20/26 19:45:21.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is updated eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:464 @ 04/20/26 19:45:21.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is updated should lead to a PaC init PR update [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:479 @ 04/20/26 19:45:21.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is updated PipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:498 @ 04/20/26 19:45:21.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is updated eventually leads to another update of a PR about the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:504 @ 04/20/26 19:45:21.367&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:530 @ 04/20/26 19:45:21.367&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:546 @ 04/20/26 19:45:21.367&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged does not have expiration set [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:552 @ 04/20/26 19:45:21.367&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged After updating image visibility to private, it should not trigger another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:564 @ 04/20/26 19:45:21.367&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged image repo is updated to private [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:595 @ 04/20/26 19:45:21.368&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged retrigger the pipeline manually [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged retriggered pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the component is removed and recreated (with the same name in the same namespace) should no longer lead to a creation of a PaC PR [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/pac_build.go:715 @ 04/20/26 19:45:21.368&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification verifies that the ReleasePlan CR is unmatched in the beginning [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="59.550017315">
              <system-err>&gt; Enter [BeforeAll] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:32 @ 04/20/26 19:14:00.557&#xA;&lt; Exit [BeforeAll] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:32 @ 04/20/26 19:15:00.077 (59.52s)&#xA;&gt; Enter [It] verifies that the ReleasePlan CR is unmatched in the beginning - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:57 @ 04/20/26 19:15:00.077&#xA;&lt; Exit [It] verifies that the ReleasePlan CR is unmatched in the beginning - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:57 @ 04/20/26 19:15:00.107 (30ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.107&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.107 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification Creates ReleasePlanAdmission CR in corresponding managed namespace [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="0.079071803">
              <system-err>&gt; Enter [It] Creates ReleasePlanAdmission CR in corresponding managed namespace - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:72 @ 04/20/26 19:15:00.107&#xA;&lt; Exit [It] Creates ReleasePlanAdmission CR in corresponding managed namespace - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:72 @ 04/20/26 19:15:00.186 (79ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.186&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.186 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when ReleasePlanAdmission CR is created in managed namespace verifies that the ReleasePlan CR is set to matched [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="0.192918216">
              <system-err>&gt; Enter [It] verifies that the ReleasePlan CR is set to matched - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:85 @ 04/20/26 19:15:00.187&#xA;&lt; Exit [It] verifies that the ReleasePlan CR is set to matched - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:85 @ 04/20/26 19:15:00.379 (193ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.379&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.38 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when ReleasePlanAdmission CR is created in managed namespace verifies that the ReleasePlanAdmission CR is set to matched [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="0.076779305">
              <system-err>&gt; Enter [It] verifies that the ReleasePlanAdmission CR is set to matched - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:105 @ 04/20/26 19:15:00.38&#xA;&lt; Exit [It] verifies that the ReleasePlanAdmission CR is set to matched - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:105 @ 04/20/26 19:15:00.456 (76ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.457&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.457 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification Creates a manual release ReleasePlan CR in devNamespace [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="0.059539849">
              <system-err>&gt; Enter [It] Creates a manual release ReleasePlan CR in devNamespace - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:123 @ 04/20/26 19:15:00.457&#xA;&lt; Exit [It] Creates a manual release ReleasePlan CR in devNamespace - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:123 @ 04/20/26 19:15:00.516 (59ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.517&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.517 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when the second ReleasePlan CR is created verifies that the second ReleasePlan CR is set to matched [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="0.17022683">
              <system-err>&gt; Enter [It] verifies that the second ReleasePlan CR is set to matched - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:129 @ 04/20/26 19:15:00.517&#xA;&lt; Exit [It] verifies that the second ReleasePlan CR is set to matched - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:129 @ 04/20/26 19:15:00.687 (170ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.687&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.687 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when the second ReleasePlan CR is created verifies that the ReleasePlanAdmission CR has two matched ReleasePlan CRs [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="0.016331722">
              <system-err>&gt; Enter [It] verifies that the ReleasePlanAdmission CR has two matched ReleasePlan CRs - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:150 @ 04/20/26 19:15:00.688&#xA;&lt; Exit [It] verifies that the ReleasePlanAdmission CR has two matched ReleasePlan CRs - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:150 @ 04/20/26 19:15:00.704 (16ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.704&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.704 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification deletes one ReleasePlan CR [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="0.05685483">
              <system-err>&gt; Enter [It] deletes one ReleasePlan CR - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:171 @ 04/20/26 19:15:00.705&#xA;&lt; Exit [It] deletes one ReleasePlan CR - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:171 @ 04/20/26 19:15:00.761 (57ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.761&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.761 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when One ReleasePlan CR is deleted in managed namespace verifies that the ReleasePlanAdmission CR has only one matching ReleasePlan [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="0.037407687">
              <system-err>&gt; Enter [It] verifies that the ReleasePlanAdmission CR has only one matching ReleasePlan - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:177 @ 04/20/26 19:15:00.762&#xA;&lt; Exit [It] verifies that the ReleasePlanAdmission CR has only one matching ReleasePlan - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:177 @ 04/20/26 19:15:00.799 (37ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.799&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.799 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification deletes the ReleasePlanAdmission CR [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="0.055305249">
              <system-err>&gt; Enter [It] deletes the ReleasePlanAdmission CR - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:198 @ 04/20/26 19:15:00.8&#xA;&lt; Exit [It] deletes the ReleasePlanAdmission CR - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:198 @ 04/20/26 19:15:00.855 (55ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.855&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.855 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when ReleasePlanAdmission CR is deleted in managed namespace verifies that the ReleasePlan CR has no matched ReleasePlanAdmission [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="passed" time="24.188162464">
              <system-err>&gt; Enter [It] verifies that the ReleasePlan CR has no matched ReleasePlanAdmission - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:204 @ 04/20/26 19:15:00.855&#xA;&lt; Exit [It] verifies that the ReleasePlan CR has no matched ReleasePlanAdmission - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:204 @ 04/20/26 19:15:00.878 (23ms)&#xA;&gt; Enter [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.878&#xA;&lt; Exit [AfterEach] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:30 @ 04/20/26 19:15:00.878 (0s)&#xA;&gt; Enter [AfterAll] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:48 @ 04/20/26 19:15:00.878&#xA;&lt; Exit [AfterAll] [release-service-suite ReleasePlan and ReleasePlanAdmission match] - /tmp/tmp.VA2UVYReoU/tests/release/service/release_plan_and_admission_matched.go:48 @ 04/20/26 19:15:25.043 (24.165s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace creates component with context directory go-component [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="passed" time="22.433652173">
              <system-err>&gt; Enter [BeforeAll] test pac with multiple components using same repository - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:40 @ 04/20/26 19:15:25.044&#xA;&lt; Exit [BeforeAll] test pac with multiple components using same repository - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:40 @ 04/20/26 19:15:27.363 (2.319s)&#xA;&gt; Enter [It] creates component with context directory go-component - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:106 @ 04/20/26 19:15:27.363&#xA;Image repository for component go-component-nofrer in namespace build-e2e-yxit do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Image repository for component go-component-nofrer in namespace build-e2e-yxit do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [It] creates component with context directory go-component - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:106 @ 04/20/26 19:15:47.477 (20.114s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:28 @ 04/20/26 19:15:47.478&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:28 @ 04/20/26 19:15:47.478 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace triggers a PipelineRun for component go-component-nofrer [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="failed" time="1802.110444682">
              <failure message="Timed out after 1800.001s.&#xA;timed out when waiting for the PipelineRun to start for the component go-component-nofrer/build-e2e-yxit&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc0014fa0e0&gt;: &#xA;    no pipelinerun found for component go-component-nofrer&#xA;    {&#xA;        s: &#34;no pipelinerun found for component go-component-nofrer&#34;,&#xA;    }" type="failed">[FAILED] Timed out after 1800.001s.&#xA;timed out when waiting for the PipelineRun to start for the component go-component-nofrer/build-e2e-yxit&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc0014fa0e0&gt;: &#xA;    no pipelinerun found for component go-component-nofrer&#xA;    {&#xA;        s: &#34;no pipelinerun found for component go-component-nofrer&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:137 @ 04/20/26 19:45:47.479&#xA;</failure>
              <system-err>&gt; Enter [It] triggers a PipelineRun for component go-component-nofrer - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:125 @ 04/20/26 19:15:47.478&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;PipelineRun has not been created yet for the component build-e2e-yxit/go-component-nofrer&#xA;[FAILED] Timed out after 1800.001s.&#xA;timed out when waiting for the PipelineRun to start for the component go-component-nofrer/build-e2e-yxit&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc0014fa0e0&gt;: &#xA;    no pipelinerun found for component go-component-nofrer&#xA;    {&#xA;        s: &#34;no pipelinerun found for component go-component-nofrer&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:137 @ 04/20/26 19:45:47.479&#xA;&lt; Exit [It] triggers a PipelineRun for component go-component-nofrer - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:125 @ 04/20/26 19:45:47.479 (30m0.001s)&#xA;&gt; Enter [AfterAll] test pac with multiple components using same repository - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:68 @ 04/20/26 19:45:47.479&#xA;&lt; Exit [AfterAll] test pac with multiple components using same repository - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:68 @ 04/20/26 19:45:49.36 (1.88s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:28 @ 04/20/26 19:45:49.36&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:28 @ 04/20/26 19:45:49.588 (228ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace should lead to a PaC PR creation for component go-component-nofrer [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:140 @ 04/20/26 19:45:49.589&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace the PipelineRun should eventually finish successfully for component go-component-nofrer [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:159 @ 04/20/26 19:45:49.589&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace merging the PR should be successful [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:164 @ 04/20/26 19:45:49.59&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace leads to triggering on push PipelineRun [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:174 @ 04/20/26 19:45:49.59&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace creates component with context directory python-component [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:106 @ 04/20/26 19:45:49.59&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace triggers a PipelineRun for component python-component-pzktwc [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:125 @ 04/20/26 19:45:49.59&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace should lead to a PaC PR creation for component python-component-pzktwc [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:140 @ 04/20/26 19:45:49.59&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace the PipelineRun should eventually finish successfully for component python-component-pzktwc [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:159 @ 04/20/26 19:45:49.59&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace merging the PR should be successful [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:164 @ 04/20/26 19:45:49.591&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace leads to triggering on push PipelineRun [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:174 @ 04/20/26 19:45:49.591&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace only one component is changed [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:190 @ 04/20/26 19:45:49.591&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace only related pipelinerun should be triggered [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:205 @ 04/20/26 19:45:49.591&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when a components is created with same git url in different namespace should fail to configure PaC for the component [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/multi_component.go:264 @ 04/20/26 19:45:49.591&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace creates component with nudges [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="passed" time="114.582051862">
              <system-err>&gt; Enter [BeforeAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:72 @ 04/20/26 19:14:00.557&#xA;ReleaseAdmissionPlan data: {&#34;Mapping&#34;:{&#34;Components&#34;:[{&#34;Name&#34;:&#34;gh-multi-component-parent-riev&#34;,&#34;Repository&#34;:&#34;quay.io/redhat-appstudio-qe/release-repository&#34;}]}}&#xA;&lt; Exit [BeforeAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:72 @ 04/20/26 19:15:05.045 (1m4.488s)&#xA;&gt; Enter [It] creates component with nudges - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:235 @ 04/20/26 19:15:05.046&#xA;Image repository for component gh-multi-component-child-riev in namespace build-e2e-jqfz do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Image repository for component gh-multi-component-child-riev in namespace build-e2e-jqfz do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Image repository for component gh-multi-component-parent-riev in namespace build-e2e-jqfz do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Image repository for component gh-multi-component-parent-riev in namespace build-e2e-jqfz do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [It] creates component with nudges - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:235 @ 04/20/26 19:15:55.139 (50.093s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:15:55.139&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:15:55.139 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace triggers a PipelineRun for parent component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="failed" time="1817.224698172">
              <failure message="Timed out after 1800.001s.&#xA;timed out when waiting for the PipelineRun to start for the component gh-multi-component-parent-riev/build-e2e-jqfz&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00088b1f0&gt;: &#xA;    no pipelinerun found for component gh-multi-component-parent-riev&#xA;    {&#xA;        s: &#34;no pipelinerun found for component gh-multi-component-parent-riev&#34;,&#xA;    }" type="failed">[FAILED] Timed out after 1800.001s.&#xA;timed out when waiting for the PipelineRun to start for the component gh-multi-component-parent-riev/build-e2e-jqfz&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00088b1f0&gt;: &#xA;    no pipelinerun found for component gh-multi-component-parent-riev&#xA;    {&#xA;        s: &#34;no pipelinerun found for component gh-multi-component-parent-riev&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:272 @ 04/20/26 19:45:55.141&#xA;</failure>
              <system-err>&gt; Enter [It] triggers a PipelineRun for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:259 @ 04/20/26 19:15:55.14&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;PipelineRun has not been created yet for the component build-e2e-jqfz/gh-multi-component-parent-riev&#xA;[FAILED] Timed out after 1800.001s.&#xA;timed out when waiting for the PipelineRun to start for the component gh-multi-component-parent-riev/build-e2e-jqfz&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00088b1f0&gt;: &#xA;    no pipelinerun found for component gh-multi-component-parent-riev&#xA;    {&#xA;        s: &#34;no pipelinerun found for component gh-multi-component-parent-riev&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:272 @ 04/20/26 19:45:55.141&#xA;&lt; Exit [It] triggers a PipelineRun for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:259 @ 04/20/26 19:45:55.141 (30m0.001s)&#xA;&gt; Enter [AfterAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:214 @ 04/20/26 19:45:55.141&#xA;&lt; Exit [AfterAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:214 @ 04/20/26 19:46:12.182 (17.041s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:46:12.183&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:46:12.364 (182ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for parent component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:274 @ 04/20/26 19:46:12.365&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for child component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:285 @ 04/20/26 19:46:12.365&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace should lead to a PaC PR creation for child component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:289 @ 04/20/26 19:46:12.365&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace Merging the PaC PR should be successful for child component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:307 @ 04/20/26 19:46:12.365&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace create dockerfile and yaml manifest that references build and distribution repositories [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:318 @ 04/20/26 19:46:12.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace should lead to a PaC PR creation for parent component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:358 @ 04/20/26 19:46:12.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace Merging the PaC PR should be successful for parent component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:375 @ 04/20/26 19:46:12.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace PR merge triggers PAC PipelineRun for parent component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:385 @ 04/20/26 19:46:12.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace PAC PipelineRun for parent component  is successful [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:401 @ 04/20/26 19:46:12.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace should lead to a nudge PR creation for child component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:412 @ 04/20/26 19:46:12.366&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace merging the PR should be successful for child component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:429 @ 04/20/26 19:46:12.367&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace Verify the nudge updated the contents [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:440 @ 04/20/26 19:46:12.367&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace creates component with nudges [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="96.263897216">
              <system-err>&gt; Enter [BeforeAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:72 @ 04/20/26 19:14:00.557&#xA;ReleaseAdmissionPlan data: {&#34;Mapping&#34;:{&#34;Components&#34;:[{&#34;Name&#34;:&#34;gl-multi-component-parent-rsqv&#34;,&#34;Repository&#34;:&#34;quay.io/redhat-appstudio-qe/release-repository&#34;}]}}&#xA;&lt; Exit [BeforeAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:72 @ 04/20/26 19:14:56.621 (56.063s)&#xA;&gt; Enter [It] creates component with nudges - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:235 @ 04/20/26 19:14:56.621&#xA;Image repository for component gl-multi-component-child-rsqv in namespace build-e2e-zttd do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;Image repository for component gl-multi-component-parent-rsqv in namespace build-e2e-zttd do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [It] creates component with nudges - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:235 @ 04/20/26 19:15:36.821 (40.2s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:15:36.821&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:15:36.821 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace triggers a PipelineRun for parent component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="100.069465241">
              <system-err>&gt; Enter [It] triggers a PipelineRun for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:259 @ 04/20/26 19:15:36.822&#xA;PipelineRun has not been created yet for the component build-e2e-zttd/gl-multi-component-parent-rsqv&#xA;PipelineRun has not been created yet for the component build-e2e-zttd/gl-multi-component-parent-rsqv&#xA;PipelineRun has not been created yet for the component build-e2e-zttd/gl-multi-component-parent-rsqv&#xA;PipelineRun has not been created yet for the component build-e2e-zttd/gl-multi-component-parent-rsqv&#xA;PipelineRun has not been created yet for the component build-e2e-zttd/gl-multi-component-parent-rsqv&#xA;&lt; Exit [It] triggers a PipelineRun for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:259 @ 04/20/26 19:17:16.891 (1m40.069s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:17:16.891&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:17:16.891 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for parent component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="611.353210889">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish successfully for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:274 @ 04/20/26 19:17:16.892&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 found for Component build-e2e-zttd/gl-multi-component-parent-rsqv&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: PipelineRunStopping&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-wl4b4 reason: Failed&#xA;attempt 1/3: PipelineRun &#34;gl-multi-component-parent-rsqv-on-pull-request-wl4b4&#34; failed: &#xA; pod: gl-multi-component-parent-rsqv-on-pull-request-wl4b4-init-pod | init container: prepare&#xA;2026/04/20 19:17:06 Entrypoint initialization&#xA;&#xA;pod: gl-multi-component-parent-rsqv-on-pull-request-wl4b4-init-pod | container step-init: &#xA;time=&#34;2026-04-20T19:17:09Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-20T19:17:09Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-20T19:17:09Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-20T19:17:09Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-20T19:17:09Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-20T19:17:09Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-20T19:17:09Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-20T19:17:09Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-20T19:17:09Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;New PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt found after retrigger for component build-e2e-zttd/gl-multi-component-parent-rsqv&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt found for Component build-e2e-zttd/gl-multi-component-parent-rsqv&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-pull-request-867bt reason: Succeeded&#xA;&lt; Exit [It] the PipelineRun should eventually finish successfully for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:274 @ 04/20/26 19:27:28.244 (10m11.353s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:27:28.245&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:27:28.245 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for child component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="271.364988247">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish successfully for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:285 @ 04/20/26 19:27:28.245&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-fwrd2 found for Component build-e2e-zttd/gl-multi-component-child-rsqv&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-fwrd2 reason: Cancelled&#xA;attempt 1/3: PipelineRun &#34;gl-multi-component-child-rsqv-on-pull-request-fwrd2&#34; failed: &#xA; pod: gl-multi-component-child-rsqv-on-pull-request-vfwj8-init-pod | init container: prepare&#xA;2026/04/20 19:16:30 Entrypoint initialization&#xA;&#xA;pod: gl-multi-component-child-rsqv-on-pull-request-vfwj8-init-pod | container step-init: &#xA;time=&#34;2026-04-20T19:16:32Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-20T19:16:32Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-20T19:16:32Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-20T19:16:32Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-20T19:16:32Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-20T19:16:32Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-20T19:16:32Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-20T19:16:32Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-20T19:16:32Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;New PipelineRun gl-multi-component-child-rsqv-on-pull-request-vfwj8 found after retrigger for component build-e2e-zttd/gl-multi-component-child-rsqv&#xA;PipelineRun has not been created yet for the Component build-e2e-zttd/gl-multi-component-child-rsqv&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw found for Component build-e2e-zttd/gl-multi-component-child-rsqv&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Running&#xA;PipelineRun gl-multi-component-child-rsqv-on-pull-request-d27mw reason: Succeeded&#xA;&lt; Exit [It] the PipelineRun should eventually finish successfully for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:285 @ 04/20/26 19:31:59.61 (4m31.365s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:31:59.61&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:31:59.61 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace should lead to a PaC PR creation for child component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="0.267199881">
              <system-err>&gt; Enter [It] should lead to a PaC PR creation for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:289 @ 04/20/26 19:31:59.611&#xA;&lt; Exit [It] should lead to a PaC PR creation for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:289 @ 04/20/26 19:31:59.877 (267ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:31:59.878&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:31:59.878 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace Merging the PaC PR should be successful for child component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="1.289315731">
              <system-err>&gt; Enter [It] Merging the PaC PR should be successful for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:307 @ 04/20/26 19:31:59.878&#xA;merged result sha: c4a59f8c6d74779020b465ad9faa1279485890b2 for PR #1&#xA;&lt; Exit [It] Merging the PaC PR should be successful for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:307 @ 04/20/26 19:32:01.167 (1.289s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:32:01.167&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:32:01.167 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace create dockerfile and yaml manifest that references build and distribution repositories [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="65.614189478">
              <system-err>&gt; Enter [It] create dockerfile and yaml manifest that references build and distribution repositories - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:318 @ 04/20/26 19:32:01.168&#xA;&lt; Exit [It] create dockerfile and yaml manifest that references build and distribution repositories - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:318 @ 04/20/26 19:33:06.782 (1m5.614s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:33:06.782&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:33:06.782 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace should lead to a PaC PR creation for parent component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="0.216226649">
              <system-err>&gt; Enter [It] should lead to a PaC PR creation for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:358 @ 04/20/26 19:33:06.783&#xA;&lt; Exit [It] should lead to a PaC PR creation for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:358 @ 04/20/26 19:33:06.998 (216ms)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:33:06.999&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:33:06.999 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace Merging the PaC PR should be successful for parent component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="1.278707155">
              <system-err>&gt; Enter [It] Merging the PaC PR should be successful for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:375 @ 04/20/26 19:33:06.999&#xA;merged result sha: 8c6aa7dd567cd31476cd2229c2c66476f226b9a0 for PR #1&#xA;&lt; Exit [It] Merging the PaC PR should be successful for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:375 @ 04/20/26 19:33:08.278 (1.278s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:33:08.278&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:33:08.278 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace PR merge triggers PAC PipelineRun for parent component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="20.04989198">
              <system-err>&gt; Enter [It] PR merge triggers PAC PipelineRun for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:385 @ 04/20/26 19:33:08.279&#xA;Push PipelineRun has not been created yet for the component build-e2e-zttd/gl-multi-component-parent-rsqv&#xA;&lt; Exit [It] PR merge triggers PAC PipelineRun for parent component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:385 @ 04/20/26 19:33:28.328 (20.05s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:33:28.328&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:33:28.328 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace PAC PipelineRun for parent component  is successful [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="passed" time="260.020429705">
              <system-err>&gt; Enter [It] PAC PipelineRun for parent component  is successful - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:401 @ 04/20/26 19:33:28.329&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh found for Component build-e2e-zttd/gl-multi-component-parent-rsqv&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Running&#xA;PipelineRun gl-multi-component-parent-rsqv-on-push-czzxh reason: Succeeded&#xA;&lt; Exit [It] PAC PipelineRun for parent component  is successful - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:401 @ 04/20/26 19:37:48.349 (4m20.02s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:37:48.349&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:37:48.349 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace should lead to a nudge PR creation for child component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="failed" time="1216.358524616">
              <failure message="Timed out after 1200.000s.&#xA;timed out when waiting for component nudge PR to be created in build-nudge-child-evhllx repository&#xA;Expected&#xA;    &lt;bool&gt;: false&#xA;to be true" type="failed">[FAILED] Timed out after 1200.000s.&#xA;timed out when waiting for component nudge PR to be created in build-nudge-child-evhllx repository&#xA;Expected&#xA;    &lt;bool&gt;: false&#xA;to be true&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:427 @ 04/20/26 19:57:48.35&#xA;</failure>
              <system-err>&gt; Enter [It] should lead to a nudge PR creation for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:412 @ 04/20/26 19:37:48.35&#xA;[FAILED] Timed out after 1200.000s.&#xA;timed out when waiting for component nudge PR to be created in build-nudge-child-evhllx repository&#xA;Expected&#xA;    &lt;bool&gt;: false&#xA;to be true&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:427 @ 04/20/26 19:57:48.35&#xA;&lt; Exit [It] should lead to a nudge PR creation for child component  - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:412 @ 04/20/26 19:57:48.35 (20m0.001s)&#xA;&gt; Enter [AfterAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:214 @ 04/20/26 19:57:48.351&#xA;&lt; Exit [AfterAll] component update with renovate - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:214 @ 04/20/26 19:58:04.425 (16.075s)&#xA;&gt; Enter [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:58:04.426&#xA;&lt; Exit [AfterEach] [build-service-suite Build service E2E tests] - /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:28 @ 04/20/26 19:58:04.708 (282ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace merging the PR should be successful for child component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:429 @ 04/20/26 19:58:04.709&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace Verify the nudge updated the contents [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.VA2UVYReoU/tests/build/renovate.go:440 @ 04/20/26 19:58:04.709&#xA;</system-err>
          </testcase>
      </testsuite>
  </testsuites>