Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-gomod/component-prefetch-gomod Running clair-action on amd64 image manifest... 2026/08/18 04:48:59 INFO matchers created matcher.alpine-matcher=https://pkg.go.dev/github.com/quay/claircore/alpine matcher.aws-matcher=https://pkg.go.dev/github.com/quay/claircore/aws matcher.debian-matcher=https://pkg.go.dev/github.com/quay/claircore/debian matcher.photon=https://pkg.go.dev/github.com/quay/claircore/photon matcher.python=https://pkg.go.dev/github.com/quay/claircore/python matcher.gobin=https://pkg.go.dev/github.com/quay/claircore/gobin matcher.ruby-gem=https://pkg.go.dev/github.com/quay/claircore/ruby matcher.rhel=https://pkg.go.dev/github.com/quay/claircore/rhel matcher.oracle=https://pkg.go.dev/github.com/quay/claircore/oracle matcher.ubuntu-matcher=https://pkg.go.dev/github.com/quay/claircore/ubuntu matcher.java-maven=https://pkg.go.dev/github.com/quay/claircore/java matcher.rhel-container-matcher=https://pkg.go.dev/github.com/quay/claircore/rhel/rhcc matcher.suse=https://pkg.go.dev/github.com/quay/claircore/suse 2026/08/18 04:48:59 INFO vex factory configured base_url=https://security.access.redhat.com/data/csaf/v2/vex/ compressed_file_timeout=2m0s 2026/08/18 04:48:59 INFO libvuln initialized 2026/08/18 04:48:59 INFO registered configured scanners 2026/08/18 04:48:59 INFO constructing 2026/08/18 04:48:59 INFO index request start 2026/08/18 04:48:59 INFO starting scan 2026/08/18 04:48:59 INFO manifest to be scanned 2026/08/18 04:48:59 INFO layers fetch start 2026/08/18 04:49:00 INFO layers fetch success 2026/08/18 04:49:00 INFO layers fetch done 2026/08/18 04:49:00 INFO layers scan start 2026/08/18 04:49:00 INFO found buildinfo Dockerfile path=root/buildinfo/Dockerfile-ubi8-minimal-8.6-751 2026/08/18 04:49:01 WARN rpm source packages always record 0 epoch; this may cause incorrect matching see-also="https://github.com/rpm-software-management/rpm/issues/2796 https://github.com/rpm-software-management/rpm/discussions/3703 https://github.com/rpm-software-management/rpm/pull/3755" 2026/08/18 04:49:01 INFO layers scan done 2026/08/18 04:49:01 INFO starting index manifest 2026/08/18 04:49:01 INFO finishing scan 2026/08/18 04:49:01 INFO manifest successfully scanned 2026/08/18 04:49:01 INFO index request done { "manifest_hash": "sha256:b74023f00f63c65f8e9c8b1f6e1236cf361e6a3943e4723f5cbf4f56dfe97a30", "packages": { "+XM+s3niWaEk1U5jnR5DpA==": { "id": "+XM+s3niWaEk1U5jnR5DpA==", "name": "libyaml", "version": "0.1.7-5.el8", "kind": "binary", "source": { "id": "", "name": "libyaml", "version": "0.1.7-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "+Xr7HyTxXf0c8jLaUyo3xA==": { "id": "+Xr7HyTxXf0c8jLaUyo3xA==", "name": "libidn2", "version": "2.2.0-1.el8", "kind": "binary", "source": { "id": "", "name": "libidn2", "version": "2.2.0-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "+oTt3EDPSdSzupH3D6G0BA==": { "id": "+oTt3EDPSdSzupH3D6G0BA==", "name": "lz4-libs", "version": "1.8.3-3.el8_4", "kind": "binary", "source": { "id": "", "name": "lz4", "version": "1.8.3-3.el8_4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "0x/GRqZgisb/k2Y9co6i/Q==": { "id": "0x/GRqZgisb/k2Y9co6i/Q==", "name": "setup", "version": "2.12.2-6.el8", "kind": "binary", "source": { "id": "", "name": "setup", "version": "2.12.2-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "1gormAsAjMuks2JveQRd0Q==": { "id": "1gormAsAjMuks2JveQRd0Q==", "name": "gobject-introspection", "version": "1.56.1-1.el8", "kind": "binary", "source": { "id": "", "name": "gobject-introspection", "version": "1.56.1-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "2MdeoPFfsUv55LlpgwkOkQ==": { "id": "2MdeoPFfsUv55LlpgwkOkQ==", "name": "stdlib", "version": "1.17.12", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "semver:0.1.17.12.0.0.0.0.0.0", "cpe": "", "detector": null }, "2k8BSFOOZ2ndA++n5wl4TA==": { "id": "2k8BSFOOZ2ndA++n5wl4TA==", "name": "glibc-common", "version": "2.28-189.1.el8", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.28-189.1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "2w5sZgHYUcx7+6n/wISUjw==": { "id": "2w5sZgHYUcx7+6n/wISUjw==", "name": "tzdata", "version": "2022a-1.el8", "kind": "binary", "source": { "id": "", "name": "tzdata", "version": "2022a-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "3uSX4NgBxQvC8LEk48QoOQ==": { "id": "3uSX4NgBxQvC8LEk48QoOQ==", "name": "cyrus-sasl-lib", "version": "2.1.27-6.el8_5", "kind": "binary", "source": { "id": "", "name": "cyrus-sasl", "version": "2.1.27-6.el8_5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "45rvgYmy022Tx6fVWfking==": { "id": "45rvgYmy022Tx6fVWfking==", "name": "publicsuffix-list-dafsa", "version": "20180723-1.el8", "kind": "binary", "source": { "id": "", "name": "publicsuffix-list", "version": "20180723-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "47OMpR7yEmE4lttsyWq3fw==": { "id": "47OMpR7yEmE4lttsyWq3fw==", "name": "libusbx", "version": "1.0.23-4.el8", "kind": "binary", "source": { "id": "", "name": "libusbx", "version": "1.0.23-4.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "5Mcqv1rmwAoEs983fcq1cg==": { "id": "5Mcqv1rmwAoEs983fcq1cg==", "name": "glibc", "version": "2.28-189.1.el8", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.28-189.1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "6KnijwRsfeerWmf5Zl8NWw==": { "id": "6KnijwRsfeerWmf5Zl8NWw==", "name": "sed", "version": "4.5-5.el8", "kind": "binary", "source": { "id": "", "name": "sed", "version": "4.5-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "6Tp9WGakxVaQJ9rGhrsxpw==": { "id": "6Tp9WGakxVaQJ9rGhrsxpw==", "name": "krb5-libs", "version": "1.18.2-14.el8", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.18.2-14.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "6dlkQEp2PtZPvC6f+1oBaA==": { "id": "6dlkQEp2PtZPvC6f+1oBaA==", "name": "bzip2-libs", "version": "1.0.6-26.el8", "kind": "binary", "source": { "id": "", "name": "bzip2", "version": "1.0.6-26.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "6mY62Fou7cJqqLJXm9hzXg==": { "id": "6mY62Fou7cJqqLJXm9hzXg==", "name": "gnupg2", "version": "2.2.20-2.el8", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.20-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "7DrAZ2wgIzOquNCQMEVChw==": { "id": "7DrAZ2wgIzOquNCQMEVChw==", "name": "golang.org/x/tools", "version": "v0.0.0-20190325161752-5a8dccf5b48a", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "semver:0.0.0.0.0.0.0.0.0.0", "cpe": "", "detector": null }, "9CuK4fRE5gzOSWH5fqWZJw==": { "id": "9CuK4fRE5gzOSWH5fqWZJw==", "name": "sqlite-libs", "version": "3.26.0-15.el8", "kind": "binary", "source": { "id": "", "name": "sqlite", "version": "3.26.0-15.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "9c4B7Edcs6gS7zy4kBT4Jw==": { "id": "9c4B7Edcs6gS7zy4kBT4Jw==", "name": "libarchive", "version": "3.3.3-3.el8_5", "kind": "binary", "source": { "id": "", "name": "libarchive", "version": "3.3.3-3.el8_5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "BPD4nm0V1xem9/HmmAnFiA==": { "id": "BPD4nm0V1xem9/HmmAnFiA==", "name": "libcom_err", "version": "1.45.6-4.el8", "kind": "binary", "source": { "id": "", "name": "e2fsprogs", "version": "1.45.6-4.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "BmK1zIjr5KsuOODCYwxRCw==": { "id": "BmK1zIjr5KsuOODCYwxRCw==", "name": "libpsl", "version": "0.20.2-6.el8", "kind": "binary", "source": { "id": "", "name": "libpsl", "version": "0.20.2-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "BrxW5JNpEdvbkoGRXbVirw==": { "id": "BrxW5JNpEdvbkoGRXbVirw==", "name": "libssh-config", "version": "0.9.6-3.el8", "kind": "binary", "source": { "id": "", "name": "libssh", "version": "0.9.6-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "Bt7v/jLkw1CWEjQhzP+6Ew==": { "id": "Bt7v/jLkw1CWEjQhzP+6Ew==", "name": "openldap", "version": "2.4.46-18.el8", "kind": "binary", "source": { "id": "", "name": "openldap", "version": "2.4.46-18.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "CbI8d0OI9wvrtddD/Wg0GA==": { "id": "CbI8d0OI9wvrtddD/Wg0GA==", "name": "libblkid", "version": "2.32.1-35.el8", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.32.1-35.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Ce3Eu6RmZkiUW2to8Kec/w==": { "id": "Ce3Eu6RmZkiUW2to8Kec/w==", "name": "libtasn1", "version": "4.13-3.el8", "kind": "binary", "source": { "id": "", "name": "libtasn1", "version": "4.13-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "D/ASdBsgxLNlG5Q8U7UPsQ==": { "id": "D/ASdBsgxLNlG5Q8U7UPsQ==", "name": "rootfiles", "version": "8.1-22.el8", "kind": "binary", "source": { "id": "", "name": "rootfiles", "version": "8.1-22.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "Du+GhNFjWqhCLFNpPgD/Xw==": { "id": "Du+GhNFjWqhCLFNpPgD/Xw==", "name": "github.com/release-engineering/retrodep/v2", "version": "(devel)", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "cpe": "", "detector": null }, "EhXwf9CihVVBNVLvlss3Vg==": { "id": "EhXwf9CihVVBNVLvlss3Vg==", "name": "gpgme", "version": "1.13.1-11.el8", "kind": "binary", "source": { "id": "", "name": "gpgme", "version": "1.13.1-11.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "F7AOP7tK5AfUXV1g9iTzFA==": { "id": "F7AOP7tK5AfUXV1g9iTzFA==", "name": "mpfr", "version": "3.1.6-1.el8", "kind": "binary", "source": { "id": "", "name": "mpfr", "version": "3.1.6-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "F8J7f4sv3sY7BmdP80pHcQ==": { "id": "F8J7f4sv3sY7BmdP80pHcQ==", "name": "redhat-release", "version": "8.6-0.1.el8", "kind": "binary", "source": { "id": "", "name": "redhat-release", "version": "8.6-0.1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "FTEArHfNxv8mTCM/rtN+pw==": { "id": "FTEArHfNxv8mTCM/rtN+pw==", "name": "libverto", "version": "0.3.0-5.el8", "kind": "binary", "source": { "id": "", "name": "libverto", "version": "0.3.0-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "FdB9K1+1CEpzAW4zwkaAGw==": { "id": "FdB9K1+1CEpzAW4zwkaAGw==", "name": "libcurl", "version": "7.61.1-22.el8", "kind": "binary", "source": { "id": "", "name": "curl", "version": "7.61.1-22.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "GLKhGblbPbPbtDKwfpCv5A==": { "id": "GLKhGblbPbPbtDKwfpCv5A==", "name": "filesystem", "version": "3.8-6.el8", "kind": "binary", "source": { "id": "", "name": "filesystem", "version": "3.8-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Gg1Q6hponuT1eSJHwaJ83w==": { "id": "Gg1Q6hponuT1eSJHwaJ83w==", "name": "libcap-ng", "version": "0.7.11-1.el8", "kind": "binary", "source": { "id": "", "name": "libcap-ng", "version": "0.7.11-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "GlWFSNV8QxYx5o3TOWf+IA==": { "id": "GlWFSNV8QxYx5o3TOWf+IA==", "name": "xz-libs", "version": "5.2.4-3.el8", "kind": "binary", "source": { "id": "", "name": "xz", "version": "5.2.4-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "HMIoZ/TKrKhxI1rD26qmpw==": { "id": "HMIoZ/TKrKhxI1rD26qmpw==", "name": "json-c", "version": "0.13.1-3.el8", "kind": "binary", "source": { "id": "", "name": "json-c", "version": "0.13.1-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "HkH7JOZ7zVk8ggpmKHnMxg==": { "id": "HkH7JOZ7zVk8ggpmKHnMxg==", "name": "rpm-libs", "version": "4.14.3-23.el8", "kind": "binary", "source": { "id": "", "name": "rpm", "version": "4.14.3-23.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Hr1TetfTnCbToWK+Q1/NLw==": { "id": "Hr1TetfTnCbToWK+Q1/NLw==", "name": "rpm", "version": "4.14.3-23.el8", "kind": "binary", "source": { "id": "", "name": "rpm", "version": "4.14.3-23.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "I+kjs7Yx80eRSvYzDMDQwg==": { "id": "I+kjs7Yx80eRSvYzDMDQwg==", "name": "librepo", "version": "1.14.2-1.el8", "kind": "binary", "source": { "id": "", "name": "librepo", "version": "1.14.2-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "IdaeQutkPjfv4bTMEkXWog==": { "id": "IdaeQutkPjfv4bTMEkXWog==", "name": "libgcrypt", "version": "1.8.5-6.el8", "kind": "binary", "source": { "id": "", "name": "libgcrypt", "version": "1.8.5-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "IzLcxZDtcvtJR5Gwdq9HDg==": { "id": "IzLcxZDtcvtJR5Gwdq9HDg==", "name": "libattr", "version": "2.4.48-3.el8", "kind": "binary", "source": { "id": "", "name": "attr", "version": "2.4.48-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "JC8eNzSj6tieJqNqASET1Q==": { "id": "JC8eNzSj6tieJqNqASET1Q==", "name": "p11-kit", "version": "0.23.22-1.el8", "kind": "binary", "source": { "id": "", "name": "p11-kit", "version": "0.23.22-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "N1RbIRo2SyHosQefv+skDw==": { "id": "N1RbIRo2SyHosQefv+skDw==", "name": "gawk", "version": "4.2.1-4.el8", "kind": "binary", "source": { "id": "", "name": "gawk", "version": "4.2.1-4.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "NJbhst8VIOwst++ZzRP6tA==": { "id": "NJbhst8VIOwst++ZzRP6tA==", "name": "libpeas", "version": "1.22.0-6.el8", "kind": "binary", "source": { "id": "", "name": "libpeas", "version": "1.22.0-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "O63QX7+X9KEjj9ex/GG2aA==": { "id": "O63QX7+X9KEjj9ex/GG2aA==", "name": "libuuid", "version": "2.32.1-35.el8", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.32.1-35.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "P5Se4zJpr8ZUwZNUojfuzA==": { "id": "P5Se4zJpr8ZUwZNUojfuzA==", "name": "libxcrypt", "version": "4.1.1-6.el8", "kind": "binary", "source": { "id": "", "name": "libxcrypt", "version": "4.1.1-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "QGSS5ebqb1I03fCvl2CZWA==": { "id": "QGSS5ebqb1I03fCvl2CZWA==", "name": "ubi8-minimal", "version": "8.6-751", "kind": "ancestry", "source": { "id": "kFL2/mnzbguW53ahZMvxTQ==", "name": "ubi8-minimal-container", "version": "8.6-751", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "rhctag:8.6.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "rhctag:8.6.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "QudMKkcOe80heCvOb+0deQ==": { "id": "QudMKkcOe80heCvOb+0deQ==", "name": "crypto-policies", "version": "20211116-1.gitae470d6.el8", "kind": "binary", "source": { "id": "", "name": "crypto-policies", "version": "20211116-1.gitae470d6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "RtrzwDgrQgu9S5B72s2sww==": { "id": "RtrzwDgrQgu9S5B72s2sww==", "name": "libunistring", "version": "0.9.9-3.el8", "kind": "binary", "source": { "id": "", "name": "libunistring", "version": "0.9.9-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Saan3FOrTRBoLj3w1k+cpw==": { "id": "Saan3FOrTRBoLj3w1k+cpw==", "name": "ubi8-minimal", "version": "8.6-751", "kind": "binary", "source": { "id": "kFL2/mnzbguW53ahZMvxTQ==", "name": "ubi8-minimal-container", "version": "8.6-751", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "rhctag:8.6.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "rhctag:8.6.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "Sg7WHD/cpWdFZ7MyPqITSQ==": { "id": "Sg7WHD/cpWdFZ7MyPqITSQ==", "name": "gmp", "version": "1:6.1.2-10.el8", "kind": "binary", "source": { "id": "", "name": "gmp", "version": "6.1.2-10.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "UKxtVVWEN0LXB/lFG1+5oA==": { "id": "UKxtVVWEN0LXB/lFG1+5oA==", "name": "libsolv", "version": "0.7.20-1.el8", "kind": "binary", "source": { "id": "", "name": "libsolv", "version": "0.7.20-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "USWNn71p+k059dbiu5HDEA==": { "id": "USWNn71p+k059dbiu5HDEA==", "name": "libassuan", "version": "2.5.1-3.el8", "kind": "binary", "source": { "id": "", "name": "libassuan", "version": "2.5.1-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "W66WOQ3v6r7mSn6+o7gaew==": { "id": "W66WOQ3v6r7mSn6+o7gaew==", "name": "popt", "version": "1.18-1.el8", "kind": "binary", "source": { "id": "", "name": "popt", "version": "1.18-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Wnakr8JK5dF9B7cFuYj+LA==": { "id": "Wnakr8JK5dF9B7cFuYj+LA==", "name": "bash", "version": "4.4.20-3.el8", "kind": "binary", "source": { "id": "", "name": "bash", "version": "4.4.20-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "WrV+rIJLRk8b24xMew9Hkg==": { "id": "WrV+rIJLRk8b24xMew9Hkg==", "name": "libksba", "version": "1.3.5-7.el8", "kind": "binary", "source": { "id": "", "name": "libksba", "version": "1.3.5-7.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "XKq3fjedO7d4LSKzSLDcMw==": { "id": "XKq3fjedO7d4LSKzSLDcMw==", "name": "glibc-minimal-langpack", "version": "2.28-189.1.el8", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.28-189.1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "XKv+fGQhqJZl6x7NNqqaaQ==": { "id": "XKv+fGQhqJZl6x7NNqqaaQ==", "name": "libsmartcols", "version": "2.32.1-35.el8", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.32.1-35.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "XVupnfoSG9GJwKd6FSNK8Q==": { "id": "XVupnfoSG9GJwKd6FSNK8Q==", "name": "chkconfig", "version": "1.19.1-1.el8", "kind": "binary", "source": { "id": "", "name": "chkconfig", "version": "1.19.1-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "ZRpVwDgK9rS2HJv/RQ5Gkg==": { "id": "ZRpVwDgK9rS2HJv/RQ5Gkg==", "name": "libgcc", "version": "8.5.0-10.el8", "kind": "binary", "source": { "id": "", "name": "gcc", "version": "8.5.0-10.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "ZeMV+HXeATqaAewlx/gEKw==": { "id": "ZeMV+HXeATqaAewlx/gEKw==", "name": "github.com/Masterminds/semver", "version": "v1.4.2", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "semver:0.1.4.2.0.0.0.0.0.0", "cpe": "", "detector": null }, "aTfPDP7oJqFwbwjiDbCnWA==": { "id": "aTfPDP7oJqFwbwjiDbCnWA==", "name": "ca-certificates", "version": "2021.2.50-80.0.el8_4", "kind": "binary", "source": { "id": "", "name": "ca-certificates", "version": "2021.2.50-80.0.el8_4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "bcw2EOFjnx1wB4M400Jpew==": { "id": "bcw2EOFjnx1wB4M400Jpew==", "name": "gnutls", "version": "3.6.16-4.el8", "kind": "binary", "source": { "id": "", "name": "gnutls", "version": "3.6.16-4.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "bfF0cEWD49u6W/lExfuSww==": { "id": "bfF0cEWD49u6W/lExfuSww==", "name": "openssl-libs", "version": "1:1.1.1k-6.el8_5", "kind": "binary", "source": { "id": "", "name": "openssl", "version": "1.1.1k-6.el8_5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "bmxL3lydQy0yU8g1iBgovg==": { "id": "bmxL3lydQy0yU8g1iBgovg==", "name": "libsepol", "version": "2.9-3.el8", "kind": "binary", "source": { "id": "", "name": "libsepol", "version": "2.9-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "dFKSSJF5WrKg9VsNZqM98g==": { "id": "dFKSSJF5WrKg9VsNZqM98g==", "name": "elfutils-libelf", "version": "0.186-1.el8", "kind": "binary", "source": { "id": "", "name": "elfutils", "version": "0.186-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "dOBT1Qffq44NOVuk9chDyg==": { "id": "dOBT1Qffq44NOVuk9chDyg==", "name": "readline", "version": "7.0-10.el8", "kind": "binary", "source": { "id": "", "name": "readline", "version": "7.0-10.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "eZ7CwFvwDCQu4vzKyuIZgA==": { "id": "eZ7CwFvwDCQu4vzKyuIZgA==", "name": "basesystem", "version": "11-5.el8", "kind": "binary", "source": { "id": "", "name": "basesystem", "version": "11-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "eiOy5bizxjO/psTcJ5Gh+g==": { "id": "eiOy5bizxjO/psTcJ5Gh+g==", "name": "libcap", "version": "2.48-2.el8", "kind": "binary", "source": { "id": "", "name": "libcap", "version": "2.48-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "eiYWF89tQpN/umjL2Ljluw==": { "id": "eiYWF89tQpN/umjL2Ljluw==", "name": "audit-libs", "version": "3.0.7-2.el8.2", "kind": "binary", "source": { "id": "", "name": "audit", "version": "3.0.7-2.el8.2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "ev1iPKY2UXha+ggKYJjsaQ==": { "id": "ev1iPKY2UXha+ggKYJjsaQ==", "name": "libxml2", "version": "2.9.7-13.el8", "kind": "binary", "source": { "id": "", "name": "libxml2", "version": "2.9.7-13.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "fCaP9cdwWsPeqX4J2VgB4g==": { "id": "fCaP9cdwWsPeqX4J2VgB4g==", "name": "github.com/pkg/errors", "version": "v0.8.1", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "semver:0.0.8.1.0.0.0.0.0.0", "cpe": "", "detector": null }, "g146nKetkX1f4hfH1b5RWA==": { "id": "g146nKetkX1f4hfH1b5RWA==", "name": "libdb", "version": "5.3.28-42.el8_4", "kind": "binary", "source": { "id": "", "name": "libdb", "version": "5.3.28-42.el8_4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "gOaN4treTmKK7tU+N6AZ1w==": { "id": "gOaN4treTmKK7tU+N6AZ1w==", "name": "pcre", "version": "8.42-6.el8", "kind": "binary", "source": { "id": "", "name": "pcre", "version": "8.42-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "hcJqCsCpWm+XI9JT6ImS5g==": { "id": "hcJqCsCpWm+XI9JT6ImS5g==", "name": "nettle", "version": "3.4.1-7.el8", "kind": "binary", "source": { "id": "", "name": "nettle", "version": "3.4.1-7.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "hqd/9D+OkW729P80H901pQ==": { "id": "hqd/9D+OkW729P80H901pQ==", "name": "zlib", "version": "1.2.11-18.el8_5", "kind": "binary", "source": { "id": "", "name": "zlib", "version": "1.2.11-18.el8_5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "jtdCxL/eH5JTPcKstKunJg==": { "id": "jtdCxL/eH5JTPcKstKunJg==", "name": "grep", "version": "3.1-6.el8", "kind": "binary", "source": { "id": "", "name": "grep", "version": "3.1-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "k4gCNgIfg7MM/e42ThRx2w==": { "id": "k4gCNgIfg7MM/e42ThRx2w==", "name": "libzstd", "version": "1.4.4-1.el8", "kind": "binary", "source": { "id": "", "name": "zstd", "version": "1.4.4-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "kFL2/mnzbguW53ahZMvxTQ==": { "id": "kFL2/mnzbguW53ahZMvxTQ==", "name": "ubi8-minimal-container", "version": "8.6-751", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "rhctag:8.6.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "lqQ3rJzPTM4e3pH+ravEcw==": { "id": "lqQ3rJzPTM4e3pH+ravEcw==", "name": "brotli", "version": "1.0.6-3.el8", "kind": "binary", "source": { "id": "", "name": "brotli", "version": "1.0.6-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "mAmp7BtGrfzV0HnAKw9sTw==": { "id": "mAmp7BtGrfzV0HnAKw9sTw==", "name": "libsigsegv", "version": "2.11-5.el8", "kind": "binary", "source": { "id": "", "name": "libsigsegv", "version": "2.11-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "mLwCNKs2wEtLWAiibtR4BQ==": { "id": "mLwCNKs2wEtLWAiibtR4BQ==", "name": "microdnf", "version": "3.8.0-2.el8", "kind": "binary", "source": { "id": "", "name": "microdnf", "version": "3.8.0-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "mkd+V76Xxq5AfXbSoR0DMg==": { "id": "mkd+V76Xxq5AfXbSoR0DMg==", "name": "libselinux", "version": "2.9-5.el8", "kind": "binary", "source": { "id": "", "name": "libselinux", "version": "2.9-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "mkledqgVtELsBjGkaINRAg==": { "id": "mkledqgVtELsBjGkaINRAg==", "name": "librhsm", "version": "0.0.3-4.el8", "kind": "binary", "source": { "id": "", "name": "librhsm", "version": "0.0.3-4.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "o4tvrO4Cuc2PXep4Fk53sA==": { "id": "o4tvrO4Cuc2PXep4Fk53sA==", "name": "file-libs", "version": "5.33-20.el8", "kind": "binary", "source": { "id": "", "name": "file", "version": "5.33-20.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "o4v1nyEgxKUJdf78CSzLEg==": { "id": "o4v1nyEgxKUJdf78CSzLEg==", "name": "libgpg-error", "version": "1.31-1.el8", "kind": "binary", "source": { "id": "", "name": "libgpg-error", "version": "1.31-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "oJIAHlP0pGe97iAzAFF0xA==": { "id": "oJIAHlP0pGe97iAzAFF0xA==", "name": "curl", "version": "7.61.1-22.el8", "kind": "binary", "source": { "id": "", "name": "curl", "version": "7.61.1-22.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "p75sU/+cD5K1Jv37jjSsxQ==": { "id": "p75sU/+cD5K1Jv37jjSsxQ==", "name": "ncurses-libs", "version": "6.1-9.20180224.el8", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.1-9.20180224.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "p9tXHgTBVU/b3sTnwfubzg==": { "id": "p9tXHgTBVU/b3sTnwfubzg==", "name": "libdb-utils", "version": "5.3.28-42.el8_4", "kind": "binary", "source": { "id": "", "name": "libdb", "version": "5.3.28-42.el8_4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "pKEOaN2eCFIneHzHE7HYug==": { "id": "pKEOaN2eCFIneHzHE7HYug==", "name": "ncurses-base", "version": "6.1-9.20180224.el8", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.1-9.20180224.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "pY2NT/GP1UxyOuAl2rKgCw==": { "id": "pY2NT/GP1UxyOuAl2rKgCw==", "name": "npth", "version": "1.5-4.el8", "kind": "binary", "source": { "id": "", "name": "npth", "version": "1.5-4.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "qN2fZ3YQPh6iZsfkdV7bIg==": { "id": "qN2fZ3YQPh6iZsfkdV7bIg==", "name": "libdnf", "version": "0.63.0-8.el8", "kind": "binary", "source": { "id": "", "name": "libdnf", "version": "0.63.0-8.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "rFsA2fU/SFo3JGOkxRURTQ==": { "id": "rFsA2fU/SFo3JGOkxRURTQ==", "name": "keyutils-libs", "version": "1.5.10-9.el8", "kind": "binary", "source": { "id": "", "name": "keyutils", "version": "1.5.10-9.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "rYu8Ys1qBj5SKpIdfiIX4Q==": { "id": "rYu8Ys1qBj5SKpIdfiIX4Q==", "name": "gopkg.in/yaml.v2", "version": "v2.2.2", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "semver:0.2.2.2.0.0.0.0.0.0", "cpe": "", "detector": null }, "riulbh7DNxLvW7j4IHJ1VA==": { "id": "riulbh7DNxLvW7j4IHJ1VA==", "name": "libnghttp2", "version": "1.33.0-3.el8_2.1", "kind": "binary", "source": { "id": "", "name": "nghttp2", "version": "1.33.0-3.el8_2.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "rrdnE/YLwpAII45HQiOssw==": { "id": "rrdnE/YLwpAII45HQiOssw==", "name": "libssh", "version": "0.9.6-3.el8", "kind": "binary", "source": { "id": "", "name": "libssh", "version": "0.9.6-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "sMrsZHOrW8FfprPHZo6Jww==": { "id": "sMrsZHOrW8FfprPHZo6Jww==", "name": "libmodulemd", "version": "2.13.0-1.el8", "kind": "binary", "source": { "id": "", "name": "libmodulemd", "version": "2.13.0-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "sm5sCuXecubhzEqZduLhHA==": { "id": "sm5sCuXecubhzEqZduLhHA==", "name": "systemd-libs", "version": "239-58.el8", "kind": "binary", "source": { "id": "", "name": "systemd", "version": "239-58.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "tD550emtLUl2wRNyHrPi+w==": { "id": "tD550emtLUl2wRNyHrPi+w==", "name": "pcre2", "version": "10.32-2.el8", "kind": "binary", "source": { "id": "", "name": "pcre2", "version": "10.32-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "uC7d+TJ+SSl/a1e/alHSPg==": { "id": "uC7d+TJ+SSl/a1e/alHSPg==", "name": "coreutils-single", "version": "8.30-12.el8", "kind": "binary", "source": { "id": "", "name": "coreutils", "version": "8.30-12.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "uyLU9Ei16xotQDva7l5eaw==": { "id": "uyLU9Ei16xotQDva7l5eaw==", "name": "github.com/op/go-logging", "version": "v0.0.0-20160315200505-970db520ece7", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "semver:0.0.0.0.0.0.0.0.0.0", "cpe": "", "detector": null }, "v/KoDsdxOHqLHd7du8yyWQ==": { "id": "v/KoDsdxOHqLHd7du8yyWQ==", "name": "lua-libs", "version": "5.3.4-12.el8", "kind": "binary", "source": { "id": "", "name": "lua", "version": "5.3.4-12.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "vQtjn4H9BmPSTQWBlhOhfQ==": { "id": "vQtjn4H9BmPSTQWBlhOhfQ==", "name": "glib2", "version": "2.56.4-158.el8", "kind": "binary", "source": { "id": "", "name": "glib2", "version": "2.56.4-158.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "wE436RbDo1t5UIcLXo90zw==": { "id": "wE436RbDo1t5UIcLXo90zw==", "name": "p11-kit-trust", "version": "0.23.22-1.el8", "kind": "binary", "source": { "id": "", "name": "p11-kit", "version": "0.23.22-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "wQToP4WURQ4/A8LQU1k5kA==": { "id": "wQToP4WURQ4/A8LQU1k5kA==", "name": "langpacks-en", "version": "1.0-12.el8", "kind": "binary", "source": { "id": "", "name": "langpacks", "version": "1.0-12.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "wpJmhjYJz5TYuh0mbRPs4Q==": { "id": "wpJmhjYJz5TYuh0mbRPs4Q==", "name": "info", "version": "6.5-7.el8", "kind": "binary", "source": { "id": "", "name": "texinfo", "version": "6.5-7.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "xTF9l16G3x26txeCsO9Bug==": { "id": "xTF9l16G3x26txeCsO9Bug==", "name": "json-glib", "version": "1.4.4-1.el8", "kind": "binary", "source": { "id": "", "name": "json-glib", "version": "1.4.4-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "z4fnEFpWc1E2kVtgPcyZxA==": { "id": "z4fnEFpWc1E2kVtgPcyZxA==", "name": "libstdc++", "version": "8.5.0-10.el8", "kind": "binary", "source": { "id": "", "name": "gcc", "version": "8.5.0-10.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "z5qQdcrRCAH7EdqVwJ79ww==": { "id": "z5qQdcrRCAH7EdqVwJ79ww==", "name": "libacl", "version": "2.2.53-1.el8", "kind": "binary", "source": { "id": "", "name": "acl", "version": "2.2.53-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "zbALRizc8CWcgSofeiuhLg==": { "id": "zbALRizc8CWcgSofeiuhLg==", "name": "libmount", "version": "2.32.1-35.el8", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.32.1-35.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "znJMhwylZjXG9XIrMaiHzw==": { "id": "znJMhwylZjXG9XIrMaiHzw==", "name": "libffi", "version": "3.1-23.el8", "kind": "binary", "source": { "id": "", "name": "libffi", "version": "3.1-23.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null } }, "distributions": { "0311fad0-2357-4a06-9e3c-cd89db081ef3": { "id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "did": "rhel", "name": "Red Hat Enterprise Linux Server", "version": "8", "version_code_name": "", "version_id": "8", "arch": "", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "pretty_name": "Red Hat Enterprise Linux Server 8" } }, "repository": { "6935d163-869e-4ee7-bcc1-50dfdd0f6580": { "id": "6935d163-869e-4ee7-bcc1-50dfdd0f6580", "name": "Red Hat Container Catalog", "key": "rhcc-container-repository", "uri": "https://catalog.redhat.com/software/containers/explore", "cpe": "" }, "aafcb663-f60b-4f84-a2bd-0af00411c9ab": { "id": "aafcb663-f60b-4f84-a2bd-0af00411c9ab", "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "f2b45511-9546-48ea-83b5-33fb02992674": { "id": "f2b45511-9546-48ea-83b5-33fb02992674", "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-8-for-x86_64-appstream-rpms", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "f813fb30-2c56-4248-b079-4572f8b77377": { "id": "f813fb30-2c56-4248-b079-4572f8b77377", "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-8-for-x86_64-baseos-rpms", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" } }, "environments": { "+XM+s3niWaEk1U5jnR5DpA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "+Xr7HyTxXf0c8jLaUyo3xA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "+oTt3EDPSdSzupH3D6G0BA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "0x/GRqZgisb/k2Y9co6i/Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "1gormAsAjMuks2JveQRd0Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "2MdeoPFfsUv55LlpgwkOkQ==": [ { "package_db": "go:retrodep-bin", "introduced_in": "sha256:b2e60927fc43a303ac58fea1775e2efa7512c33f4b4059cfb7024f3a74909879", "distribution_id": "", "repository_ids": [ "aafcb663-f60b-4f84-a2bd-0af00411c9ab" ] } ], "2k8BSFOOZ2ndA++n5wl4TA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "2w5sZgHYUcx7+6n/wISUjw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "3uSX4NgBxQvC8LEk48QoOQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "45rvgYmy022Tx6fVWfking==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "47OMpR7yEmE4lttsyWq3fw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "5Mcqv1rmwAoEs983fcq1cg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "6KnijwRsfeerWmf5Zl8NWw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "6Tp9WGakxVaQJ9rGhrsxpw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "6dlkQEp2PtZPvC6f+1oBaA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "6mY62Fou7cJqqLJXm9hzXg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "7DrAZ2wgIzOquNCQMEVChw==": [ { "package_db": "go:retrodep-bin", "introduced_in": "sha256:b2e60927fc43a303ac58fea1775e2efa7512c33f4b4059cfb7024f3a74909879", "distribution_id": "", "repository_ids": [ "aafcb663-f60b-4f84-a2bd-0af00411c9ab" ] } ], "9CuK4fRE5gzOSWH5fqWZJw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "9c4B7Edcs6gS7zy4kBT4Jw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "BPD4nm0V1xem9/HmmAnFiA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "BmK1zIjr5KsuOODCYwxRCw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "BrxW5JNpEdvbkoGRXbVirw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "Bt7v/jLkw1CWEjQhzP+6Ew==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "CbI8d0OI9wvrtddD/Wg0GA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "Ce3Eu6RmZkiUW2to8Kec/w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "D/ASdBsgxLNlG5Q8U7UPsQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "Du+GhNFjWqhCLFNpPgD/Xw==": [ { "package_db": "go:retrodep-bin", "introduced_in": "sha256:b2e60927fc43a303ac58fea1775e2efa7512c33f4b4059cfb7024f3a74909879", "distribution_id": "", "repository_ids": [ "aafcb663-f60b-4f84-a2bd-0af00411c9ab" ] } ], "EhXwf9CihVVBNVLvlss3Vg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "F7AOP7tK5AfUXV1g9iTzFA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "F8J7f4sv3sY7BmdP80pHcQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "FTEArHfNxv8mTCM/rtN+pw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "FdB9K1+1CEpzAW4zwkaAGw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "GLKhGblbPbPbtDKwfpCv5A==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "Gg1Q6hponuT1eSJHwaJ83w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "GlWFSNV8QxYx5o3TOWf+IA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "HMIoZ/TKrKhxI1rD26qmpw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "HkH7JOZ7zVk8ggpmKHnMxg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "Hr1TetfTnCbToWK+Q1/NLw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "I+kjs7Yx80eRSvYzDMDQwg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "IdaeQutkPjfv4bTMEkXWog==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "IzLcxZDtcvtJR5Gwdq9HDg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "JC8eNzSj6tieJqNqASET1Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "N1RbIRo2SyHosQefv+skDw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "NJbhst8VIOwst++ZzRP6tA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "O63QX7+X9KEjj9ex/GG2aA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "P5Se4zJpr8ZUwZNUojfuzA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "QGSS5ebqb1I03fCvl2CZWA==": [ { "package_db": "root/buildinfo/Dockerfile-ubi8-minimal-8.6-751", "introduced_in": "sha256:8ca21e5fedc58b98be949cf3ddc647cb6a00cfc555df1bbfe6431ce4b7599730", "distribution_id": "", "repository_ids": [ "6935d163-869e-4ee7-bcc1-50dfdd0f6580", "6935d163-869e-4ee7-bcc1-50dfdd0f6580" ] } ], "QudMKkcOe80heCvOb+0deQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "RtrzwDgrQgu9S5B72s2sww==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "Saan3FOrTRBoLj3w1k+cpw==": [ { "package_db": "root/buildinfo/Dockerfile-ubi8-minimal-8.6-751", "introduced_in": "sha256:8ca21e5fedc58b98be949cf3ddc647cb6a00cfc555df1bbfe6431ce4b7599730", "distribution_id": "", "repository_ids": [ "6935d163-869e-4ee7-bcc1-50dfdd0f6580", "6935d163-869e-4ee7-bcc1-50dfdd0f6580" ] } ], "Sg7WHD/cpWdFZ7MyPqITSQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "UKxtVVWEN0LXB/lFG1+5oA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "USWNn71p+k059dbiu5HDEA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "W66WOQ3v6r7mSn6+o7gaew==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "Wnakr8JK5dF9B7cFuYj+LA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "WrV+rIJLRk8b24xMew9Hkg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "XKq3fjedO7d4LSKzSLDcMw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "XKv+fGQhqJZl6x7NNqqaaQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "XVupnfoSG9GJwKd6FSNK8Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "ZRpVwDgK9rS2HJv/RQ5Gkg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "ZeMV+HXeATqaAewlx/gEKw==": [ { "package_db": "go:retrodep-bin", "introduced_in": "sha256:b2e60927fc43a303ac58fea1775e2efa7512c33f4b4059cfb7024f3a74909879", "distribution_id": "", "repository_ids": [ "aafcb663-f60b-4f84-a2bd-0af00411c9ab" ] } ], "aTfPDP7oJqFwbwjiDbCnWA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "bcw2EOFjnx1wB4M400Jpew==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "bfF0cEWD49u6W/lExfuSww==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "bmxL3lydQy0yU8g1iBgovg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "dFKSSJF5WrKg9VsNZqM98g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "dOBT1Qffq44NOVuk9chDyg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "eZ7CwFvwDCQu4vzKyuIZgA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "eiOy5bizxjO/psTcJ5Gh+g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "eiYWF89tQpN/umjL2Ljluw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "ev1iPKY2UXha+ggKYJjsaQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "fCaP9cdwWsPeqX4J2VgB4g==": [ { "package_db": "go:retrodep-bin", "introduced_in": "sha256:b2e60927fc43a303ac58fea1775e2efa7512c33f4b4059cfb7024f3a74909879", "distribution_id": "", "repository_ids": [ "aafcb663-f60b-4f84-a2bd-0af00411c9ab" ] } ], "g146nKetkX1f4hfH1b5RWA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "gOaN4treTmKK7tU+N6AZ1w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "hcJqCsCpWm+XI9JT6ImS5g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "hqd/9D+OkW729P80H901pQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "jtdCxL/eH5JTPcKstKunJg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "k4gCNgIfg7MM/e42ThRx2w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "kFL2/mnzbguW53ahZMvxTQ==": [ { "package_db": "root/buildinfo/Dockerfile-ubi8-minimal-8.6-751", "introduced_in": "sha256:8ca21e5fedc58b98be949cf3ddc647cb6a00cfc555df1bbfe6431ce4b7599730", "distribution_id": "", "repository_ids": [ "6935d163-869e-4ee7-bcc1-50dfdd0f6580", "6935d163-869e-4ee7-bcc1-50dfdd0f6580" ] } ], "lqQ3rJzPTM4e3pH+ravEcw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "mAmp7BtGrfzV0HnAKw9sTw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "mLwCNKs2wEtLWAiibtR4BQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "mkd+V76Xxq5AfXbSoR0DMg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "mkledqgVtELsBjGkaINRAg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "o4tvrO4Cuc2PXep4Fk53sA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "o4v1nyEgxKUJdf78CSzLEg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "oJIAHlP0pGe97iAzAFF0xA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "p75sU/+cD5K1Jv37jjSsxQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "p9tXHgTBVU/b3sTnwfubzg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "pKEOaN2eCFIneHzHE7HYug==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "pY2NT/GP1UxyOuAl2rKgCw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "qN2fZ3YQPh6iZsfkdV7bIg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "rFsA2fU/SFo3JGOkxRURTQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "rYu8Ys1qBj5SKpIdfiIX4Q==": [ { "package_db": "go:retrodep-bin", "introduced_in": "sha256:b2e60927fc43a303ac58fea1775e2efa7512c33f4b4059cfb7024f3a74909879", "distribution_id": "", "repository_ids": [ "aafcb663-f60b-4f84-a2bd-0af00411c9ab" ] } ], "riulbh7DNxLvW7j4IHJ1VA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "rrdnE/YLwpAII45HQiOssw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "sMrsZHOrW8FfprPHZo6Jww==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "sm5sCuXecubhzEqZduLhHA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "tD550emtLUl2wRNyHrPi+w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "uC7d+TJ+SSl/a1e/alHSPg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "uyLU9Ei16xotQDva7l5eaw==": [ { "package_db": "go:retrodep-bin", "introduced_in": "sha256:b2e60927fc43a303ac58fea1775e2efa7512c33f4b4059cfb7024f3a74909879", "distribution_id": "", "repository_ids": [ "aafcb663-f60b-4f84-a2bd-0af00411c9ab" ] } ], "v/KoDsdxOHqLHd7du8yyWQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "vQtjn4H9BmPSTQWBlhOhfQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "wE436RbDo1t5UIcLXo90zw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "wQToP4WURQ4/A8LQU1k5kA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "wpJmhjYJz5TYuh0mbRPs4Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "xTF9l16G3x26txeCsO9Bug==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "z4fnEFpWc1E2kVtgPcyZxA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "z5qQdcrRCAH7EdqVwJ79ww==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "zbALRizc8CWcgSofeiuhLg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ], "znJMhwylZjXG9XIrMaiHzw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "0311fad0-2357-4a06-9e3c-cd89db081ef3", "repository_ids": [ "f2b45511-9546-48ea-83b5-33fb02992674", "f813fb30-2c56-4248-b079-4572f8b77377" ] }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:b8441ca6c1ca31f0d23fd1dd166e9bfb857ff99d26869519ed047496a4006167", "distribution_id": "", "repository_ids": null } ] }, "vulnerabilities": { "+5YAvs7pNh2OXMNza1K1SQ==": { "id": "+5YAvs7pNh2OXMNza1K1SQ==", "updater": "rhel-vex", "name": "CVE-2023-39615", "description": "A flaw was found in Libxml2, where it contains a global buffer overflow via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a denial of service (DoS) by supplying a crafted XML file.", "issued": "2023-08-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-39615 https://bugzilla.redhat.com/show_bug.cgi?id=2235864 https://www.cve.org/CVERecord?id=CVE-2023-39615 https://nvd.nist.gov/vuln/detail/CVE-2023-39615 https://gitlab.gnome.org/GNOME/libxml2/-/issues/535 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-39615.json https://access.redhat.com/errata/RHSA-2024:0119", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-18.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+CCbBbxF4hCSEcLE2gCuCA==": { "id": "+CCbBbxF4hCSEcLE2gCuCA==", "updater": "osv/go", "name": "GO-2025-3563", "description": "Request smuggling due to acceptance of invalid chunked data in net/http", "issued": "2025-04-08T19:46:23Z", "links": "https://go.dev/cl/652998 https://go.dev/issue/71988 https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk https://osv.dev/vulnerability/BIT-golang-2025-22871 https://osv.dev/vulnerability/CVE-2025-22871 https://osv.dev/vulnerability/GHSA-g9pc-8g42-g6vq", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.23.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+H82pW871t8eenixI/+tlw==": { "id": "+H82pW871t8eenixI/+tlw==", "updater": "osv/go", "name": "GHSA-r88r-gmrh-7j83", "description": "YAML Go package vulnerable to denial of service", "issued": "2022-12-28T00:30:23Z", "links": "https://nvd.nist.gov/vuln/detail/CVE-2021-4235 https://github.com/go-yaml/yaml/pull/375 https://github.com/go-yaml/yaml/commit/bb4e33bf68bf89cad44d386192cbed201f35b241 https://github.com/go-yaml/yaml https://lists.debian.org/debian-lts-announce/2023/07/msg00001.html https://pkg.go.dev/vuln/GO-2021-0061 https://osv.dev/vulnerability/CVE-2021-4235 https://osv.dev/vulnerability/GO-2021-0061", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gopkg.in/yaml.v2", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "2.2.3", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+KBioDGBgFmFBqrp2FkLIQ==": { "id": "+KBioDGBgFmFBqrp2FkLIQ==", "updater": "rhel-vex", "name": "CVE-2022-40303", "description": "A flaw was found in libxml2. Parsing a XML document with the XML_PARSE_HUGE option enabled can result in an integer overflow because safety checks were missing in some functions. Also, the xmlParseEntityValue function didn't have any length limitation.", "issued": "2022-10-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-40303 https://bugzilla.redhat.com/show_bug.cgi?id=2136266 https://www.cve.org/CVERecord?id=CVE-2022-40303 https://nvd.nist.gov/vuln/detail/CVE-2022-40303 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-40303.json https://access.redhat.com/errata/RHSA-2023:0173", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-15.el8_7.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+aouF4dLx+YkeGMSFc9q+g==": { "id": "+aouF4dLx+YkeGMSFc9q+g==", "updater": "rhel-vex", "name": "CVE-2024-52533", "description": "A flaw was found in the Glib library. A buffer overflow condition can be triggered in certain conditions due to an off-by-one error in SOCKS4_CONN_MSG_LEN. This issue may lead to an application crash or other undefined behavior.", "issued": "2024-11-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-52533 https://bugzilla.redhat.com/show_bug.cgi?id=2325340 https://www.cve.org/CVERecord?id=CVE-2024-52533 https://nvd.nist.gov/vuln/detail/CVE-2024-52533 https://gitlab.gnome.org/GNOME/glib/-/issues/3461 https://gitlab.gnome.org/GNOME/glib/-/releases/2.82.1 https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-52533.json https://access.redhat.com/errata/RHSA-2025:11327", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.56.4-166.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+et2nlLBpUOdsIiOQHCCVQ==": { "id": "+et2nlLBpUOdsIiOQHCCVQ==", "updater": "rhel-vex", "name": "CVE-2019-8906", "description": "A vulnerability has been identified in the File Project, specifically in the do_core_note function within readelf.c of libmagic.a where, an out-of-bounds read, can be exploited by a local attacker using a specially crafted file which could result in a denial of service or leakage of sensitive information.", "issued": "2019-01-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-8906 https://bugzilla.redhat.com/show_bug.cgi?id=1679175 https://www.cve.org/CVERecord?id=CVE-2019-8906 https://nvd.nist.gov/vuln/detail/CVE-2019-8906 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-8906.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "file", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+v7atIO/jUEFghZH7rPomw==": { "id": "+v7atIO/jUEFghZH7rPomw==", "updater": "rhel-vex", "name": "CVE-2025-0395", "description": "A flaw was found in the GNU C Library (glibc). A buffer overflow condition via the `assert()` function may be triggered due to glibc not allocating enough space for the assertion failure message string and size information. In certain conditions, a local attacker can exploit this, potentially leading to an application crash or other undefined behavior.", "issued": "2025-01-22T13:11:30Z", "links": "https://access.redhat.com/security/cve/CVE-2025-0395 https://bugzilla.redhat.com/show_bug.cgi?id=2339460 https://www.cve.org/CVERecord?id=CVE-2025-0395 https://nvd.nist.gov/vuln/detail/CVE-2025-0395 https://sourceware.org/bugzilla/show_bug.cgi?id=32582 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-0395.json https://access.redhat.com/errata/RHSA-2025:3828", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.16", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/Eu6u3EM/g6M29wF7eD4HA==": { "id": "/Eu6u3EM/g6M29wF7eD4HA==", "updater": "rhel-vex", "name": "CVE-2024-33599", "description": "A stack-based buffer overflow flaw was found in the glibc netgroup cache. In certain conditions, its possible to trigger a stack-based buffer overflow condition that can lead to a denial of service and potentially other malicious actions that impact confidentiality and integrity.", "issued": "2024-04-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33599 https://bugzilla.redhat.com/show_bug.cgi?id=2277202 https://www.cve.org/CVERecord?id=CVE-2024-33599 https://nvd.nist.gov/vuln/detail/CVE-2024-33599 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33599.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/MGsJ9KCE7TaFp0QWQ2amQ==": { "id": "/MGsJ9KCE7TaFp0QWQ2amQ==", "updater": "rhel-vex", "name": "CVE-2024-12133", "description": "A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.", "issued": "2025-02-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-12133 https://bugzilla.redhat.com/show_bug.cgi?id=2344611 https://www.cve.org/CVERecord?id=CVE-2024-12133 https://nvd.nist.gov/vuln/detail/CVE-2024-12133 https://gitlab.com/gnutls/libtasn1/-/blob/master/doc/security/CVE-2024-12133.md https://gitlab.com/gnutls/libtasn1/-/issues/52 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-12133.json https://access.redhat.com/errata/RHSA-2025:4049", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libtasn1", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:4.13-5.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/QaL/BUIdoF2MAB/C1YiGQ==": { "id": "/QaL/BUIdoF2MAB/C1YiGQ==", "updater": "rhel-vex", "name": "CVE-2026-4424", "description": "A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.", "issued": "2026-03-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4424 https://bugzilla.redhat.com/show_bug.cgi?id=2449006 https://www.cve.org/CVERecord?id=CVE-2026-4424 https://nvd.nist.gov/vuln/detail/CVE-2026-4424 https://github.com/libarchive/libarchive/pull/2898 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4424.json https://access.redhat.com/errata/RHSA-2026:8534", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "High", "package": { "id": "", "name": "libarchive", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.3.3-7.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/WMB1nTGBVOBOwBvvW76zA==": { "id": "/WMB1nTGBVOBOwBvvW76zA==", "updater": "rhel-vex", "name": "CVE-2022-1586", "description": "An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.", "issued": "2022-03-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-1586 https://bugzilla.redhat.com/show_bug.cgi?id=2077976 https://www.cve.org/CVERecord?id=CVE-2022-1586 https://nvd.nist.gov/vuln/detail/CVE-2022-1586 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-1586.json https://access.redhat.com/errata/RHSA-2022:5809", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "pcre2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:10.32-3.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/X3Awdl9dZDLotIfpsQK/g==": { "id": "/X3Awdl9dZDLotIfpsQK/g==", "updater": "rhel-vex", "name": "CVE-2021-46848", "description": "An out-of-bounds read flaw was found in Libtasn1 due to an ETYPE_OK off-by-one error in the asn1_encode_simple_der() function. This flaw allows a remote attacker to pass specially crafted data or invalid values to the application, triggering an off-by-one error, corrupting the memory, and possibly performing a denial of service (DoS) attack.", "issued": "2022-10-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-46848 https://bugzilla.redhat.com/show_bug.cgi?id=2140058 https://www.cve.org/CVERecord?id=CVE-2021-46848 https://nvd.nist.gov/vuln/detail/CVE-2021-46848 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-46848.json https://access.redhat.com/errata/RHSA-2023:0116", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libtasn1", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:4.13-4.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/hG2eFl/EZ15/sR5oOZbCA==": { "id": "/hG2eFl/EZ15/sR5oOZbCA==", "updater": "rhel-vex", "name": "CVE-2026-7383", "description": "A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-7383 https://bugzilla.redhat.com/show_bug.cgi?id=2481879 https://www.cve.org/CVERecord?id=CVE-2026-7383 https://nvd.nist.gov/vuln/detail/CVE-2026-7383 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7383.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/n3JLGVkGgJxFBUJuV7OqA==": { "id": "/n3JLGVkGgJxFBUJuV7OqA==", "updater": "osv/go", "name": "GO-2026-4340", "description": "Handshake messages may be processed at the incorrect encryption level in crypto/tls", "issued": "2026-01-28T19:08:09Z", "links": "https://go.dev/cl/724120 https://go.dev/issue/76443 https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc https://osv.dev/vulnerability/BIT-golang-2025-61730 https://osv.dev/vulnerability/CVE-2025-61730", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/u+MoX7ESLBePT8pNUw5FQ==": { "id": "/u+MoX7ESLBePT8pNUw5FQ==", "updater": "rhel-vex", "name": "CVE-2024-34459", "description": "A flaw was found in the xmllint program distributed by the libxml2 package. A buffer over-read in the xmlHTMLPrintFileContext function in the xmllint.c file may be triggered when a crafted file is processed with the xmllint program using the `--htmlout` command line option, causing an application crash and resulting in a denial of service.", "issued": "2024-05-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-34459 https://bugzilla.redhat.com/show_bug.cgi?id=2280532 https://www.cve.org/CVERecord?id=CVE-2024-34459 https://nvd.nist.gov/vuln/detail/CVE-2024-34459 https://gitlab.gnome.org/GNOME/libxml2/-/issues/720 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-34459.json https://access.redhat.com/errata/RHSA-2026:26354", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-21.el8_10.5", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/viT+PF8pyoWGfVITKNvYA==": { "id": "/viT+PF8pyoWGfVITKNvYA==", "updater": "rhel-vex", "name": "CVE-2024-28182", "description": "A vulnerability was found in how nghttp2 implements the HTTP/2 protocol. There are insufficient limitations placed on the amount of CONTINUATION frames that can be sent within a single stream. This issue could allow an unauthenticated remote attacker to send packets to vulnerable servers, which could use up compute or memory resources to cause a Denial of Service.", "issued": "2024-04-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-28182 https://bugzilla.redhat.com/show_bug.cgi?id=2268639 https://www.cve.org/CVERecord?id=CVE-2024-28182 https://nvd.nist.gov/vuln/detail/CVE-2024-28182 https://github.com/nghttp2/nghttp2/security/advisories/GHSA-x6x3-gv8h-m57q https://nowotarski.info/http2-continuation-flood/ https://www.kb.cert.org/vuls/id/421644 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-28182.json https://access.redhat.com/errata/RHSA-2024:4252", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libnghttp2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.33.0-6.el8_10.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0IkIJ5q/xNX41U2yF71Pyw==": { "id": "0IkIJ5q/xNX41U2yF71Pyw==", "updater": "rhel-vex", "name": "CVE-2026-13595", "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.", "issued": "2026-05-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13595 https://bugzilla.redhat.com/show_bug.cgi?id=2494101 https://www.cve.org/CVERecord?id=CVE-2026-13595 https://nvd.nist.gov/vuln/detail/CVE-2026-13595 https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13595.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0QnoqOg3TG4vdvby55jMig==": { "id": "0QnoqOg3TG4vdvby55jMig==", "updater": "osv/go", "name": "GO-2023-1751", "description": "Improper sanitization of CSS values in html/template", "issued": "2023-05-05T21:10:20Z", "links": "https://go.dev/issue/59720 https://go.dev/cl/491615 https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU https://osv.dev/vulnerability/BIT-golang-2023-24539 https://osv.dev/vulnerability/CVE-2023-24539", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0fCtWwB6iclgRvIA+IqiJQ==": { "id": "0fCtWwB6iclgRvIA+IqiJQ==", "updater": "rhel-vex", "name": "CVE-2026-1484", "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1484 https://bugzilla.redhat.com/show_bug.cgi?id=2433259 https://www.cve.org/CVERecord?id=CVE-2026-1484 https://nvd.nist.gov/vuln/detail/CVE-2026-1484 https://gitlab.gnome.org/GNOME/glib/-/issues/3870 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1484.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0fRIluxuaC1n6wm+qP9Pjw==": { "id": "0fRIluxuaC1n6wm+qP9Pjw==", "updater": "rhel-vex", "name": "CVE-2026-59848", "description": "A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.", "issued": "2026-07-21T13:18:03Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59848 https://bugzilla.redhat.com/show_bug.cgi?id=2498181 https://www.cve.org/CVERecord?id=CVE-2026-59848 https://nvd.nist.gov/vuln/detail/CVE-2026-59848 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59848.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0nQ3GJDLY22M176Z5ESg6A==": { "id": "0nQ3GJDLY22M176Z5ESg6A==", "updater": "rhel-vex", "name": "CVE-2025-68972", "description": "A flaw was found in GnuPG. An adversary can exploit this vulnerability by crafting a signed message that includes a form feed character (\\f) at the end of a plaintext line. This allows the adversary to append additional, unsigned text to the message while the signature verification still reports success. This issue leads to an integrity bypass, potentially enabling the spoofing of signed communications.", "issued": "2025-12-27T22:52:30Z", "links": "https://access.redhat.com/security/cve/CVE-2025-68972 https://bugzilla.redhat.com/show_bug.cgi?id=2425646 https://www.cve.org/CVERecord?id=CVE-2025-68972 https://nvd.nist.gov/vuln/detail/CVE-2025-68972 https://gpg.fail/formfeed https://news.ycombinator.com/item?id=46404339 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68972.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0ooSlh5nhhmGfw4m42ye2A==": { "id": "0ooSlh5nhhmGfw4m42ye2A==", "updater": "rhel-vex", "name": "CVE-2024-33602", "description": "A flaw was found in the glibc netgroup cache. The buffer-resizing code in addgetnetgrentX assumes that all string pointers point into the supplied buffer. This can potentially lead to memory corruption and cause a crash.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33602 https://bugzilla.redhat.com/show_bug.cgi?id=2277206 https://www.cve.org/CVERecord?id=CVE-2024-33602 https://nvd.nist.gov/vuln/detail/CVE-2024-33602 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33602.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0v/g0Z/XEXV13r48i52JgA==": { "id": "0v/g0Z/XEXV13r48i52JgA==", "updater": "rhel-vex", "name": "CVE-2026-6276", "description": "A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intended for the first host to the second host, resulting in a cookie leak. This issue is categorized as an Origin Validation Error (CWE-346). Exploitation typically requires specific debugging configurations.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6276 https://bugzilla.redhat.com/show_bug.cgi?id=2461203 https://www.cve.org/CVERecord?id=CVE-2026-6276 https://nvd.nist.gov/vuln/detail/CVE-2026-6276 https://curl.se/docs/CVE-2026-6276.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6276.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0wAoL7EHybTff1dEx4QX9w==": { "id": "0wAoL7EHybTff1dEx4QX9w==", "updater": "rhel-vex", "name": "CVE-2023-23916", "description": "A flaw was found in the Curl package. A malicious server can insert an unlimited number of compression steps. This decompression chain could result in out-of-memory errors.", "issued": "2023-02-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-23916 https://bugzilla.redhat.com/show_bug.cgi?id=2167815 https://www.cve.org/CVERecord?id=CVE-2023-23916 https://nvd.nist.gov/vuln/detail/CVE-2023-23916 https://curl.se/docs/CVE-2023-23916.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-23916.json https://access.redhat.com/errata/RHSA-2023:1140", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-25.el8_7.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0ywB8yoh2sWnVY1GY399UQ==": { "id": "0ywB8yoh2sWnVY1GY399UQ==", "updater": "rhel-vex", "name": "CVE-2024-33601", "description": "A flaw was found in the glibc netgroup cache. The netgroup cache uses xmalloc/xrealloc and may terminate the process due to a memory allocation failure.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33601 https://bugzilla.redhat.com/show_bug.cgi?id=2277205 https://www.cve.org/CVERecord?id=CVE-2024-33601 https://nvd.nist.gov/vuln/detail/CVE-2024-33601 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33601.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "10mkuQa11DvXpmFksl36qw==": { "id": "10mkuQa11DvXpmFksl36qw==", "updater": "osv/go", "name": "GO-2023-1752", "description": "Improper handling of JavaScript whitespace in html/template", "issued": "2023-05-05T21:10:22Z", "links": "https://go.dev/issue/59721 https://go.dev/cl/491616 https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU https://osv.dev/vulnerability/BIT-golang-2023-24540 https://osv.dev/vulnerability/CVE-2023-24540", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "15glBRF4pyCc/Aq0eHsKqA==": { "id": "15glBRF4pyCc/Aq0eHsKqA==", "updater": "rhel-vex", "name": "CVE-2022-3821", "description": "An off-by-one error flaw was found in systemd in the format_timespan() function of time-util.c. This flaw allows an attacker to supply specific values for time and accuracy, leading to a buffer overrun in format_timespan(), leading to a denial of service.", "issued": "2022-07-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-3821 https://bugzilla.redhat.com/show_bug.cgi?id=2139327 https://www.cve.org/CVERecord?id=CVE-2022-3821 https://nvd.nist.gov/vuln/detail/CVE-2022-3821 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3821.json https://access.redhat.com/errata/RHSA-2023:0100", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:239-68.el8_7.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "18zPxSgJwI7mcSJsDFvIMA==": { "id": "18zPxSgJwI7mcSJsDFvIMA==", "updater": "osv/go", "name": "GHSA-6q6q-88xp-6f2r", "description": "yaml package for Go can consume excessive amounts of CPU or memory", "issued": "2022-12-28T00:30:22Z", "links": "https://nvd.nist.gov/vuln/detail/CVE-2022-3064 https://github.com/go-yaml/yaml/commit/f221b8435cfb71e54062f6c6e99e9ade30b124d5 https://github.com/go-yaml/yaml https://github.com/go-yaml/yaml/releases/tag/v2.2.4 https://lists.debian.org/debian-lts-announce/2023/07/msg00001.html https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4SBIUECMLNC572P23DDOKJNKPJVX26SP https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ANIOPUXWIHVRA6CEWXCGOMX3YYS6KFHG https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PW3XC47AUW5J5M2ULJX7WCCL3B2ETLMT https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI https://pkg.go.dev/vuln/GO-2022-0956 https://osv.dev/vulnerability/CVE-2022-3064 https://osv.dev/vulnerability/GO-2022-0956", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "gopkg.in/yaml.v2", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "2.2.4", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1MernTu9spjwGBRYkNkZIg==": { "id": "1MernTu9spjwGBRYkNkZIg==", "updater": "rhel-vex", "name": "CVE-2025-6395", "description": "A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().", "issued": "2025-07-10T07:56:53Z", "links": "https://access.redhat.com/security/cve/CVE-2025-6395 https://bugzilla.redhat.com/show_bug.cgi?id=2376755 https://www.cve.org/CVERecord?id=CVE-2025-6395 https://nvd.nist.gov/vuln/detail/CVE-2025-6395 https://gitlab.com/gnutls/gnutls/-/issues/1718 https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6395.json https://access.redhat.com/errata/RHSA-2025:17415", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.4", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1Mr3ID1dsZJrqfRCJnrW+g==": { "id": "1Mr3ID1dsZJrqfRCJnrW+g==", "updater": "rhel-vex", "name": "CVE-2021-35938", "description": "A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "issued": "2021-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-35938 https://bugzilla.redhat.com/show_bug.cgi?id=1964114 https://www.cve.org/CVERecord?id=CVE-2021-35938 https://nvd.nist.gov/vuln/detail/CVE-2021-35938 https://rpm.org/wiki/Releases/4.18.0 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-35938.json https://access.redhat.com/errata/RHSA-2024:0647", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "rpm", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:4.14.3-28.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1kwBKuPYWuGsNWB/ZWkPvg==": { "id": "1kwBKuPYWuGsNWB/ZWkPvg==", "updater": "rhel-vex", "name": "CVE-2025-6021", "description": "A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.", "issued": "2025-06-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-6021 https://bugzilla.redhat.com/show_bug.cgi?id=2372406 https://www.cve.org/CVERecord?id=CVE-2025-6021 https://nvd.nist.gov/vuln/detail/CVE-2025-6021 https://gitlab.gnome.org/GNOME/libxml2/-/issues/926 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6021.json https://access.redhat.com/errata/RHSA-2025:10698", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-21.el8_10.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1lUHOMB3ANHGWpqCBv9Ynw==": { "id": "1lUHOMB3ANHGWpqCBv9Ynw==", "updater": "rhel-vex", "name": "CVE-2026-4105", "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.", "issued": "2026-03-13T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4105 https://bugzilla.redhat.com/show_bug.cgi?id=2447262 https://www.cve.org/CVERecord?id=CVE-2026-4105 https://nvd.nist.gov/vuln/detail/CVE-2026-4105 https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4105.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1vSI4M5c48FhFckHzvLxNA==": { "id": "1vSI4M5c48FhFckHzvLxNA==", "updater": "rhel-vex", "name": "CVE-2022-2509", "description": "A vulnerability was found in gnutls. This issue is due to a double-free error that occurs during the verification of pkcs7 signatures in the gnutls_pkcs7_verify function.", "issued": "2022-07-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-2509 https://bugzilla.redhat.com/show_bug.cgi?id=2108977 https://www.cve.org/CVERecord?id=CVE-2022-2509 https://nvd.nist.gov/vuln/detail/CVE-2022-2509 https://gnutls.org/security-new.html#GNUTLS-SA-2022-07-07 https://lists.gnupg.org/pipermail/gnutls-help/2022-July/004746.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2509.json https://access.redhat.com/errata/RHSA-2022:7105", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-5.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1wPGWBpDgFCknqwW3nIAlQ==": { "id": "1wPGWBpDgFCknqwW3nIAlQ==", "updater": "osv/go", "name": "GO-2026-5026", "description": "Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna", "issued": "2026-05-22T02:46:43Z", "links": "https://go.dev/cl/767220 https://go.dev/issue/78760 https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 https://groups.google.com/g/golang-announce/c/94pEornpRlI https://osv.dev/vulnerability/CVE-2026-39821", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.13", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1x64uH6cdOb5OUrxpLCD0Q==": { "id": "1x64uH6cdOb5OUrxpLCD0Q==", "updater": "rhel-vex", "name": "CVE-2026-5928", "description": "A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.", "issued": "2026-04-20T20:37:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42733", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.40", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1xXjuza0G6LPntbEUbkuMg==": { "id": "1xXjuza0G6LPntbEUbkuMg==", "updater": "osv/go", "name": "GO-2026-4976", "description": "ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil", "issued": "2026-05-07T19:21:40Z", "links": "https://go.dev/cl/770541 https://go.dev/issue/78948 https://groups.google.com/g/golang-announce/c/qcCIEXso47M https://osv.dev/vulnerability/BIT-golang-2026-39825 https://osv.dev/vulnerability/CVE-2026-39825", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2DLcncUUd6/1/JtsPnknxw==": { "id": "2DLcncUUd6/1/JtsPnknxw==", "updater": "rhel-vex", "name": "CVE-2018-20839", "description": "The issue arises from the way systemd handles user passwords during the boot process. Specifically, passwords entered on the console during the system boot (e.g., for unlocking encrypted disks or logging in) could be logged in plaintext if certain conditions are met.", "issued": "2019-05-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-20839 https://bugzilla.redhat.com/show_bug.cgi?id=1716955 https://www.cve.org/CVERecord?id=CVE-2018-20839 https://nvd.nist.gov/vuln/detail/CVE-2018-20839 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-20839.json", "severity": "CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2NoNPjVWSksxN+sTENwoIw==": { "id": "2NoNPjVWSksxN+sTENwoIw==", "updater": "rhel-vex", "name": "CVE-2022-4415", "description": "A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.", "issued": "2022-12-21T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-4415 https://bugzilla.redhat.com/show_bug.cgi?id=2155515 https://www.cve.org/CVERecord?id=CVE-2022-4415 https://nvd.nist.gov/vuln/detail/CVE-2022-4415 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-4415.json https://access.redhat.com/errata/RHSA-2023:0837", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:239-68.el8_7.4", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2RxMNudsmmn7hs6tgte0cg==": { "id": "2RxMNudsmmn7hs6tgte0cg==", "updater": "rhel-vex", "name": "CVE-2023-38546", "description": "A flaw was found in the Curl package. This flaw allows an attacker to insert cookies into a running program using libcurl if the specific series of conditions are met.", "issued": "2023-10-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-38546 https://bugzilla.redhat.com/show_bug.cgi?id=2241938 https://access.redhat.com/errata/RHSA-2024:2101 https://www.cve.org/CVERecord?id=CVE-2023-38546 https://nvd.nist.gov/vuln/detail/CVE-2023-38546 https://curl.se/docs/CVE-2023-38546.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-38546.json https://access.redhat.com/errata/RHSA-2024:1601", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-33.el8_9.5", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2U6d1qsPVwS8vUnflv9AcQ==": { "id": "2U6d1qsPVwS8vUnflv9AcQ==", "updater": "rhel-vex", "name": "CVE-2026-4873", "description": "A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass the TLS requirement, leading to the transmission of sensitive information in cleartext. This vulnerability, categorized as Cleartext Transmission of Sensitive Information (CWE-319), results in information disclosure.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4873 https://bugzilla.redhat.com/show_bug.cgi?id=2461200 https://www.cve.org/CVERecord?id=CVE-2026-4873 https://nvd.nist.gov/vuln/detail/CVE-2026-4873 https://curl.se/docs/CVE-2026-4873.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4873.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2nTJR0d4Yks4joGlPZKftw==": { "id": "2nTJR0d4Yks4joGlPZKftw==", "updater": "rhel-vex", "name": "CVE-2020-35527", "description": "An out-of-bounds read vulnerability was found in SQLite. This security flaw occurs when the ALTER TABLE for views has a nested FROM clause. This flaw allows an attacker to triage an out-of-bounds read and access confidential data successfully.", "issued": "2020-02-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-35527 https://bugzilla.redhat.com/show_bug.cgi?id=2122329 https://www.cve.org/CVERecord?id=CVE-2020-35527 https://nvd.nist.gov/vuln/detail/CVE-2020-35527 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-35527.json https://access.redhat.com/errata/RHSA-2022:7108", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "sqlite-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.26.0-16.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "339w21eGPDsPlNhgbxaeRw==": { "id": "339w21eGPDsPlNhgbxaeRw==", "updater": "rhel-vex", "name": "CVE-2021-43618", "description": "A flaw was found in gmp. An integer overflow vulnerability could allow an attacker to input an integer value leading to a crash. The highest threat from this vulnerability is to system availability.", "issued": "2021-11-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-43618 https://bugzilla.redhat.com/show_bug.cgi?id=2024904 https://www.cve.org/CVERecord?id=CVE-2021-43618 https://nvd.nist.gov/vuln/detail/CVE-2021-43618 https://bugs.debian.org/994405 https://gmplib.org/list-archives/gmp-bugs/2021-September/005077.html https://gmplib.org/repo/gmp-6.2/rev/561a9c25298e https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-43618.json https://access.redhat.com/errata/RHSA-2024:3214", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gmp", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:6.1.2-11.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3O4IzHXnRQMZXCe1gYATvw==": { "id": "3O4IzHXnRQMZXCe1gYATvw==", "updater": "rhel-vex", "name": "CVE-2026-22185", "description": "A flaw was found in OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load. When processing malformed input, a local attacker can exploit a heap buffer underflow vulnerability in the readline() function. This can lead to an out-of-bounds read, potentially causing a denial of service (DoS) and limited disclosure of heap memory contents.", "issued": "2026-01-07T20:26:30Z", "links": "https://access.redhat.com/security/cve/CVE-2026-22185 https://bugzilla.redhat.com/show_bug.cgi?id=2427679 https://www.cve.org/CVERecord?id=CVE-2026-22185 https://nvd.nist.gov/vuln/detail/CVE-2026-22185 https://seclists.org/fulldisclosure/2026/Jan/5 https://seclists.org/fulldisclosure/2026/Jan/8 https://www.openldap.org/ https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22185.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openldap", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3O56WVSolkvoABYGfjiFHg==": { "id": "3O56WVSolkvoABYGfjiFHg==", "updater": "rhel-vex", "name": "CVE-2024-33601", "description": "A flaw was found in the glibc netgroup cache. The netgroup cache uses xmalloc/xrealloc and may terminate the process due to a memory allocation failure.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33601 https://bugzilla.redhat.com/show_bug.cgi?id=2277205 https://www.cve.org/CVERecord?id=CVE-2024-33601 https://nvd.nist.gov/vuln/detail/CVE-2024-33601 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33601.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3Rl0hdm/K5SiiE3lXagVYg==": { "id": "3Rl0hdm/K5SiiE3lXagVYg==", "updater": "rhel-vex", "name": "CVE-2026-42013", "description": "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42013 https://bugzilla.redhat.com/show_bug.cgi?id=2467448 https://www.cve.org/CVERecord?id=CVE-2026-42013 https://nvd.nist.gov/vuln/detail/CVE-2026-42013 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42013.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3RvU4z8AafN9DpKXu1VimQ==": { "id": "3RvU4z8AafN9DpKXu1VimQ==", "updater": "rhel-vex", "name": "CVE-2026-5435", "description": "A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.", "issued": "2026-04-28T11:58:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42733", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.40", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3YfvdccW37dXx04g7wb1eg==": { "id": "3YfvdccW37dXx04g7wb1eg==", "updater": "rhel-vex", "name": "CVE-2024-2961", "description": "An out-of-bounds write flaw was found in the ISO-2022-CN-EXT plugin for glibc's iconv library. When converting from UCS4 charset, adding certain escape charterers is required to indicate where the charset was changed to the library. During this process, iconv improperly checks the boundaries of internal buffers, leading to a buffer overflow, which allows writing up to 3 bytes outside the desired memory location. This issue may allow an attacker to craft a malicious characters sequence that will trigger the out-of-bounds write and perform remote code execution, presenting a high impact to the Integrity, Confidentiality, and Availability triad.", "issued": "2024-04-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2961 https://bugzilla.redhat.com/show_bug.cgi?id=2273404 https://www.cve.org/CVERecord?id=CVE-2024-2961 https://nvd.nist.gov/vuln/detail/CVE-2024-2961 https://www.openwall.com/lists/oss-security/2024/04/17/9 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2961.json https://access.redhat.com/errata/RHSA-2024:3269", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3i3rFQ2YbuMILxtg++/X5Q==": { "id": "3i3rFQ2YbuMILxtg++/X5Q==", "updater": "osv/go", "name": "GO-2026-4601", "description": "Incorrect parsing of IPv6 host literals in net/url", "issued": "2026-03-06T21:03:42Z", "links": "https://go.dev/cl/752180 https://go.dev/issue/77578 https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk https://osv.dev/vulnerability/BIT-golang-2026-25679 https://osv.dev/vulnerability/CVE-2026-25679", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "49iR5D1WXClVofqwu/tZ8Q==": { "id": "49iR5D1WXClVofqwu/tZ8Q==", "updater": "rhel-vex", "name": "CVE-2021-35938", "description": "A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "issued": "2021-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-35938 https://bugzilla.redhat.com/show_bug.cgi?id=1964114 https://www.cve.org/CVERecord?id=CVE-2021-35938 https://nvd.nist.gov/vuln/detail/CVE-2021-35938 https://rpm.org/wiki/Releases/4.18.0 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-35938.json https://access.redhat.com/errata/RHSA-2024:0647", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "rpm-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:4.14.3-28.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4BMu8XKXu+ZtEjv/XhWxXA==": { "id": "4BMu8XKXu+ZtEjv/XhWxXA==", "updater": "rhel-vex", "name": "CVE-2026-58016", "description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.", "issued": "2026-04-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58016 https://bugzilla.redhat.com/show_bug.cgi?id=2492257 https://www.cve.org/CVERecord?id=CVE-2026-58016 https://nvd.nist.gov/vuln/detail/CVE-2026-58016 https://gitlab.gnome.org/GNOME/glib/-/issues/3932 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58016.json https://access.redhat.com/errata/RHSA-2026:42090", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.56.4-170.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4JszZEguo/SAFbgp6PdKMQ==": { "id": "4JszZEguo/SAFbgp6PdKMQ==", "updater": "rhel-vex", "name": "CVE-2026-5773", "description": "A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5773 https://bugzilla.redhat.com/show_bug.cgi?id=2461201 https://www.cve.org/CVERecord?id=CVE-2026-5773 https://nvd.nist.gov/vuln/detail/CVE-2026-5773 https://curl.se/docs/CVE-2026-5773.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5773.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4jAWcNPbUa6mXzywmxFG1g==": { "id": "4jAWcNPbUa6mXzywmxFG1g==", "updater": "rhel-vex", "name": "CVE-2026-58011", "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.", "issued": "2026-03-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58011 https://bugzilla.redhat.com/show_bug.cgi?id=2492245 https://www.cve.org/CVERecord?id=CVE-2026-58011 https://nvd.nist.gov/vuln/detail/CVE-2026-58011 https://gitlab.gnome.org/GNOME/glib/-/issues/3917 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58011.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4jwyohcb+1bhgpZNrF5JUA==": { "id": "4jwyohcb+1bhgpZNrF5JUA==", "updater": "rhel-vex", "name": "CVE-2022-32816", "description": "A vulnerability was found in webkit. This issue occurs when visiting a website that frames malicious content, which may lead to UI spoofing.", "issued": "2022-07-04T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-32816 https://bugzilla.redhat.com/show_bug.cgi?id=2238975 https://www.cve.org/CVERecord?id=CVE-2022-32816 https://nvd.nist.gov/vuln/detail/CVE-2022-32816 https://wpewebkit.org/security/WSA-2022-0007.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-32816.json https://access.redhat.com/errata/RHSA-2022:7704", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.56.4-159.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4rmNFfTLXyhGn97x/e++IA==": { "id": "4rmNFfTLXyhGn97x/e++IA==", "updater": "rhel-vex", "name": "CVE-2022-27782", "description": "A vulnerability was found in curl. This issue occurs because curl can reuse a previously created connection even when a TLS or SSH-related option is changed that should have prohibited reuse. This flaw leads to an authentication bypass, either by mistake or by a malicious actor.", "issued": "2022-05-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-27782 https://bugzilla.redhat.com/show_bug.cgi?id=2082215 https://www.cve.org/CVERecord?id=CVE-2022-27782 https://nvd.nist.gov/vuln/detail/CVE-2022-27782 https://curl.se/docs/CVE-2022-27782.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-27782.json https://access.redhat.com/errata/RHSA-2022:5313", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5+EwPLeLLejao7ij4WmWAQ==": { "id": "5+EwPLeLLejao7ij4WmWAQ==", "updater": "rhel-vex", "name": "CVE-2020-24736", "description": "A flaw was found in SQLite. A buffer overflow vulnerability allows a local attacker to cause a denial of service via a crafted script.", "issued": "2023-04-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-24736 https://bugzilla.redhat.com/show_bug.cgi?id=2186385 https://www.cve.org/CVERecord?id=CVE-2020-24736 https://nvd.nist.gov/vuln/detail/CVE-2020-24736 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-24736.json https://access.redhat.com/errata/RHSA-2023:3840", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "sqlite-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.26.0-18.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "54QMeb97RdTZwYWYELMfPw==": { "id": "54QMeb97RdTZwYWYELMfPw==", "updater": "rhel-vex", "name": "CVE-2018-1000654", "description": "A vulnerability was found in GNU Libtasn1, where a resource management issue can lead to a denial of service, here an attacker could exploit this flaw by persuading a victim to parse a specially crafted file, exhausting all available CPU resources.", "issued": "2018-08-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-1000654 https://bugzilla.redhat.com/show_bug.cgi?id=1621972 https://www.cve.org/CVERecord?id=CVE-2018-1000654 https://nvd.nist.gov/vuln/detail/CVE-2018-1000654 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-1000654.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libtasn1", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "584yXY5vNaGck4ra71kLOQ==": { "id": "584yXY5vNaGck4ra71kLOQ==", "updater": "osv/go", "name": "GO-2023-2375", "description": "Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel", "issued": "2023-12-05T16:16:44Z", "links": "https://go.dev/issue/20654 https://go.dev/cl/326012/26 https://groups.google.com/g/golang-announce/c/QMK8IQALDvA https://people.redhat.com/~hkario/marvin/ https://osv.dev/vulnerability/BIT-golang-2023-45287 https://osv.dev/vulnerability/CVE-2023-45287", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.20.0", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5B1tQ2BK8z/YjRkYcvwqag==": { "id": "5B1tQ2BK8z/YjRkYcvwqag==", "updater": "rhel-vex", "name": "CVE-2019-19244", "description": "A flaw was found in the way SQLite handled certain types of SQL queries using DISTINCT, OVER and ORDER BY clauses. A remote attacker could exploit this flaw by providing a malicious SQL query that, when processed by an application linked to SQLite, would crash the application causing a denial of service.", "issued": "2019-11-22T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-19244 https://bugzilla.redhat.com/show_bug.cgi?id=1777945 https://www.cve.org/CVERecord?id=CVE-2019-19244 https://nvd.nist.gov/vuln/detail/CVE-2019-19244 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-19244.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5J7GXlJ1u8j1vVS3M0/JgA==": { "id": "5J7GXlJ1u8j1vVS3M0/JgA==", "updater": "osv/go", "name": "GO-2025-3849", "description": "Incorrect results returned from Rows.Scan in database/sql", "issued": "2025-08-07T15:07:27Z", "links": "https://go.dev/cl/693735 https://go.dev/issue/74831 https://groups.google.com/g/golang-announce/c/x5MKroML2yM https://osv.dev/vulnerability/BIT-golang-2025-47907 https://osv.dev/vulnerability/CVE-2025-47907", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.23.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5N/X0o1/JN9fqvD4aiuURA==": { "id": "5N/X0o1/JN9fqvD4aiuURA==", "updater": "rhel-vex", "name": "CVE-2026-42250", "description": "A flaw was found in bzip2. The bzip2recover utility contains an off-by-one error that allows a local attacker to cause an out-of-bounds write to a global buffer by processing a specially crafted file. This memory corruption can lead to a crash, resulting in a Denial of Service (DoS).", "issued": "2026-05-28T13:15:19Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42250 https://bugzilla.redhat.com/show_bug.cgi?id=2482704 https://www.cve.org/CVERecord?id=CVE-2026-42250 https://nvd.nist.gov/vuln/detail/CVE-2026-42250 https://cert.pl/en/posts/2026/05/CVE-2026-42250/ https://sourceware.org/bzip2/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42250.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "bzip2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5e3gC+KDeb36jTLxBYtijg==": { "id": "5e3gC+KDeb36jTLxBYtijg==", "updater": "rhel-vex", "name": "CVE-2026-41990", "description": "A flaw was found in Libgcrypt. During Dilithium signing operations, the library fails to perform a bounds check when writing to a static array. While the data involved is not directly controlled by an attacker, this vulnerability could lead to memory corruption, potentially resulting in a denial of service (DoS) or affecting data integrity.", "issued": "2026-04-23T04:39:04Z", "links": "https://access.redhat.com/security/cve/CVE-2026-41990 https://bugzilla.redhat.com/show_bug.cgi?id=2461068 https://www.cve.org/CVERecord?id=CVE-2026-41990 https://nvd.nist.gov/vuln/detail/CVE-2026-41990 https://dev.gnupg.org/T8208 https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html https://www.openwall.com/lists/oss-security/2026/04/21/1 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41990.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "619DQiII/+IW12e6tmtrxw==": { "id": "619DQiII/+IW12e6tmtrxw==", "updater": "rhel-vex", "name": "CVE-2026-6732", "description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.", "issued": "2026-04-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6732 https://bugzilla.redhat.com/show_bug.cgi?id=2461300 https://www.cve.org/CVERecord?id=CVE-2026-6732 https://nvd.nist.gov/vuln/detail/CVE-2026-6732 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097 https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6732.json", "severity": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "62mwE4DQA6gTvSLjP2HaOg==": { "id": "62mwE4DQA6gTvSLjP2HaOg==", "updater": "rhel-vex", "name": "CVE-2023-4527", "description": "A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.", "issued": "2023-09-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4527 https://bugzilla.redhat.com/show_bug.cgi?id=2234712 https://www.cve.org/CVERecord?id=CVE-2023-4527 https://nvd.nist.gov/vuln/detail/CVE-2023-4527 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4527.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "673FKazcUiydbfN5c6amaw==": { "id": "673FKazcUiydbfN5c6amaw==", "updater": "rhel-vex", "name": "CVE-2020-19190", "description": "A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19190 https://bugzilla.redhat.com/show_bug.cgi?id=2234923 https://www.cve.org/CVERecord?id=CVE-2020-19190 https://nvd.nist.gov/vuln/detail/CVE-2020-19190 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19190.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6AErW03qOxvwfBKrSzg4iA==": { "id": "6AErW03qOxvwfBKrSzg4iA==", "updater": "rhel-vex", "name": "CVE-2026-5450", "description": "A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.", "issued": "2026-04-20T20:55:41Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33126", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.38", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6Cqvzp5JbuVfHsuYnIJNFw==": { "id": "6Cqvzp5JbuVfHsuYnIJNFw==", "updater": "rhel-vex", "name": "CVE-2026-4438", "description": "A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.", "issued": "2026-03-20T19:59:06Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4438 https://bugzilla.redhat.com/show_bug.cgi?id=2449783 https://www.cve.org/CVERecord?id=CVE-2026-4438 https://nvd.nist.gov/vuln/detail/CVE-2026-4438 https://sourceware.org/bugzilla/show_bug.cgi?id=34015 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4438.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6FQUI3OxX4C5skWXKgq80Q==": { "id": "6FQUI3OxX4C5skWXKgq80Q==", "updater": "rhel-vex", "name": "CVE-2023-0464", "description": "A security vulnerability has been identified in all supported OpenSSL versions related to verifying X.509 certificate chains that include policy constraints. This flaw allows attackers to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial of service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the -policy' argument to the command line utilities or calling the X509_VERIFY_PARAM_set1_policies()' function.", "issued": "2023-03-22T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-0464 https://bugzilla.redhat.com/show_bug.cgi?id=2181082 https://www.cve.org/CVERecord?id=CVE-2023-0464 https://nvd.nist.gov/vuln/detail/CVE-2023-0464 https://www.openssl.org/news/secadv/20230322.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0464.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6GwsF+MSFOJ9Sierd0uYzw==": { "id": "6GwsF+MSFOJ9Sierd0uYzw==", "updater": "rhel-vex", "name": "CVE-2026-42010", "description": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42010 https://bugzilla.redhat.com/show_bug.cgi?id=2467289 https://www.cve.org/CVERecord?id=CVE-2026-42010 https://nvd.nist.gov/vuln/detail/CVE-2026-42010 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42010.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N", "normalized_severity": "High", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6QNkz1Y+JhK+YsJ1oospGg==": { "id": "6QNkz1Y+JhK+YsJ1oospGg==", "updater": "osv/go", "name": "GO-2025-4006", "description": "Excessive CPU consumption in ParseAddress in net/mail", "issued": "2025-10-29T21:48:35Z", "links": "https://go.dev/cl/709860 https://go.dev/issue/75680 https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI https://osv.dev/vulnerability/BIT-golang-2025-61725 https://osv.dev/vulnerability/CVE-2025-61725", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6UnjveNMgk4ukDQJdTGvOQ==": { "id": "6UnjveNMgk4ukDQJdTGvOQ==", "updater": "rhel-vex", "name": "CVE-2026-18739", "description": "A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.", "issued": "2026-08-03T18:46:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-18739 https://bugzilla.redhat.com/show_bug.cgi?id=2510737 https://www.cve.org/CVERecord?id=CVE-2026-18739 https://nvd.nist.gov/vuln/detail/CVE-2026-18739 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18739.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "popt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6dd3s2x6XRSOCR1hRF275Q==": { "id": "6dd3s2x6XRSOCR1hRF275Q==", "updater": "osv/go", "name": "GO-2026-4865", "description": "JsBraceDepth Context Tracking Bugs (XSS) in html/template", "issued": "2026-04-07T22:53:49Z", "links": "https://go.dev/cl/763762 https://go.dev/issue/78331 https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU https://osv.dev/vulnerability/BIT-golang-2026-32289 https://osv.dev/vulnerability/CVE-2026-32289", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6pD/2IKN8cR6N6PBQHwPrQ==": { "id": "6pD/2IKN8cR6N6PBQHwPrQ==", "updater": "rhel-vex", "name": "CVE-2026-42766", "description": "A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42766 https://bugzilla.redhat.com/show_bug.cgi?id=2481890 https://www.cve.org/CVERecord?id=CVE-2026-42766 https://nvd.nist.gov/vuln/detail/CVE-2026-42766 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42766.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6yoZPg/otXO9Ox3LLPygPQ==": { "id": "6yoZPg/otXO9Ox3LLPygPQ==", "updater": "rhel-vex", "name": "CVE-2025-9086", "description": "An out of bounds read flaw has been discovered in the curl project. Under specific conditions the path comparison logic makes curl read outside a heap buffer boundary. This bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.", "issued": "2025-09-12T05:10:03Z", "links": "https://access.redhat.com/security/cve/CVE-2025-9086 https://bugzilla.redhat.com/show_bug.cgi?id=2394750 https://www.cve.org/CVERecord?id=CVE-2025-9086 https://nvd.nist.gov/vuln/detail/CVE-2025-9086 https://curl.se/docs/CVE-2025-9086.html https://curl.se/docs/CVE-2025-9086.json https://github.com/curl/curl/commit/c6ae07c6a541e0e96d0040afb6 https://hackerone.com/reports/3294999 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9086.json https://access.redhat.com/errata/RHSA-2025:23383", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-34.el8_10.9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "73fA3MvglACzfufm+EV8fw==": { "id": "73fA3MvglACzfufm+EV8fw==", "updater": "rhel-vex", "name": "CVE-2025-5372", "description": "A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.", "issued": "2025-06-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5372 https://bugzilla.redhat.com/show_bug.cgi?id=2369388 https://www.cve.org/CVERecord?id=CVE-2025-5372 https://nvd.nist.gov/vuln/detail/CVE-2025-5372 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5372.json https://access.redhat.com/errata/RHSA-2025:21977", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh-config", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-16.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7Fk3wVCUvtHC5JGu/YwCEw==": { "id": "7Fk3wVCUvtHC5JGu/YwCEw==", "updater": "rhel-vex", "name": "CVE-2026-54371", "description": "A flaw was found in the `attr` package. This vulnerability allows a local attacker to perform a symlink traversal attack by replacing a pathname component with a symbolic link - either during directory hierarchy traversal by `getfattr` or during backup restoration by `setfattr`, which reads and resolves full pathnames from backup files. In both cases, when these utilities are executed by a privileged process over a path controlled by the attacker, this can lead to local privilege escalation.", "issued": "2026-06-29T13:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-54371 https://bugzilla.redhat.com/show_bug.cgi?id=2490283 https://www.cve.org/CVERecord?id=CVE-2026-54371 https://nvd.nist.gov/vuln/detail/CVE-2026-54371 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "attr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7MTZYXN1wiJGDdcyRQJ1Fg==": { "id": "7MTZYXN1wiJGDdcyRQJ1Fg==", "updater": "rhel-vex", "name": "CVE-2021-35938", "description": "A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "issued": "2021-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-35938 https://bugzilla.redhat.com/show_bug.cgi?id=1964114 https://www.cve.org/CVERecord?id=CVE-2021-35938 https://nvd.nist.gov/vuln/detail/CVE-2021-35938 https://rpm.org/wiki/Releases/4.18.0 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-35938.json https://access.redhat.com/errata/RHSA-2024:0647", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "rpm", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:4.14.3-28.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7Puka2o1jq4jSr2Hekrfhg==": { "id": "7Puka2o1jq4jSr2Hekrfhg==", "updater": "rhel-vex", "name": "CVE-2026-1757", "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.", "issued": "2026-02-02T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1757 https://bugzilla.redhat.com/show_bug.cgi?id=2435940 https://www.cve.org/CVERecord?id=CVE-2026-1757 https://nvd.nist.gov/vuln/detail/CVE-2026-1757 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1757.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7bIaOY2SLxEwDeZXOjwejQ==": { "id": "7bIaOY2SLxEwDeZXOjwejQ==", "updater": "rhel-vex", "name": "CVE-2024-37370", "description": "A vulnerability was found in the MIT Kerberos 5 GSS krb5 wrap token, where an attacker can modify the plaintext Extra Count field, causing the unwrapped token to appear truncated to the application, occurs when the attacker alters the token data during transmission which can lead to improper handling of authentication tokens.", "issued": "2024-06-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-37370 https://bugzilla.redhat.com/show_bug.cgi?id=2294677 https://www.cve.org/CVERecord?id=CVE-2024-37370 https://nvd.nist.gov/vuln/detail/CVE-2024-37370 https://web.mit.edu/kerberos/www/krb5-1.21/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-37370.json https://access.redhat.com/errata/RHSA-2024:5312", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-29.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7lpl5ajwZr5ADf7iLSBbkA==": { "id": "7lpl5ajwZr5ADf7iLSBbkA==", "updater": "osv/go", "name": "GO-2023-1987", "description": "Large RSA keys can cause high CPU usage in crypto/tls", "issued": "2023-08-02T17:25:58Z", "links": "https://go.dev/issue/61460 https://go.dev/cl/515257 https://groups.google.com/g/golang-announce/c/X0b6CsSAaYI/m/Efv5DbZ9AwAJ https://osv.dev/vulnerability/BIT-golang-2023-29409 https://osv.dev/vulnerability/CVE-2023-29409", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8/XTjhUL73PmS+RFgd07FA==": { "id": "8/XTjhUL73PmS+RFgd07FA==", "updater": "rhel-vex", "name": "CVE-2024-33601", "description": "A flaw was found in the glibc netgroup cache. The netgroup cache uses xmalloc/xrealloc and may terminate the process due to a memory allocation failure.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33601 https://bugzilla.redhat.com/show_bug.cgi?id=2277205 https://www.cve.org/CVERecord?id=CVE-2024-33601 https://nvd.nist.gov/vuln/detail/CVE-2024-33601 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33601.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "86unVXyTxdffdcXWZTYw5g==": { "id": "86unVXyTxdffdcXWZTYw5g==", "updater": "rhel-vex", "name": "CVE-2023-0465", "description": "A flaw was found in OpenSSL. Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. OpenSSL and other certificate policy checks silently ignore invalid certificate policies in leaf certificates that are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.", "issued": "2023-03-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-0465 https://bugzilla.redhat.com/show_bug.cgi?id=2182561 https://www.cve.org/CVERecord?id=CVE-2023-0465 https://nvd.nist.gov/vuln/detail/CVE-2023-0465 https://www.openssl.org/news/secadv/20230328.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0465.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8D3i4K1ylUr5dGk9imV9zA==": { "id": "8D3i4K1ylUr5dGk9imV9zA==", "updater": "rhel-vex", "name": "CVE-2025-69420", "description": "A flaw was found in OpenSSL. A type confusion vulnerability exists in the TimeStamp Response verification code, where an ASN1_TYPE union member is accessed without proper type validation. A remote attacker can exploit this by providing a malformed TimeStamp Response to an application that verifies timestamp responses. This can lead to an invalid or NULL pointer dereference, resulting in a Denial of Service (DoS) due to an application crash.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-69420 https://bugzilla.redhat.com/show_bug.cgi?id=2430388 https://www.cve.org/CVERecord?id=CVE-2025-69420 https://nvd.nist.gov/vuln/detail/CVE-2025-69420 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69420.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8KH5GLr9/x1y00jN/HK8MA==": { "id": "8KH5GLr9/x1y00jN/HK8MA==", "updater": "rhel-vex", "name": "CVE-2023-2953", "description": "A vulnerability was found in OpenLDAP, in ber_memalloc_x() function, leading to a null pointer dereference. This flaw can result in reduced system memory and cause LDAP authentication failures. The impact is primarily a disruption in authentication processes, which may hinder user access or service operations relying on LDAP for authentication.", "issued": "2023-05-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-2953 https://bugzilla.redhat.com/show_bug.cgi?id=2210651 https://www.cve.org/CVERecord?id=CVE-2023-2953 https://nvd.nist.gov/vuln/detail/CVE-2023-2953 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-2953.json https://access.redhat.com/errata/RHSA-2024:4264", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openldap", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.4.46-19.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8KJb4x3mXgChaQULEsid2A==": { "id": "8KJb4x3mXgChaQULEsid2A==", "updater": "rhel-vex", "name": "CVE-2025-15224", "description": "A flaw was found in libcurl. When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15224 https://bugzilla.redhat.com/show_bug.cgi?id=2426410 https://www.cve.org/CVERecord?id=CVE-2025-15224 https://nvd.nist.gov/vuln/detail/CVE-2025-15224 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15224.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8OaUZ5FEonzWI2BSl0pn5Q==": { "id": "8OaUZ5FEonzWI2BSl0pn5Q==", "updater": "osv/go", "name": "GO-2026-4981", "description": "Crash when handling long CNAME response in net", "issued": "2026-05-07T19:21:40Z", "links": "https://go.dev/issue/78803 https://go.dev/cl/767860 https://groups.google.com/g/golang-announce/c/qcCIEXso47M https://osv.dev/vulnerability/BIT-golang-2026-33811 https://osv.dev/vulnerability/CVE-2026-33811", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8Sec+JvKiQWGqYCOBdZhjg==": { "id": "8Sec+JvKiQWGqYCOBdZhjg==", "updater": "rhel-vex", "name": "CVE-2025-5918", "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5918 https://bugzilla.redhat.com/show_bug.cgi?id=2370877 https://www.cve.org/CVERecord?id=CVE-2025-5918 https://nvd.nist.gov/vuln/detail/CVE-2025-5918 https://github.com/libarchive/libarchive/pull/2584 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5918.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8TFgFlUtgZLpn2Ire1885g==": { "id": "8TFgFlUtgZLpn2Ire1885g==", "updater": "rhel-vex", "name": "CVE-2023-6918", "description": "A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.", "issued": "2023-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-6918 https://bugzilla.redhat.com/show_bug.cgi?id=2254997 https://www.cve.org/CVERecord?id=CVE-2023-6918 https://nvd.nist.gov/vuln/detail/CVE-2023-6918 https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases/ https://www.libssh.org/security/advisories/CVE-2023-6918.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6918.json https://access.redhat.com/errata/RHSA-2024:3233", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh-config", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-14.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8U0+E/NmfCj/l/7kqufLug==": { "id": "8U0+E/NmfCj/l/7kqufLug==", "updater": "rhel-vex", "name": "CVE-2021-35939", "description": "It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "issued": "2021-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-35939 https://bugzilla.redhat.com/show_bug.cgi?id=1964129 https://www.cve.org/CVERecord?id=CVE-2021-35939 https://nvd.nist.gov/vuln/detail/CVE-2021-35939 https://rpm.org/wiki/Releases/4.18.0 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-35939.json https://access.redhat.com/errata/RHSA-2024:0647", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "rpm-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:4.14.3-28.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8WDcymWmuQ3Sn9ymHvtn4Q==": { "id": "8WDcymWmuQ3Sn9ymHvtn4Q==", "updater": "rhel-vex", "name": "CVE-2026-13757", "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.", "issued": "2026-06-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13757 https://bugzilla.redhat.com/show_bug.cgi?id=2494556 https://www.cve.org/CVERecord?id=CVE-2026-13757 https://nvd.nist.gov/vuln/detail/CVE-2026-13757 https://github.com/advisories/GHSA-p2wm-69qx-x25w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13757.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "p11-kit", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8ZxbhBIT+9Mj99/XbMpLSQ==": { "id": "8ZxbhBIT+9Mj99/XbMpLSQ==", "updater": "rhel-vex", "name": "CVE-2024-0232", "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.", "issued": "2023-10-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-0232 https://bugzilla.redhat.com/show_bug.cgi?id=2243754 https://www.cve.org/CVERecord?id=CVE-2024-0232 https://nvd.nist.gov/vuln/detail/CVE-2024-0232 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0232.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8dbu5kTJCKmDz6HN0xziDw==": { "id": "8dbu5kTJCKmDz6HN0xziDw==", "updater": "osv/go", "name": "GO-2023-1621", "description": "Incorrect calculation on P256 curves in crypto/internal/nistec", "issued": "2023-03-08T19:30:53Z", "links": "https://go.dev/issue/58647 https://go.dev/cl/471255 https://groups.google.com/g/golang-announce/c/3-TpUx48iQY https://osv.dev/vulnerability/BIT-golang-2023-24532 https://osv.dev/vulnerability/CVE-2023-24532", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.7", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8nqmUoZ94lq9djmfK/BUAw==": { "id": "8nqmUoZ94lq9djmfK/BUAw==", "updater": "rhel-vex", "name": "CVE-2021-35939", "description": "It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "issued": "2021-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-35939 https://bugzilla.redhat.com/show_bug.cgi?id=1964129 https://www.cve.org/CVERecord?id=CVE-2021-35939 https://nvd.nist.gov/vuln/detail/CVE-2021-35939 https://rpm.org/wiki/Releases/4.18.0 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-35939.json https://access.redhat.com/errata/RHSA-2024:0647", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "rpm", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:4.14.3-28.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8rDgIikh0LbAtcEOjHed4Q==": { "id": "8rDgIikh0LbAtcEOjHed4Q==", "updater": "rhel-vex", "name": "CVE-2026-6368", "description": "A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS).", "issued": "2026-08-10T18:40:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6368 https://bugzilla.redhat.com/show_bug.cgi?id=2513608 https://www.cve.org/CVERecord?id=CVE-2026-6368 https://nvd.nist.gov/vuln/detail/CVE-2026-6368 https://sourceware.org/bugzilla/show_bug.cgi?id=34090 https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6368.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8xq5LOlvJAlBMFm8t08VOg==": { "id": "8xq5LOlvJAlBMFm8t08VOg==", "updater": "osv/go", "name": "GO-2025-4009", "description": "Quadratic complexity when parsing some invalid inputs in encoding/pem", "issued": "2025-10-29T21:49:55Z", "links": "https://go.dev/issue/75676 https://go.dev/cl/709858 https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI https://osv.dev/vulnerability/BIT-golang-2025-61723 https://osv.dev/vulnerability/CVE-2025-61723", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "97PwDrD8knMveLXwKCvQjA==": { "id": "97PwDrD8knMveLXwKCvQjA==", "updater": "rhel-vex", "name": "CVE-2026-22795", "description": "A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a Denial of Service (DoS) by tricking a user or application into processing a maliciously crafted PKCS#12 (Personal Information Exchange Syntax Standard) file. The vulnerability leads to an invalid or NULL pointer dereference, resulting in an application crash.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-22795 https://bugzilla.redhat.com/show_bug.cgi?id=2430389 https://www.cve.org/CVERecord?id=CVE-2026-22795 https://nvd.nist.gov/vuln/detail/CVE-2026-22795 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22795.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9TZ4yQhaDigJqc3QE7rzRQ==": { "id": "9TZ4yQhaDigJqc3QE7rzRQ==", "updater": "rhel-vex", "name": "CVE-2024-33602", "description": "A flaw was found in the glibc netgroup cache. The buffer-resizing code in addgetnetgrentX assumes that all string pointers point into the supplied buffer. This can potentially lead to memory corruption and cause a crash.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33602 https://bugzilla.redhat.com/show_bug.cgi?id=2277206 https://www.cve.org/CVERecord?id=CVE-2024-33602 https://nvd.nist.gov/vuln/detail/CVE-2024-33602 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33602.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9ZyVWoLQ5lFBoIjtu4uEOQ==": { "id": "9ZyVWoLQ5lFBoIjtu4uEOQ==", "updater": "rhel-vex", "name": "CVE-2024-33599", "description": "A stack-based buffer overflow flaw was found in the glibc netgroup cache. In certain conditions, its possible to trigger a stack-based buffer overflow condition that can lead to a denial of service and potentially other malicious actions that impact confidentiality and integrity.", "issued": "2024-04-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33599 https://bugzilla.redhat.com/show_bug.cgi?id=2277202 https://www.cve.org/CVERecord?id=CVE-2024-33599 https://nvd.nist.gov/vuln/detail/CVE-2024-33599 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33599.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9v7GjmoBpXznA/4f7FLNTw==": { "id": "9v7GjmoBpXznA/4f7FLNTw==", "updater": "rhel-vex", "name": "CVE-2024-26458", "description": "A memory leak flaw was found in krb5 in /krb5/src/lib/rpc/pmap_rmt.c. This issue can lead to a denial of service through memory exhaustion.", "issued": "2024-02-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-26458 https://bugzilla.redhat.com/show_bug.cgi?id=2266731 https://www.cve.org/CVERecord?id=CVE-2024-26458 https://nvd.nist.gov/vuln/detail/CVE-2024-26458 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-26458.json https://access.redhat.com/errata/RHSA-2024:3268", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-27.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A/8WFcBgNb2KqM+8djtoNg==": { "id": "A/8WFcBgNb2KqM+8djtoNg==", "updater": "rhel-vex", "name": "CVE-2022-27776", "description": "A vulnerability was found in curl. This security flaw allows leak authentication or cookie header data on HTTP redirects to the same host but another port number. Sending the same set of headers to a server on a different port number is a problem for applications that pass on custom `Authorization:` or `Cookie:`headers. Those headers often contain privacy-sensitive information or data.", "issued": "2022-04-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-27776 https://bugzilla.redhat.com/show_bug.cgi?id=2078408 https://www.cve.org/CVERecord?id=CVE-2022-27776 https://nvd.nist.gov/vuln/detail/CVE-2022-27776 https://curl.se/docs/CVE-2022-27776.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-27776.json https://access.redhat.com/errata/RHSA-2022:5313", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A0ZMrO+gsPP+1kjH7JYgNw==": { "id": "A0ZMrO+gsPP+1kjH7JYgNw==", "updater": "rhel-vex", "name": "CVE-2024-11053", "description": "A flaw was found in curl. A logic error when processing credentials from the .netrc file while performing redirects allows the transfer of credentials from the original host to the followed-to host under certain circumstances, leaking the credentials to the followed-to host.", "issued": "2024-12-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-11053 https://bugzilla.redhat.com/show_bug.cgi?id=2331191 https://www.cve.org/CVERecord?id=CVE-2024-11053 https://nvd.nist.gov/vuln/detail/CVE-2024-11053 https://curl.se/docs/CVE-2024-11053.html https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-11053.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AE8Cp1u8I9t52OYW7oGU4w==": { "id": "AE8Cp1u8I9t52OYW7oGU4w==", "updater": "rhel-vex", "name": "CVE-2024-57970", "description": "A flaw was found in the libarchive library. A specially-crafted tar file may trigger a head-based buffer over-read condition due to incorrect handling of truncation in the middle of a long GNU linkname. This issue can cause an application crash leading to a denial of service.", "issued": "2025-02-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-57970 https://bugzilla.redhat.com/show_bug.cgi?id=2345954 https://www.cve.org/CVERecord?id=CVE-2024-57970 https://nvd.nist.gov/vuln/detail/CVE-2024-57970 https://github.com/libarchive/libarchive/issues/2415 https://github.com/libarchive/libarchive/pull/2422 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-57970.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AFfQXLrpt1jw7bczIIvo6Q==": { "id": "AFfQXLrpt1jw7bczIIvo6Q==", "updater": "rhel-vex", "name": "CVE-2018-1000879", "description": "A vulnerability was found in libarchive, where a NULL pointer dereference in the archive_acl_from_text_l function in libarchive/archive_acl.c can lead to a denial of service, a remote attacker could exploit this flaw by persuading a victim to open a specially crafted file, causing the application to crash.", "issued": "2018-11-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-1000879 https://bugzilla.redhat.com/show_bug.cgi?id=1663890 https://www.cve.org/CVERecord?id=CVE-2018-1000879 https://nvd.nist.gov/vuln/detail/CVE-2018-1000879 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-1000879.json", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AKK15am6qQUGnIgHe5PZkQ==": { "id": "AKK15am6qQUGnIgHe5PZkQ==", "updater": "rhel-vex", "name": "CVE-2023-4813", "description": "A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.", "issued": "2022-03-01T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4813 https://bugzilla.redhat.com/show_bug.cgi?id=2237798 https://www.cve.org/CVERecord?id=CVE-2023-4813 https://nvd.nist.gov/vuln/detail/CVE-2023-4813 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4813.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "APwVrIce77Ku6UBCO29tAg==": { "id": "APwVrIce77Ku6UBCO29tAg==", "updater": "rhel-vex", "name": "CVE-2023-27536", "description": "A flaw was found in the Curl package. Libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, the GSS delegation setting was left out from the configuration match checks, making them match too easily, affecting krb5/kerberos/negotiate/GSSAPI transfers.", "issued": "2023-03-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-27536 https://bugzilla.redhat.com/show_bug.cgi?id=2179092 https://www.cve.org/CVERecord?id=CVE-2023-27536 https://nvd.nist.gov/vuln/detail/CVE-2023-27536 https://curl.se/docs/CVE-2023-27536.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27536.json https://access.redhat.com/errata/RHSA-2023:4523", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-30.el8_8.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AZQ9MHTiNLYiRU7sYZlVGw==": { "id": "AZQ9MHTiNLYiRU7sYZlVGw==", "updater": "rhel-vex", "name": "CVE-2022-4899", "description": "A vulnerability was found in zstd. This flaw allows an attacker to supply an empty string as an argument to the command line tool to cause a buffer overrun.", "issued": "2022-07-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-4899 https://bugzilla.redhat.com/show_bug.cgi?id=2179864 https://www.cve.org/CVERecord?id=CVE-2022-4899 https://nvd.nist.gov/vuln/detail/CVE-2022-4899 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-4899.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "zstd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ahnxi92nCGMJDrFfn/I6Wg==": { "id": "Ahnxi92nCGMJDrFfn/I6Wg==", "updater": "rhel-vex", "name": "CVE-2024-34397", "description": "A flaw was found in GNOME GLib. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This issue could lead to the GDBus-based client behaving incorrectly with an application-dependent impact.", "issued": "2024-05-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-34397 https://bugzilla.redhat.com/show_bug.cgi?id=2279632 https://www.cve.org/CVERecord?id=CVE-2024-34397 https://nvd.nist.gov/vuln/detail/CVE-2024-34397 https://gitlab.gnome.org/GNOME/glib/-/issues/3268 https://www.openwall.com/lists/oss-security/2024/05/07/5 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-34397.json https://access.redhat.com/errata/RHSA-2025:11327", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.56.4-166.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AkM7UIP5BtWgOljRb7sV2w==": { "id": "AkM7UIP5BtWgOljRb7sV2w==", "updater": "osv/go", "name": "GO-2026-4946", "description": "Inefficient policy validation in crypto/x509", "issued": "2026-04-07T22:53:49Z", "links": "https://go.dev/cl/758061 https://go.dev/issue/78281 https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU https://osv.dev/vulnerability/BIT-golang-2026-32281 https://osv.dev/vulnerability/CVE-2026-32281", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ao/QxV1G+txY/o+fZamBDw==": { "id": "Ao/QxV1G+txY/o+fZamBDw==", "updater": "rhel-vex", "name": "CVE-2025-4802", "description": "A flaw was found in the glibc library. A statically linked setuid binary that calls dlopen(), including internal dlopen() calls after setlocale() or calls to NSS functions such as getaddrinfo(), may incorrectly search LD_LIBRARY_PATH to determine which library to load, allowing a local attacker to load malicious shared libraries, escalate privileges and execute arbitrary code.", "issued": "2025-05-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-4802 https://bugzilla.redhat.com/show_bug.cgi?id=2367468 https://www.cve.org/CVERecord?id=CVE-2025-4802 https://nvd.nist.gov/vuln/detail/CVE-2025-4802 https://inbox.sourceware.org/libc-announce/3ac997b0-28a5-4129-af53-675efe4c2dec@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=32976 https://www.openwall.com/lists/oss-security/2025/05/16/7 https://www.openwall.com/lists/oss-security/2025/05/17/2 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4802.json https://access.redhat.com/errata/RHSA-2025:8686", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.22", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AsUlQvbhYUzI8ZRGAIAAkw==": { "id": "AsUlQvbhYUzI8ZRGAIAAkw==", "updater": "rhel-vex", "name": "CVE-2026-8932", "description": "A flaw was found in curl. The libcurl library, used for transferring data with URLs, could improperly reuse existing network connections. This occurred even when changes to mutual Transport Layer Security (mTLS) settings, particularly those for client certificates, should have prevented such reuse. This issue could lead to a security feature bypass, where a client might use a connection with an unintended or weaker security configuration, potentially compromising the integrity or confidentiality of data.", "issued": "2026-07-03T06:16:30Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8932 https://bugzilla.redhat.com/show_bug.cgi?id=2496759 https://www.cve.org/CVERecord?id=CVE-2026-8932 https://nvd.nist.gov/vuln/detail/CVE-2026-8932 https://curl.se/docs/CVE-2026-8932.html https://curl.se/docs/CVE-2026-8932.json https://hackerone.com/reports/3733910 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8932.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "B1yLegFFcSieySsw74cDww==": { "id": "B1yLegFFcSieySsw74cDww==", "updater": "osv/go", "name": "GO-2026-6088", "description": "Add recursion depth guard during decode in encoding/xml", "issued": "2026-08-13T21:43:54Z", "links": "https://go.dev/issue/80481 https://go.dev/cl/803320 https://groups.google.com/g/golang-announce/c/94pEornpRlI https://osv.dev/vulnerability/CVE-2026-56859", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.13", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "B3GLjxsk0fvju/+IzG5Prg==": { "id": "B3GLjxsk0fvju/+IzG5Prg==", "updater": "rhel-vex", "name": "CVE-2023-6918", "description": "A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.", "issued": "2023-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-6918 https://bugzilla.redhat.com/show_bug.cgi?id=2254997 https://www.cve.org/CVERecord?id=CVE-2023-6918 https://nvd.nist.gov/vuln/detail/CVE-2023-6918 https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases/ https://www.libssh.org/security/advisories/CVE-2023-6918.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6918.json https://access.redhat.com/errata/RHSA-2024:3233", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh-config", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-14.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BUzSiF4P8l2fba8+4vytIw==": { "id": "BUzSiF4P8l2fba8+4vytIw==", "updater": "rhel-vex", "name": "CVE-2023-1667", "description": "A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.", "issued": "2023-04-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-1667 https://bugzilla.redhat.com/show_bug.cgi?id=2182199 https://www.cve.org/CVERecord?id=CVE-2023-1667 https://nvd.nist.gov/vuln/detail/CVE-2023-1667 http://www.libssh.org/security/advisories/CVE-2023-1667.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1667.json https://access.redhat.com/errata/RHSA-2023:3839", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh-config", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-10.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BV++s35Ur4bQRS6HK0QCIA==": { "id": "BV++s35Ur4bQRS6HK0QCIA==", "updater": "rhel-vex", "name": "CVE-2026-31789", "description": "A flaw was found in OpenSSL. This vulnerability, a heap buffer overflow, affects 32-bit systems when processing an unusually large X.509 certificate. If an application or service attempts to print or log such a specially crafted certificate, it could lead to a system crash or potentially allow an attacker to execute arbitrary code. This issue is considered low severity due to the specific conditions required for exploitation, including the need for an extremely large certificate and a 32-bit operating environment.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-31789 https://bugzilla.redhat.com/show_bug.cgi?id=2451095 https://www.cve.org/CVERecord?id=CVE-2026-31789 https://nvd.nist.gov/vuln/detail/CVE-2026-31789 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31789.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BfjzSlo8p3Mkdy2LzyRaeg==": { "id": "BfjzSlo8p3Mkdy2LzyRaeg==", "updater": "rhel-vex", "name": "CVE-2025-14104", "description": "A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.", "issued": "2025-12-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1852", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libblkid", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.32.1-48.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BooDzA4nzaDI1l3E5zAHgg==": { "id": "BooDzA4nzaDI1l3E5zAHgg==", "updater": "rhel-vex", "name": "CVE-2021-3997", "description": "A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.", "issued": "2022-01-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-3997 https://bugzilla.redhat.com/show_bug.cgi?id=2024639 https://www.cve.org/CVERecord?id=CVE-2021-3997 https://nvd.nist.gov/vuln/detail/CVE-2021-3997 https://www.openwall.com/lists/oss-security/2022/01/10/2 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-3997.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "C/7x/dKLKsO/O2OclcdjjA==": { "id": "C/7x/dKLKsO/O2OclcdjjA==", "updater": "osv/go", "name": "GO-2023-1570", "description": "Panic on large handshake records in crypto/tls", "issued": "2023-02-16T22:24:51Z", "links": "https://go.dev/issue/58001 https://go.dev/cl/468125 https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E https://osv.dev/vulnerability/BIT-golang-2022-41724 https://osv.dev/vulnerability/CVE-2022-41724", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.6", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "C8MCCElz0FGYpiXZKAjC8Q==": { "id": "C8MCCElz0FGYpiXZKAjC8Q==", "updater": "osv/go", "name": "GO-2023-1753", "description": "Improper handling of empty HTML attributes in html/template", "issued": "2023-05-05T21:10:24Z", "links": "https://go.dev/issue/59722 https://go.dev/cl/491617 https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU https://osv.dev/vulnerability/BIT-golang-2023-29400 https://osv.dev/vulnerability/CVE-2023-29400", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "C8yN/CDEhgO0iUoSyqjl2Q==": { "id": "C8yN/CDEhgO0iUoSyqjl2Q==", "updater": "osv/go", "name": "GO-2025-3751", "description": "Sensitive headers not cleared on cross-origin redirect in net/http", "issued": "2025-06-11T16:23:58Z", "links": "https://go.dev/cl/679257 https://go.dev/issue/73816 https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A https://osv.dev/vulnerability/BIT-golang-2025-4673 https://osv.dev/vulnerability/CVE-2025-4673", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.23.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CFJplXTrY46a5BwwNnwfeQ==": { "id": "CFJplXTrY46a5BwwNnwfeQ==", "updater": "rhel-vex", "name": "CVE-2022-2526", "description": "A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.", "issued": "2022-08-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-2526 https://bugzilla.redhat.com/show_bug.cgi?id=2109926 https://www.cve.org/CVERecord?id=CVE-2022-2526 https://nvd.nist.gov/vuln/detail/CVE-2022-2526 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2526.json https://access.redhat.com/errata/RHSA-2022:6206", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "systemd-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:239-58.el8_6.4", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CNBhlzOLGRw6hilca+FCgA==": { "id": "CNBhlzOLGRw6hilca+FCgA==", "updater": "rhel-vex", "name": "CVE-2024-33602", "description": "A flaw was found in the glibc netgroup cache. The buffer-resizing code in addgetnetgrentX assumes that all string pointers point into the supplied buffer. This can potentially lead to memory corruption and cause a crash.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33602 https://bugzilla.redhat.com/show_bug.cgi?id=2277206 https://www.cve.org/CVERecord?id=CVE-2024-33602 https://nvd.nist.gov/vuln/detail/CVE-2024-33602 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33602.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CPZo3oXfySRcVVjDJkrS3g==": { "id": "CPZo3oXfySRcVVjDJkrS3g==", "updater": "rhel-vex", "name": "CVE-2019-9937", "description": "A vulnerability was found in SQLite due to a NULL pointer dereference in the fts5ChunkIterate function within sqlite3.c, where an attacker could exploit this flaw by creating a specially crafted table, causing the application to crash and resulting in a denial of service condition.", "issued": "2019-03-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-9937 https://bugzilla.redhat.com/show_bug.cgi?id=1692357 https://www.cve.org/CVERecord?id=CVE-2019-9937 https://nvd.nist.gov/vuln/detail/CVE-2019-9937 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-9937.json", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CYdgitwltENTL9rtsuaouQ==": { "id": "CYdgitwltENTL9rtsuaouQ==", "updater": "rhel-vex", "name": "CVE-2025-6965", "description": "A memory corruption flaw was found in SQLite. Under specific conditions a query can be generated where the number of aggregate terms could exceed the number of columns available. This issue could lead to memory corruption and subsequent unintended behavior.", "issued": "2025-07-15T13:44:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-6965 https://bugzilla.redhat.com/show_bug.cgi?id=2380149 https://www.cve.org/CVERecord?id=CVE-2025-6965 https://nvd.nist.gov/vuln/detail/CVE-2025-6965 https://www.oracle.com/security-alerts/cpujan2026.html#AppendixMSQL https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6965.json https://access.redhat.com/errata/RHSA-2025:12010", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L", "normalized_severity": "High", "package": { "id": "", "name": "sqlite-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.26.0-20.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Cbzd/bqnZLJIbxJ/1EtUpA==": { "id": "Cbzd/bqnZLJIbxJ/1EtUpA==", "updater": "osv/go", "name": "GO-2023-2382", "description": "Denial of service via chunk extensions in net/http", "issued": "2023-12-06T16:22:36Z", "links": "https://go.dev/issue/64433 https://go.dev/cl/547335 https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ https://osv.dev/vulnerability/BIT-golang-2023-39326 https://osv.dev/vulnerability/CVE-2023-39326", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.20.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Cc4ne2QMiCdzg9ej7Ay22A==": { "id": "Cc4ne2QMiCdzg9ej7Ay22A==", "updater": "osv/go", "name": "GO-2026-4870", "description": "Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls", "issued": "2026-04-07T22:53:49Z", "links": "https://go.dev/cl/763767 https://go.dev/issue/78334 https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU https://osv.dev/vulnerability/BIT-golang-2026-32283 https://osv.dev/vulnerability/CVE-2026-32283", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CmGl35oJyKxCfItoqDiYoQ==": { "id": "CmGl35oJyKxCfItoqDiYoQ==", "updater": "rhel-vex", "name": "CVE-2026-15588", "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.", "issued": "2026-07-12T10:10:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-15588 https://bugzilla.redhat.com/show_bug.cgi?id=2499675 https://www.cve.org/CVERecord?id=CVE-2026-15588 https://nvd.nist.gov/vuln/detail/CVE-2026-15588 https://gitlab.gnome.org/GNOME/glib/-/issues/3985 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15588.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CwmELSAfO/DM/HghGDWwow==": { "id": "CwmELSAfO/DM/HghGDWwow==", "updater": "rhel-vex", "name": "CVE-2026-6653", "description": "A flaw was found in libxml2. A remote attacker can exploit a use-after-free vulnerability in the `xmlParseInternalSubset` function by providing maliciously crafted XML input. This improper handling of entity resolution can lead to a denial-of-service (DoS), making the affected system or application unavailable.", "issued": "2026-06-22T12:40:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6653 https://bugzilla.redhat.com/show_bug.cgi?id=2491354 https://www.cve.org/CVERecord?id=CVE-2026-6653 https://nvd.nist.gov/vuln/detail/CVE-2026-6653 https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260 https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6653.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DAA1dKzv1qLCntHLpPLIog==": { "id": "DAA1dKzv1qLCntHLpPLIog==", "updater": "osv/go", "name": "GO-2026-4977", "description": "Quadratic string concatenation in consumePhrase in net/mail", "issued": "2026-05-07T19:21:40Z", "links": "https://go.dev/issue/78987 https://go.dev/cl/771520 https://groups.google.com/g/golang-announce/c/qcCIEXso47M https://osv.dev/vulnerability/BIT-golang-2026-42499 https://osv.dev/vulnerability/CVE-2026-42499", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DDWmqlxBSfXi2KJJ5mwTNg==": { "id": "DDWmqlxBSfXi2KJJ5mwTNg==", "updater": "rhel-vex", "name": "CVE-2025-60753", "description": "A vulnerability in apply_substitution() function in libarchive's bsdtar allows crafted -s substitution rules to repeatedly match a zero-length substring and append replacements without advancing the input pointer. When the rule uses the global /g flag (or an explicitly empty pattern), this leads to unbounded output allocation and eventual process OOM (Denial of Service). Upgrade to libarchive 3.8.1 or apply a patch that prevents zero-length match loops or rejects empty patterns.", "issued": "2025-11-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-60753 https://bugzilla.redhat.com/show_bug.cgi?id=2412648 https://www.cve.org/CVERecord?id=CVE-2025-60753 https://nvd.nist.gov/vuln/detail/CVE-2025-60753 https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753 https://github.com/libarchive/libarchive/issues/2725 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-60753.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DcFGNfCGa6QmD0IQUzLpCQ==": { "id": "DcFGNfCGa6QmD0IQUzLpCQ==", "updater": "rhel-vex", "name": "CVE-2025-15281", "description": "A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service.", "issued": "2026-01-20T13:22:46Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15281 https://bugzilla.redhat.com/show_bug.cgi?id=2431196 https://www.cve.org/CVERecord?id=CVE-2025-15281 https://nvd.nist.gov/vuln/detail/CVE-2025-15281 https://sourceware.org/bugzilla/show_bug.cgi?id=33814 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15281.json https://access.redhat.com/errata/RHSA-2026:4772", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.31", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DdbtHYUAFK3EvhnE38LOBw==": { "id": "DdbtHYUAFK3EvhnE38LOBw==", "updater": "rhel-vex", "name": "CVE-2026-57062", "description": "A flaw in GnuPG's gpgsm component improperly handles the Cryptographic Message Syntax (CMS) format for AES-GCM. By accepting an authentication tag length of 4 bytes instead of the required 12 bytes, this vulnerability allows for a low-impact data integrity issue where the cryptographic validity of messages could be compromised.", "issued": "2026-06-23T17:26:25Z", "links": "https://access.redhat.com/security/cve/CVE-2026-57062 https://bugzilla.redhat.com/show_bug.cgi?id=2491859 https://www.cve.org/CVERecord?id=CVE-2026-57062 https://nvd.nist.gov/vuln/detail/CVE-2026-57062 https://blog.calif.io/p/how-to-format-a-ciphertext https://www.gnupg.org/download/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57062.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DkHpdzAuAlElCotBlgVgPA==": { "id": "DkHpdzAuAlElCotBlgVgPA==", "updater": "rhel-vex", "name": "CVE-2026-18839", "description": "An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.", "issued": "2026-08-05T18:56:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-18839 https://bugzilla.redhat.com/show_bug.cgi?id=2511010 https://www.cve.org/CVERecord?id=CVE-2026-18839 https://nvd.nist.gov/vuln/detail/CVE-2026-18839 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18839.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "popt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DluUanANT5nvELzWjLa/TA==": { "id": "DluUanANT5nvELzWjLa/TA==", "updater": "rhel-vex", "name": "CVE-2026-4046", "description": "A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).", "issued": "2026-03-30T17:16:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20587", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.37", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DoTF+GSVr6bH3qr9kb98Iw==": { "id": "DoTF+GSVr6bH3qr9kb98Iw==", "updater": "rhel-vex", "name": "CVE-2025-3360", "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.", "issued": "2025-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-3360 https://bugzilla.redhat.com/show_bug.cgi?id=2357754 https://www.cve.org/CVERecord?id=CVE-2025-3360 https://nvd.nist.gov/vuln/detail/CVE-2025-3360 https://gitlab.gnome.org/GNOME/glib/-/issues/3647 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-3360.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Dztwmkxu9NB/xbjOo2p2ZA==": { "id": "Dztwmkxu9NB/xbjOo2p2ZA==", "updater": "rhel-vex", "name": "CVE-2024-33602", "description": "A flaw was found in the glibc netgroup cache. The buffer-resizing code in addgetnetgrentX assumes that all string pointers point into the supplied buffer. This can potentially lead to memory corruption and cause a crash.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33602 https://bugzilla.redhat.com/show_bug.cgi?id=2277206 https://www.cve.org/CVERecord?id=CVE-2024-33602 https://nvd.nist.gov/vuln/detail/CVE-2024-33602 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33602.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "E+Il2jDXO1Rg5FnzzStA+A==": { "id": "E+Il2jDXO1Rg5FnzzStA+A==", "updater": "rhel-vex", "name": "CVE-2023-6918", "description": "A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.", "issued": "2023-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-6918 https://bugzilla.redhat.com/show_bug.cgi?id=2254997 https://www.cve.org/CVERecord?id=CVE-2023-6918 https://nvd.nist.gov/vuln/detail/CVE-2023-6918 https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases/ https://www.libssh.org/security/advisories/CVE-2023-6918.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6918.json https://access.redhat.com/errata/RHSA-2024:3233", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-14.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "E97yacFb4u2m5K6ETIUDAQ==": { "id": "E97yacFb4u2m5K6ETIUDAQ==", "updater": "rhel-vex", "name": "CVE-2024-2961", "description": "An out-of-bounds write flaw was found in the ISO-2022-CN-EXT plugin for glibc's iconv library. When converting from UCS4 charset, adding certain escape charterers is required to indicate where the charset was changed to the library. During this process, iconv improperly checks the boundaries of internal buffers, leading to a buffer overflow, which allows writing up to 3 bytes outside the desired memory location. This issue may allow an attacker to craft a malicious characters sequence that will trigger the out-of-bounds write and perform remote code execution, presenting a high impact to the Integrity, Confidentiality, and Availability triad.", "issued": "2024-04-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2961 https://bugzilla.redhat.com/show_bug.cgi?id=2273404 https://www.cve.org/CVERecord?id=CVE-2024-2961 https://nvd.nist.gov/vuln/detail/CVE-2024-2961 https://www.openwall.com/lists/oss-security/2024/04/17/9 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2961.json https://access.redhat.com/errata/RHSA-2024:3269", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EBRh8/O2Nfmk9fpGdTJfHg==": { "id": "EBRh8/O2Nfmk9fpGdTJfHg==", "updater": "osv/go", "name": "GO-2026-4918", "description": "Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net", "issued": "2026-05-07T19:21:40Z", "links": "https://go.dev/cl/761581 https://go.dev/cl/761640 https://go.dev/issue/78476 https://groups.google.com/g/golang-announce/c/qcCIEXso47M https://osv.dev/vulnerability/BIT-golang-2026-33814 https://osv.dev/vulnerability/CVE-2026-33814", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EDi0HswnDmwfAMMYtcTUqQ==": { "id": "EDi0HswnDmwfAMMYtcTUqQ==", "updater": "rhel-vex", "name": "CVE-2023-38546", "description": "A flaw was found in the Curl package. This flaw allows an attacker to insert cookies into a running program using libcurl if the specific series of conditions are met.", "issued": "2023-10-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-38546 https://bugzilla.redhat.com/show_bug.cgi?id=2241938 https://access.redhat.com/errata/RHSA-2024:2101 https://www.cve.org/CVERecord?id=CVE-2023-38546 https://nvd.nist.gov/vuln/detail/CVE-2023-38546 https://curl.se/docs/CVE-2023-38546.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-38546.json https://access.redhat.com/errata/RHSA-2024:1601", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-33.el8_9.5", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EFaMNy5vJQV+C1E4TtRpFw==": { "id": "EFaMNy5vJQV+C1E4TtRpFw==", "updater": "rhel-vex", "name": "CVE-2024-2961", "description": "An out-of-bounds write flaw was found in the ISO-2022-CN-EXT plugin for glibc's iconv library. When converting from UCS4 charset, adding certain escape charterers is required to indicate where the charset was changed to the library. During this process, iconv improperly checks the boundaries of internal buffers, leading to a buffer overflow, which allows writing up to 3 bytes outside the desired memory location. This issue may allow an attacker to craft a malicious characters sequence that will trigger the out-of-bounds write and perform remote code execution, presenting a high impact to the Integrity, Confidentiality, and Availability triad.", "issued": "2024-04-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2961 https://bugzilla.redhat.com/show_bug.cgi?id=2273404 https://www.cve.org/CVERecord?id=CVE-2024-2961 https://nvd.nist.gov/vuln/detail/CVE-2024-2961 https://www.openwall.com/lists/oss-security/2024/04/17/9 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2961.json https://access.redhat.com/errata/RHSA-2024:3269", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EKs36DFwHVCzU/cF0Be9pQ==": { "id": "EKs36DFwHVCzU/cF0Be9pQ==", "updater": "rhel-vex", "name": "CVE-2023-29499", "description": "A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.", "issued": "2022-12-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-29499 https://bugzilla.redhat.com/show_bug.cgi?id=2211828 https://www.cve.org/CVERecord?id=CVE-2023-29499 https://nvd.nist.gov/vuln/detail/CVE-2023-29499 https://gitlab.gnome.org/GNOME/glib/-/issues/2794 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-29499.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EP6GBY33NlRo5j/mmDBLxw==": { "id": "EP6GBY33NlRo5j/mmDBLxw==", "updater": "osv/go", "name": "GO-2025-3750", "description": "Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscall", "issued": "2025-06-11T16:59:06Z", "links": "https://go.dev/cl/672396 https://go.dev/issue/73702 https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A https://osv.dev/vulnerability/BIT-golang-2025-0913 https://osv.dev/vulnerability/CVE-2025-0913", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.23.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EiJx6rOT8KoLX+Wu7/N6HQ==": { "id": "EiJx6rOT8KoLX+Wu7/N6HQ==", "updater": "rhel-vex", "name": "CVE-2025-27113", "description": "A flaw was found in libxml2. This vulnerability allows a NULL pointer dereference, leading to a potential crash or denial of service via a crafted XML pattern.", "issued": "2025-02-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-27113 https://bugzilla.redhat.com/show_bug.cgi?id=2346410 https://www.cve.org/CVERecord?id=CVE-2025-27113 https://nvd.nist.gov/vuln/detail/CVE-2025-27113 https://gitlab.gnome.org/GNOME/libxml2/-/issues/861 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-27113.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EiL50P2QSOoRA18XAAH6Pg==": { "id": "EiL50P2QSOoRA18XAAH6Pg==", "updater": "rhel-vex", "name": "CVE-2023-32665", "description": "A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.", "issued": "2022-12-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-32665 https://bugzilla.redhat.com/show_bug.cgi?id=2211827 https://www.cve.org/CVERecord?id=CVE-2023-32665 https://nvd.nist.gov/vuln/detail/CVE-2023-32665 https://gitlab.gnome.org/GNOME/glib/-/issues/2121 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-32665.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ElIjMFAz33tt/XVMysRkdA==": { "id": "ElIjMFAz33tt/XVMysRkdA==", "updater": "rhel-vex", "name": "CVE-2026-0988", "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0988 https://bugzilla.redhat.com/show_bug.cgi?id=2429886 https://www.cve.org/CVERecord?id=CVE-2026-0988 https://nvd.nist.gov/vuln/detail/CVE-2026-0988 https://gitlab.gnome.org/GNOME/glib/-/issues/3851 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0988.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Eri53zjDpZ39TFPuRdYDKw==": { "id": "Eri53zjDpZ39TFPuRdYDKw==", "updater": "rhel-vex", "name": "CVE-2026-48864", "description": "A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.", "issued": "2026-05-26T16:07:55Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48864 https://bugzilla.redhat.com/show_bug.cgi?id=2460425 https://www.cve.org/CVERecord?id=CVE-2026-48864 https://nvd.nist.gov/vuln/detail/CVE-2026-48864 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48864.json https://access.redhat.com/errata/RHSA-2026:36730", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libsolv", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.7.20-7.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Eyr9WSXlMOV35hvg7CeJKg==": { "id": "Eyr9WSXlMOV35hvg7CeJKg==", "updater": "osv/go", "name": "GO-2026-6218", "description": "Avoid quadratic complexity in resolvePath in net/url", "issued": "2026-08-13T21:43:54Z", "links": "https://go.dev/cl/803681 https://go.dev/issue/80494 https://groups.google.com/g/golang-announce/c/94pEornpRlI https://osv.dev/vulnerability/CVE-2026-56860", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.13", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EzAzLccAjftKnyVlmDBV6g==": { "id": "EzAzLccAjftKnyVlmDBV6g==", "updater": "rhel-vex", "name": "CVE-2022-1292", "description": "A flaw was found in OpenSSL. The `c_rehash` script does not properly sanitize shell meta-characters to prevent command injection. Some operating systems distribute this script in a manner where it is automatically executed. This flaw allows an attacker to execute arbitrary commands with the privileges of the script on these operating systems.", "issued": "2022-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-1292 https://bugzilla.redhat.com/show_bug.cgi?id=2081494 https://www.cve.org/CVERecord?id=CVE-2022-1292 https://nvd.nist.gov/vuln/detail/CVE-2022-1292 https://www.openssl.org/news/secadv/20220503.txt https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-1292.json https://access.redhat.com/errata/RHSA-2022:5818", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-7.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EzTkSUGeeQgpxoz/kHYgqA==": { "id": "EzTkSUGeeQgpxoz/kHYgqA==", "updater": "rhel-vex", "name": "CVE-2025-32415", "description": "A flaw was found in the libxml2 library. A heap-based underflow can be triggered when a crafted XML document is validated against an XML schema with certain identity constraints or when a crafted XML schema is used, causing a crash to the application linked to the library and resulting in a denial of service.", "issued": "2025-04-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-32415 https://bugzilla.redhat.com/show_bug.cgi?id=2360768 https://www.cve.org/CVERecord?id=CVE-2025-32415 https://nvd.nist.gov/vuln/detail/CVE-2025-32415 https://gitlab.gnome.org/GNOME/libxml2/-/issues/890 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-32415.json https://access.redhat.com/errata/RHSA-2025:13203", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-21.el8_10.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "F0n/1XXyzTob8lElmXmB6g==": { "id": "F0n/1XXyzTob8lElmXmB6g==", "updater": "rhel-vex", "name": "CVE-2026-16517", "description": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.", "issued": "2026-07-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-16517 https://bugzilla.redhat.com/show_bug.cgi?id=2505492 https://www.cve.org/CVERecord?id=CVE-2026-16517 https://nvd.nist.gov/vuln/detail/CVE-2026-16517 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16517.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "F2aHNsZ7wIxMKRFoRhLULQ==": { "id": "F2aHNsZ7wIxMKRFoRhLULQ==", "updater": "rhel-vex", "name": "CVE-2026-9076", "description": "A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9076 https://bugzilla.redhat.com/show_bug.cgi?id=2481880 https://www.cve.org/CVERecord?id=CVE-2026-9076 https://nvd.nist.gov/vuln/detail/CVE-2026-9076 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9076.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FHCOXtsZkfB1HxIZ+8xgpA==": { "id": "FHCOXtsZkfB1HxIZ+8xgpA==", "updater": "osv/go", "name": "GO-2024-2687", "description": "HTTP/2 CONTINUATION flood in net/http", "issued": "2024-04-03T21:12:01Z", "links": "https://go.dev/issue/65051 https://go.dev/cl/576155 https://groups.google.com/g/golang-announce/c/YgW0sx8mN3M https://osv.dev/vulnerability/BIT-golang-2023-45288 https://osv.dev/vulnerability/CVE-2023-45288 https://osv.dev/vulnerability/GHSA-4v7x-pqxf-cx7m", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.21.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FYcmLqfShPp9H+6QnddlhQ==": { "id": "FYcmLqfShPp9H+6QnddlhQ==", "updater": "osv/go", "name": "GO-2021-0061", "description": "Denial of service in gopkg.in/yaml.v2", "issued": "2021-04-14T20:04:52Z", "links": "https://github.com/go-yaml/yaml/pull/375 https://github.com/go-yaml/yaml/commit/bb4e33bf68bf89cad44d386192cbed201f35b241 https://osv.dev/vulnerability/CVE-2021-4235 https://osv.dev/vulnerability/GHSA-r88r-gmrh-7j83", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "gopkg.in/yaml.v2", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "2.2.3", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FjCuOB8g+V6CndsJn96RJA==": { "id": "FjCuOB8g+V6CndsJn96RJA==", "updater": "rhel-vex", "name": "CVE-2025-69419", "description": "A flaw was found in OpenSSL. When processing a specially crafted PKCS#12 (Personal Information Exchange Syntax Standard) file, a remote attacker can exploit an out-of-bounds write vulnerability. This issue, occurring within the OPENSSL_uni2utf8() function, leads to memory corruption by writing data beyond its allocated buffer. Successful exploitation could result in a denial of service or potentially allow for arbitrary code execution.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-69419 https://bugzilla.redhat.com/show_bug.cgi?id=2430386 https://www.cve.org/CVERecord?id=CVE-2025-69419 https://nvd.nist.gov/vuln/detail/CVE-2025-69419 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69419.json https://access.redhat.com/errata/RHSA-2026:3042", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-15.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Fp999hDC/lucBsNHwOlp/A==": { "id": "Fp999hDC/lucBsNHwOlp/A==", "updater": "rhel-vex", "name": "CVE-2024-13176", "description": "A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected.", "issued": "2025-01-20T13:29:57Z", "links": "https://access.redhat.com/security/cve/CVE-2024-13176 https://bugzilla.redhat.com/show_bug.cgi?id=2338999 https://www.cve.org/CVERecord?id=CVE-2024-13176 https://nvd.nist.gov/vuln/detail/CVE-2024-13176 https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-13176.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FwjfnEjZvR6Y8qr6vjzDlA==": { "id": "FwjfnEjZvR6Y8qr6vjzDlA==", "updater": "osv/go", "name": "GO-2022-0956", "description": "Excessive resource consumption in gopkg.in/yaml.v2", "issued": "2022-08-29T22:15:46Z", "links": "https://github.com/go-yaml/yaml/commit/f221b8435cfb71e54062f6c6e99e9ade30b124d5 https://github.com/go-yaml/yaml/releases/tag/v2.2.4 https://osv.dev/vulnerability/CVE-2022-3064 https://osv.dev/vulnerability/GHSA-6q6q-88xp-6f2r", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "gopkg.in/yaml.v2", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "2.2.4", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FwlsVCWuXM6wdnEAE0M5tw==": { "id": "FwlsVCWuXM6wdnEAE0M5tw==", "updater": "rhel-vex", "name": "CVE-2023-0215", "description": "A use-after-free vulnerability was found in OpenSSL's BIO_new_NDEF function. The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally by OpenSSL to support the SMIME, CMS, and PKCS7 streaming capabilities, but it may also be called directly by end-user applications. The function receives a BIO from the caller, prepends a new BIO_f_asn1 filter BIO onto the front of it to form a BIO chain, and then returns the new head of the BIO chain to the caller. Under certain conditions. For example, if a CMS recipient public key is invalid, the new filter BIO is freed, and the function returns a NULL result indicating a failure. However, in this case, the BIO chain is not properly cleaned up, and the BIO passed by the caller still retains internal pointers to the previously freed filter BIO. If the caller then calls BIO_pop() on the BIO, a use-after-free will occur, possibly resulting in a crash.", "issued": "2023-02-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-0215 https://bugzilla.redhat.com/show_bug.cgi?id=2164492 https://www.cve.org/CVERecord?id=CVE-2023-0215 https://nvd.nist.gov/vuln/detail/CVE-2023-0215 https://www.openssl.org/news/secadv/20230207.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0215.json https://access.redhat.com/errata/RHSA-2023:1405", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-9.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "G2Djh6mj4eOKfpIiPPuLew==": { "id": "G2Djh6mj4eOKfpIiPPuLew==", "updater": "rhel-vex", "name": "CVE-2026-15028", "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.", "issued": "2026-07-08T10:10:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-15028 https://bugzilla.redhat.com/show_bug.cgi?id=2497970 https://www.cve.org/CVERecord?id=CVE-2026-15028 https://nvd.nist.gov/vuln/detail/CVE-2026-15028 https://github.com/libarchive/libarchive/issues/3251 https://github.com/libarchive/libarchive/pull/3253 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15028.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "G3sKOMxS4ta72W4huhBvJw==": { "id": "G3sKOMxS4ta72W4huhBvJw==", "updater": "rhel-vex", "name": "CVE-2023-28322", "description": "A use-after-free flaw was found in the Curl package. This issue may lead to unintended information disclosure by the application.", "issued": "2023-05-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-28322 https://bugzilla.redhat.com/show_bug.cgi?id=2196793 https://www.cve.org/CVERecord?id=CVE-2023-28322 https://nvd.nist.gov/vuln/detail/CVE-2023-28322 https://curl.se/docs/CVE-2023-28322.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-28322.json https://access.redhat.com/errata/RHSA-2024:1601", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-33.el8_9.5", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "G7736sGJCA2FtLz6Qs+G1Q==": { "id": "G7736sGJCA2FtLz6Qs+G1Q==", "updater": "rhel-vex", "name": "CVE-2024-33601", "description": "A flaw was found in the glibc netgroup cache. The netgroup cache uses xmalloc/xrealloc and may terminate the process due to a memory allocation failure.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33601 https://bugzilla.redhat.com/show_bug.cgi?id=2277205 https://www.cve.org/CVERecord?id=CVE-2024-33601 https://nvd.nist.gov/vuln/detail/CVE-2024-33601 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33601.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "G7IyfoPhe9f8QzIGbOfn7Q==": { "id": "G7IyfoPhe9f8QzIGbOfn7Q==", "updater": "rhel-vex", "name": "CVE-2023-45322", "description": "A flaw was found in libxml2. In an out-of-memory condition or when limiting the memory allocation, processing a XML document using the HTML parser may result in a use-after-free vulnerability.", "issued": "2023-08-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-45322 https://bugzilla.redhat.com/show_bug.cgi?id=2242945 https://www.cve.org/CVERecord?id=CVE-2023-45322 https://nvd.nist.gov/vuln/detail/CVE-2023-45322 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-45322.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GLs3IdvMKiw6/G8PtNw8BQ==": { "id": "GLs3IdvMKiw6/G8PtNw8BQ==", "updater": "rhel-vex", "name": "CVE-2022-35737", "description": "An array-bounds overflow vulnerability was discovered in SQLite. The vulnerability occurs when handling an overly large input passed as a string argument to some of the C-language APIs provided by SQLite. This flaw allows a remote attacker to pass specially crafted large input to the application and perform a denial of service (DoS) attack.", "issued": "2022-07-22T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-35737 https://bugzilla.redhat.com/show_bug.cgi?id=2110291 https://www.cve.org/CVERecord?id=CVE-2022-35737 https://nvd.nist.gov/vuln/detail/CVE-2022-35737 https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/ https://www.sqlite.org/releaselog/3_39_2.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-35737.json https://access.redhat.com/errata/RHSA-2023:0110", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "sqlite-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.26.0-17.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GWg5WOvOqfRt4sWhRhSM+A==": { "id": "GWg5WOvOqfRt4sWhRhSM+A==", "updater": "rhel-vex", "name": "CVE-2026-58014", "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58014 https://bugzilla.redhat.com/show_bug.cgi?id=2492255 https://www.cve.org/CVERecord?id=CVE-2026-58014 https://nvd.nist.gov/vuln/detail/CVE-2026-58014 https://gitlab.gnome.org/GNOME/glib/-/issues/3930 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58014.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GX3nMI8DKulYH9XgAGkCjw==": { "id": "GX3nMI8DKulYH9XgAGkCjw==", "updater": "rhel-vex", "name": "CVE-2026-42011", "description": "A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42011 https://bugzilla.redhat.com/show_bug.cgi?id=2467437 https://www.cve.org/CVERecord?id=CVE-2026-42011 https://nvd.nist.gov/vuln/detail/CVE-2026-42011 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42011.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "H3G4pMSGLHVSf7Q/IdqlDQ==": { "id": "H3G4pMSGLHVSf7Q/IdqlDQ==", "updater": "rhel-vex", "name": "CVE-2025-15281", "description": "A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service.", "issued": "2026-01-20T13:22:46Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15281 https://bugzilla.redhat.com/show_bug.cgi?id=2431196 https://www.cve.org/CVERecord?id=CVE-2025-15281 https://nvd.nist.gov/vuln/detail/CVE-2025-15281 https://sourceware.org/bugzilla/show_bug.cgi?id=33814 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15281.json https://access.redhat.com/errata/RHSA-2026:4772", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.31", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "H9Ud41wofJc/QlL6Rm7WkA==": { "id": "H9Ud41wofJc/QlL6Rm7WkA==", "updater": "rhel-vex", "name": "CVE-2026-0968", "description": "A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.", "issued": "2026-02-10T18:46:58Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0968 https://bugzilla.redhat.com/show_bug.cgi?id=2436982 https://www.cve.org/CVERecord?id=CVE-2026-0968 https://nvd.nist.gov/vuln/detail/CVE-2026-0968 https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0968.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HDr4rB3dwHneK78KvohfHQ==": { "id": "HDr4rB3dwHneK78KvohfHQ==", "updater": "rhel-vex", "name": "CVE-2026-34180", "description": "A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34180 https://bugzilla.redhat.com/show_bug.cgi?id=2481881 https://www.cve.org/CVERecord?id=CVE-2026-34180 https://nvd.nist.gov/vuln/detail/CVE-2026-34180 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34180.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HGfAft6M/YdppebImEvcaA==": { "id": "HGfAft6M/YdppebImEvcaA==", "updater": "rhel-vex", "name": "CVE-2024-2398", "description": "A flaw was found in curl. When an application configures libcurl to use HTTP/2 server push and the amount of received headers for the push surpasses the maximum allowed limit, libcurl aborts the server push. When aborting, libcurl does not free all the previously allocated headers, resulting in a memory leak.", "issued": "2024-03-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2398 https://bugzilla.redhat.com/show_bug.cgi?id=2270498 https://www.cve.org/CVERecord?id=CVE-2024-2398 https://nvd.nist.gov/vuln/detail/CVE-2024-2398 https://curl.se/docs/CVE-2024-2398.html https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2398.json https://access.redhat.com/errata/RHSA-2024:5654", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-34.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HNpGGr9eP5twQKC3yCh1mA==": { "id": "HNpGGr9eP5twQKC3yCh1mA==", "updater": "rhel-vex", "name": "CVE-2025-5915", "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5915 https://bugzilla.redhat.com/show_bug.cgi?id=2370865 https://www.cve.org/CVERecord?id=CVE-2025-5915 https://nvd.nist.gov/vuln/detail/CVE-2025-5915 https://github.com/libarchive/libarchive/pull/2599 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5915.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HSXdNax5s4311f36iab1RA==": { "id": "HSXdNax5s4311f36iab1RA==", "updater": "rhel-vex", "name": "CVE-2025-9820", "description": "A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.", "issued": "2025-11-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-9820 https://bugzilla.redhat.com/show_bug.cgi?id=2392528 https://www.cve.org/CVERecord?id=CVE-2025-9820 https://nvd.nist.gov/vuln/detail/CVE-2025-9820 https://gitlab.com/gnutls/gnutls/-/commit/1d56f96f6ab5034d677136b9d50b5a75dff0faf5 https://gitlab.com/gnutls/gnutls/-/issues/1732 https://www.gnutls.org/security-new.html#GNUTLS-SA-2025-11-18 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9820.json https://access.redhat.com/errata/RHSA-2026:5585", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.5", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HTk+AAyRWNCrZTtBLx34Aw==": { "id": "HTk+AAyRWNCrZTtBLx34Aw==", "updater": "rhel-vex", "name": "CVE-2024-25260", "description": "A NULL pointer dereference vulnerability in the elfutils library has been discovered. This vulnerability occurs within the handle_verdef() function in the readelf.c source file. A NULL pointer dereference typically happens when a program attempts to access memory using a pointer that is not pointing anywhere (i.e., it's NULL), leading to a crash or potentially exploitable behavior.", "issued": "2024-02-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-25260 https://bugzilla.redhat.com/show_bug.cgi?id=2265194 https://www.cve.org/CVERecord?id=CVE-2024-25260 https://nvd.nist.gov/vuln/detail/CVE-2024-25260 https://github.com/schsiung/fuzzer_issues/issues/1 https://sourceware.org/bugzilla/show_bug.cgi?id=31058 https://sourceware.org/elfutils/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-25260.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "elfutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HdAyLUATPStr/HXiy9fgQw==": { "id": "HdAyLUATPStr/HXiy9fgQw==", "updater": "rhel-vex", "name": "CVE-2026-0990", "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0990 https://bugzilla.redhat.com/show_bug.cgi?id=2429959 https://www.cve.org/CVERecord?id=CVE-2026-0990 https://nvd.nist.gov/vuln/detail/CVE-2026-0990 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0990.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HocAP230I+D9IrmRCBNVSw==": { "id": "HocAP230I+D9IrmRCBNVSw==", "updater": "rhel-vex", "name": "CVE-2024-2961", "description": "An out-of-bounds write flaw was found in the ISO-2022-CN-EXT plugin for glibc's iconv library. When converting from UCS4 charset, adding certain escape charterers is required to indicate where the charset was changed to the library. During this process, iconv improperly checks the boundaries of internal buffers, leading to a buffer overflow, which allows writing up to 3 bytes outside the desired memory location. This issue may allow an attacker to craft a malicious characters sequence that will trigger the out-of-bounds write and perform remote code execution, presenting a high impact to the Integrity, Confidentiality, and Availability triad.", "issued": "2024-04-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2961 https://bugzilla.redhat.com/show_bug.cgi?id=2273404 https://www.cve.org/CVERecord?id=CVE-2024-2961 https://nvd.nist.gov/vuln/detail/CVE-2024-2961 https://www.openwall.com/lists/oss-security/2024/04/17/9 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2961.json https://access.redhat.com/errata/RHSA-2024:2722", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-236.el8_9.13", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HrSeOrH2KyUnC4rq2IXWgg==": { "id": "HrSeOrH2KyUnC4rq2IXWgg==", "updater": "rhel-vex", "name": "CVE-2025-8058", "description": "A double-free vulnerability has been discovered in glibc (GNU C Library). This flaw occurs during bracket expression parsing within the regcomp function, specifically when a memory allocation failure takes place. Exploitation of a double-free vulnerability can lead to memory corruption, which could enable an attacker to achieve arbitrary code execution or a denial of service condition.", "issued": "2025-07-23T19:57:17Z", "links": "https://access.redhat.com/security/cve/CVE-2025-8058 https://bugzilla.redhat.com/show_bug.cgi?id=2383146 https://www.cve.org/CVERecord?id=CVE-2025-8058 https://nvd.nist.gov/vuln/detail/CVE-2025-8058 https://sourceware.org/bugzilla/show_bug.cgi?id=33185 https://sourceware.org/git/?p=glibc.git;a=commit;h=3ff17af18c38727b88d9115e536c069e6b5d601f https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-8058.json https://access.redhat.com/errata/RHSA-2025:12980", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.25", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HsgdR+ZUz/buofS6xN/cdA==": { "id": "HsgdR+ZUz/buofS6xN/cdA==", "updater": "rhel-vex", "name": "CVE-2023-6004", "description": "A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.", "issued": "2023-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-6004 https://bugzilla.redhat.com/show_bug.cgi?id=2251110 https://www.cve.org/CVERecord?id=CVE-2023-6004 https://nvd.nist.gov/vuln/detail/CVE-2023-6004 https://www.libssh.org/security/advisories/CVE-2023-6004.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6004.json https://access.redhat.com/errata/RHSA-2024:3233", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh-config", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-14.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HuOxI+pWjgGV0XsBvltzlg==": { "id": "HuOxI+pWjgGV0XsBvltzlg==", "updater": "rhel-vex", "name": "CVE-2020-19187", "description": "A flaw was found in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash, leading to a denial of service.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19187 https://bugzilla.redhat.com/show_bug.cgi?id=2234911 https://www.cve.org/CVERecord?id=CVE-2020-19187 https://nvd.nist.gov/vuln/detail/CVE-2020-19187 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19187.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IEMHgBMw35D4hXSAa095xA==": { "id": "IEMHgBMw35D4hXSAa095xA==", "updater": "rhel-vex", "name": "CVE-2023-37920", "description": "A flaw was found in the python-certifi package. This issue occurs when the e-Tugra root certificate in Certifi is removed, resulting in an unspecified error that has an unknown impact and attack vector.", "issued": "2023-07-25T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-37920 https://bugzilla.redhat.com/show_bug.cgi?id=2226586 https://www.cve.org/CVERecord?id=CVE-2023-37920 https://nvd.nist.gov/vuln/detail/CVE-2023-37920 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-37920.json https://access.redhat.com/errata/RHBA-2024:5736", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "ca-certificates", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2024.2.69_v8.0.303-80.0.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IGPwsZmhKfFY6/NwDIOUqQ==": { "id": "IGPwsZmhKfFY6/NwDIOUqQ==", "updater": "osv/go", "name": "GO-2022-0537", "description": "Panic when decoding Float and Rat types in math/big", "issued": "2022-08-01T22:21:06Z", "links": "https://go.dev/cl/417774 https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66 https://go.dev/issue/53871 https://groups.google.com/g/golang-announce/c/YqYYG87xB10 https://osv.dev/vulnerability/BIT-golang-2022-32189 https://osv.dev/vulnerability/CVE-2022-32189", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.17.13", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IZ0eLKcSsRufomKfqpkTfg==": { "id": "IZ0eLKcSsRufomKfqpkTfg==", "updater": "rhel-vex", "name": "CVE-2022-35252", "description": "A vulnerability found in curl. This security flaw happens when curl is used to retrieve and parse cookies from an HTTP(S) server, where it accepts cookies using control codes (byte values below 32), and also when cookies that contain such control codes are later sent back to an HTTP(S) server, possibly causing the server to return a 400 response. This issue effectively allows a \"sister site\" to deny service to siblings and cause a denial of service attack.", "issued": "2022-08-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-35252 https://bugzilla.redhat.com/show_bug.cgi?id=2120718 https://www.cve.org/CVERecord?id=CVE-2022-35252 https://nvd.nist.gov/vuln/detail/CVE-2022-35252 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-35252.json https://access.redhat.com/errata/RHSA-2023:2963", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-30.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IaK9TiZl7D4PrFM5K8yoVQ==": { "id": "IaK9TiZl7D4PrFM5K8yoVQ==", "updater": "rhel-vex", "name": "CVE-2022-29824", "description": "A flaw was found in the libxml2 library in functions used to manipulate the xmlBuf and the xmlBuffer types. A substantial input causes values to calculate buffer sizes to overflow, resulting in an out-of-bounds write.", "issued": "2022-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-29824 https://bugzilla.redhat.com/show_bug.cgi?id=2082158 https://www.cve.org/CVERecord?id=CVE-2022-29824 https://nvd.nist.gov/vuln/detail/CVE-2022-29824 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-29824.json https://access.redhat.com/errata/RHSA-2022:5317", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-13.el8_6.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IeRhFWzdFJzG/TLyibYj4g==": { "id": "IeRhFWzdFJzG/TLyibYj4g==", "updater": "rhel-vex", "name": "CVE-2022-40304", "description": "A flaw was found in libxml2. When a reference cycle is detected in the XML entity cleanup function the XML entity data can be stored in a dictionary. In this case, the dictionary becomes corrupted resulting in logic errors, including memory errors like double free.", "issued": "2022-10-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-40304 https://bugzilla.redhat.com/show_bug.cgi?id=2136288 https://www.cve.org/CVERecord?id=CVE-2022-40304 https://nvd.nist.gov/vuln/detail/CVE-2022-40304 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-40304.json https://access.redhat.com/errata/RHSA-2023:0173", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-15.el8_7.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ig/iNncFD4P4EYoOu9TAeQ==": { "id": "Ig/iNncFD4P4EYoOu9TAeQ==", "updater": "rhel-vex", "name": "CVE-2026-59843", "description": "A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.", "issued": "2026-07-21T11:07:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59843 https://bugzilla.redhat.com/show_bug.cgi?id=2498176 https://www.cve.org/CVERecord?id=CVE-2026-59843 https://nvd.nist.gov/vuln/detail/CVE-2026-59843 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59843.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ihsg9gWq7HOzHuNR/r3Psw==": { "id": "Ihsg9gWq7HOzHuNR/r3Psw==", "updater": "osv/go", "name": "GO-2025-4010", "description": "Insufficient validation of bracketed IPv6 hostnames in net/url", "issued": "2025-10-29T21:49:58Z", "links": "https://go.dev/issue/75678 https://go.dev/cl/709857 https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI https://osv.dev/vulnerability/BIT-golang-2025-47912 https://osv.dev/vulnerability/CVE-2025-47912", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IrOkLYqY2+NBEePGW9P7+A==": { "id": "IrOkLYqY2+NBEePGW9P7+A==", "updater": "osv/go", "name": "GO-2026-4602", "description": "FileInfo can escape from a Root in os", "issued": "2026-03-06T21:03:42Z", "links": "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk https://go.dev/issue/77827 https://go.dev/cl/749480 https://osv.dev/vulnerability/BIT-golang-2026-27139 https://osv.dev/vulnerability/CVE-2026-27139", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IrZ293CgkZfECHUvFvmpSw==": { "id": "IrZ293CgkZfECHUvFvmpSw==", "updater": "rhel-vex", "name": "CVE-2026-5435", "description": "A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.", "issued": "2026-04-28T11:58:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42733", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.40", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IzKl0lqTDhgKE5HPnTfjkA==": { "id": "IzKl0lqTDhgKE5HPnTfjkA==", "updater": "osv/go", "name": "GO-2026-6091", "description": "Fix Javascript regexp context tracking in html/template", "issued": "2026-08-13T21:43:54Z", "links": "https://go.dev/issue/80435 https://go.dev/cl/807100 https://groups.google.com/g/golang-announce/c/94pEornpRlI https://osv.dev/vulnerability/CVE-2026-56858", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.13", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "J0YQQx6sv/Elt2kRDVPlXg==": { "id": "J0YQQx6sv/Elt2kRDVPlXg==", "updater": "rhel-vex", "name": "CVE-2026-8458", "description": "A flaw was found in libcurl. A logical error in the connection pooling mechanism may cause libcurl to reuse an authenticated connection for an unintended service. This could allow an application to wrongfully reuse an existing connection to the same server that was authenticated for a different service, potentially leading to unauthorized access or information disclosure.", "issued": "2026-07-03T06:14:42Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8458 https://bugzilla.redhat.com/show_bug.cgi?id=2496764 https://www.cve.org/CVERecord?id=CVE-2026-8458 https://nvd.nist.gov/vuln/detail/CVE-2026-8458 https://curl.se/docs/CVE-2026-8458.html https://curl.se/docs/CVE-2026-8458.json https://hackerone.com/reports/3721183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8458.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JBUzZfAmFuub9+ICcI9U+A==": { "id": "JBUzZfAmFuub9+ICcI9U+A==", "updater": "rhel-vex", "name": "CVE-2019-17543", "description": "LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states \"only a few specific / uncommon usages of the API are at risk.\"", "issued": "2019-07-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-17543 https://bugzilla.redhat.com/show_bug.cgi?id=1765316 https://www.cve.org/CVERecord?id=CVE-2019-17543 https://nvd.nist.gov/vuln/detail/CVE-2019-17543 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-17543.json https://access.redhat.com/errata/RHSA-2025:11035", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "lz4-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.8.3-5.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JhtH2WNXIzfDA0h7qZ7RLw==": { "id": "JhtH2WNXIzfDA0h7qZ7RLw==", "updater": "rhel-vex", "name": "CVE-2025-0395", "description": "A flaw was found in the GNU C Library (glibc). A buffer overflow condition via the `assert()` function may be triggered due to glibc not allocating enough space for the assertion failure message string and size information. In certain conditions, a local attacker can exploit this, potentially leading to an application crash or other undefined behavior.", "issued": "2025-01-22T13:11:30Z", "links": "https://access.redhat.com/security/cve/CVE-2025-0395 https://bugzilla.redhat.com/show_bug.cgi?id=2339460 https://www.cve.org/CVERecord?id=CVE-2025-0395 https://nvd.nist.gov/vuln/detail/CVE-2025-0395 https://sourceware.org/bugzilla/show_bug.cgi?id=32582 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-0395.json https://access.redhat.com/errata/RHSA-2025:3828", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.16", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JqERGcsh34MVDceN6DnHvw==": { "id": "JqERGcsh34MVDceN6DnHvw==", "updater": "rhel-vex", "name": "CVE-2026-4046", "description": "A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).", "issued": "2026-03-30T17:16:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20587", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.37", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Jqukx5R9h3ieXFJ4Kcl9Ig==": { "id": "Jqukx5R9h3ieXFJ4Kcl9Ig==", "updater": "rhel-vex", "name": "CVE-2026-42014", "description": "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42014 https://bugzilla.redhat.com/show_bug.cgi?id=2467451 https://www.cve.org/CVERecord?id=CVE-2026-42014 https://nvd.nist.gov/vuln/detail/CVE-2026-42014 https://gitlab.com/gnutls/gnutls/-/issues/1766 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-9 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42014.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "K2gOcFXEpHuJkqp/DWKlBQ==": { "id": "K2gOcFXEpHuJkqp/DWKlBQ==", "updater": "osv/go", "name": "GO-2024-2609", "description": "Comments in display names are incorrectly handled in net/mail", "issued": "2024-03-05T22:15:04Z", "links": "https://go.dev/issue/65083 https://go.dev/cl/555596 https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg https://osv.dev/vulnerability/BIT-golang-2024-24784 https://osv.dev/vulnerability/CVE-2024-24784", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.21.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "K2zSg30ZJqCOrHCu65WPsQ==": { "id": "K2zSg30ZJqCOrHCu65WPsQ==", "updater": "osv/go", "name": "GO-2023-1569", "description": "Excessive resource consumption in mime/multipart", "issued": "2023-02-21T20:44:30Z", "links": "https://go.dev/issue/58006 https://go.dev/cl/468124 https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E https://osv.dev/vulnerability/BIT-golang-2022-41725 https://osv.dev/vulnerability/CVE-2022-41725", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.6", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KCgCqCavM9U0xL+GHJqzSg==": { "id": "KCgCqCavM9U0xL+GHJqzSg==", "updater": "rhel-vex", "name": "CVE-2026-0964", "description": "A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\n\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111.", "issued": "2026-02-10T18:44:42Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0964 https://bugzilla.redhat.com/show_bug.cgi?id=2436979 https://www.cve.org/CVERecord?id=CVE-2026-0964 https://nvd.nist.gov/vuln/detail/CVE-2026-0964 https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0964.json", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KQnPK7rlVAdImKcQqtSObQ==": { "id": "KQnPK7rlVAdImKcQqtSObQ==", "updater": "osv/go", "name": "GO-2025-4014", "description": "Unbounded allocation when parsing GNU sparse map in archive/tar", "issued": "2025-10-29T21:51:04Z", "links": "https://go.dev/cl/709861 https://go.dev/issue/75677 https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI https://osv.dev/vulnerability/BIT-golang-2025-58183 https://osv.dev/vulnerability/CVE-2025-58183", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KaROgE0QmtiOixMG9Wi1RA==": { "id": "KaROgE0QmtiOixMG9Wi1RA==", "updater": "rhel-vex", "name": "CVE-2023-32636", "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.", "issued": "2022-12-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-32636 https://bugzilla.redhat.com/show_bug.cgi?id=2211833 https://www.cve.org/CVERecord?id=CVE-2023-32636 https://nvd.nist.gov/vuln/detail/CVE-2023-32636 https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835 https://gitlab.gnome.org/GNOME/glib/-/issues/2841 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-32636.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KgGohRx9O58TbLH2PqdLRw==": { "id": "KgGohRx9O58TbLH2PqdLRw==", "updater": "rhel-vex", "name": "CVE-2023-4806", "description": "A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.", "issued": "2023-09-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4806 https://bugzilla.redhat.com/show_bug.cgi?id=2237782 https://www.cve.org/CVERecord?id=CVE-2023-4806 https://nvd.nist.gov/vuln/detail/CVE-2023-4806 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4806.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KrdA+ZSJ60jp3zLcReaBRQ==": { "id": "KrdA+ZSJ60jp3zLcReaBRQ==", "updater": "rhel-vex", "name": "CVE-2023-6004", "description": "A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.", "issued": "2023-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-6004 https://bugzilla.redhat.com/show_bug.cgi?id=2251110 https://www.cve.org/CVERecord?id=CVE-2023-6004 https://nvd.nist.gov/vuln/detail/CVE-2023-6004 https://www.libssh.org/security/advisories/CVE-2023-6004.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6004.json https://access.redhat.com/errata/RHSA-2024:3233", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh-config", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-14.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KwU14JJquPd6TePl7iIt1A==": { "id": "KwU14JJquPd6TePl7iIt1A==", "updater": "rhel-vex", "name": "CVE-2026-54369", "description": "A flaw was found in the `acl` package, specifically within its `libacl` pathname-based functions. A local attacker could exploit this vulnerability by using a symbolic link to replace a pathname component. This could allow the attacker to redirect access control list (ACL) read or write operations to arbitrary files or directories, leading to unauthorized manipulation of ACLs and ultimately local privilege escalation.", "issued": "2026-06-29T13:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-54369 https://bugzilla.redhat.com/show_bug.cgi?id=2490277 https://www.cve.org/CVERecord?id=CVE-2026-54369 https://nvd.nist.gov/vuln/detail/CVE-2026-54369 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json https://access.redhat.com/errata/RHSA-2026:43420", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "libacl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.4.0-1.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "L/KNFtLGHvteeF6ArV/0DA==": { "id": "L/KNFtLGHvteeF6ArV/0DA==", "updater": "rhel-vex", "name": "CVE-2023-0286", "description": "A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or cause a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, of which neither needs a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. In this case, this vulnerability is likely only to affect applications that have implemented their own functionality for retrieving CRLs over a network.", "issued": "2023-02-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-0286 https://bugzilla.redhat.com/show_bug.cgi?id=2164440 https://www.cve.org/CVERecord?id=CVE-2023-0286 https://nvd.nist.gov/vuln/detail/CVE-2023-0286 https://www.openssl.org/news/secadv/20230207.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0286.json https://access.redhat.com/errata/RHSA-2023:1405", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-9.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "L5csyNx8FnjUaMAb5WgZaQ==": { "id": "L5csyNx8FnjUaMAb5WgZaQ==", "updater": "rhel-vex", "name": "CVE-2025-4802", "description": "A flaw was found in the glibc library. A statically linked setuid binary that calls dlopen(), including internal dlopen() calls after setlocale() or calls to NSS functions such as getaddrinfo(), may incorrectly search LD_LIBRARY_PATH to determine which library to load, allowing a local attacker to load malicious shared libraries, escalate privileges and execute arbitrary code.", "issued": "2025-05-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-4802 https://bugzilla.redhat.com/show_bug.cgi?id=2367468 https://www.cve.org/CVERecord?id=CVE-2025-4802 https://nvd.nist.gov/vuln/detail/CVE-2025-4802 https://inbox.sourceware.org/libc-announce/3ac997b0-28a5-4129-af53-675efe4c2dec@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=32976 https://www.openwall.com/lists/oss-security/2025/05/16/7 https://www.openwall.com/lists/oss-security/2025/05/17/2 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4802.json https://access.redhat.com/errata/RHSA-2025:8686", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.22", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LGLL5bzn6z1heSEK9DVkdg==": { "id": "LGLL5bzn6z1heSEK9DVkdg==", "updater": "osv/go", "name": "GO-2023-2102", "description": "HTTP/2 rapid reset can cause excessive work in net/http", "issued": "2023-10-11T16:49:53Z", "links": "https://go.dev/issue/63417 https://go.dev/cl/534215 https://go.dev/cl/534235 https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ https://osv.dev/vulnerability/BIT-golang-2023-39325 https://osv.dev/vulnerability/CVE-2023-39325 https://osv.dev/vulnerability/GHSA-4374-p667-p6c8", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.20.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LUmQoE3ILxXEHVxGRqYkVA==": { "id": "LUmQoE3ILxXEHVxGRqYkVA==", "updater": "rhel-vex", "name": "CVE-2026-41989", "description": "A flaw was found in Libgcrypt. A remote attacker could exploit this vulnerability by sending crafted Elliptic Curve Diffie-Hellman (ECDH) ciphertext to the `gcry_pk_decrypt` function. This can lead to a heap-based buffer overflow, potentially causing a denial of service (DoS) condition.", "issued": "2026-04-23T04:30:26Z", "links": "https://access.redhat.com/security/cve/CVE-2026-41989 https://bugzilla.redhat.com/show_bug.cgi?id=2461063 https://www.cve.org/CVERecord?id=CVE-2026-41989 https://nvd.nist.gov/vuln/detail/CVE-2026-41989 https://dev.gnupg.org/T8211 https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html https://www.openwall.com/lists/oss-security/2026/04/21/1 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41989.json https://access.redhat.com/errata/RHSA-2026:47117", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.8.5-8.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LVqCXgCDKHDbHsi8OdeBdA==": { "id": "LVqCXgCDKHDbHsi8OdeBdA==", "updater": "osv/go", "name": "GO-2025-4175", "description": "Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509", "issued": "2025-12-02T20:55:55Z", "links": "https://go.dev/cl/723900 https://go.dev/issue/76442 https://groups.google.com/g/golang-announce/c/8FJoBkPddm4 https://osv.dev/vulnerability/BIT-golang-2025-61727 https://osv.dev/vulnerability/CVE-2025-61727", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LWLSX4FCLbzYWK97i5Or+A==": { "id": "LWLSX4FCLbzYWK97i5Or+A==", "updater": "rhel-vex", "name": "CVE-2026-28389", "description": "A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-28389 https://bugzilla.redhat.com/show_bug.cgi?id=2451096 https://www.cve.org/CVERecord?id=CVE-2026-28389 https://nvd.nist.gov/vuln/detail/CVE-2026-28389 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28389.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ld3pT/jZvU2DonJRAxTnLw==": { "id": "Ld3pT/jZvU2DonJRAxTnLw==", "updater": "rhel-vex", "name": "CVE-2022-4450", "description": "A double-free vulnerability was found in OpenSSL's PEM_read_bio_ex function. The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the \"name\" (for example, \"CERTIFICATE\"), any header data, and the payload data. If the function succeeds, then the \"name_out,\" \"header,\" and \"data\" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is responsible for freeing those buffers. Constructing a PEM file that results in 0 bytes of payload data is possible. In this case, PEM_read_bio_ex() will return a failure code but will populate the header argument with a pointer to a freed buffer. A double-free will occur if the caller also frees this buffer. This will most likely lead to a crash. This could be exploited by an attacker who can supply malicious PEM files for parsing to achieve a denial of service attack.", "issued": "2023-02-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-4450 https://bugzilla.redhat.com/show_bug.cgi?id=2164494 https://www.cve.org/CVERecord?id=CVE-2022-4450 https://nvd.nist.gov/vuln/detail/CVE-2022-4450 https://www.openssl.org/news/secadv/20230207.txt https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-4450.json https://access.redhat.com/errata/RHSA-2023:1405", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-9.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LrSw4TBb1fk8iUV1LcC4Cg==": { "id": "LrSw4TBb1fk8iUV1LcC4Cg==", "updater": "rhel-vex", "name": "CVE-2023-29469", "description": "A flaw was found in libxml2. This issue occurs when hashing empty strings which aren't null-terminated, xmlDictComputeFastKey could produce inconsistent results, which may lead to various logic or memory errors, including double free errors.", "issued": "2023-04-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-29469 https://bugzilla.redhat.com/show_bug.cgi?id=2185984 https://www.cve.org/CVERecord?id=CVE-2023-29469 https://nvd.nist.gov/vuln/detail/CVE-2023-29469 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-29469.json https://access.redhat.com/errata/RHSA-2023:4529", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-16.el8_8.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Lu3XtaI6dYpKttbUCbs47A==": { "id": "Lu3XtaI6dYpKttbUCbs47A==", "updater": "rhel-vex", "name": "CVE-2025-9230", "description": "A flaw was found in the OpenSSL CMS implementation (RFC 3211 KEK Unwrap). This vulnerability allows memory corruption, an application level denial of service, or potential execution of attacker-supplied code via crafted CMS messages using password-based encryption (PWRI).", "issued": "2025-09-30T23:59:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-9230 https://bugzilla.redhat.com/show_bug.cgi?id=2396054 https://www.cve.org/CVERecord?id=CVE-2025-9230 https://nvd.nist.gov/vuln/detail/CVE-2025-9230 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9230.json https://access.redhat.com/errata/RHSA-2026:0337", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-14.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "M59UwDbs3+/LtSu1P1x+Rg==": { "id": "M59UwDbs3+/LtSu1P1x+Rg==", "updater": "rhel-vex", "name": "CVE-2026-9149", "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).", "issued": "2026-05-20T22:19:32Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9149 https://bugzilla.redhat.com/show_bug.cgi?id=2460380 https://www.cve.org/CVERecord?id=CVE-2026-9149 https://nvd.nist.gov/vuln/detail/CVE-2026-9149 https://github.com/openSUSE/libsolv/pull/617 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9149.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libsolv", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "M6HQbjeJD01kGqvzEOS2FQ==": { "id": "M6HQbjeJD01kGqvzEOS2FQ==", "updater": "rhel-vex", "name": "CVE-2025-3576", "description": "A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.", "issued": "2025-04-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-3576 https://bugzilla.redhat.com/show_bug.cgi?id=2359465 https://www.cve.org/CVERecord?id=CVE-2025-3576 https://nvd.nist.gov/vuln/detail/CVE-2025-3576 https://web.mit.edu/kerberos/krb5-1.22/krb5-1.22.html https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-3576.json https://access.redhat.com/errata/RHSA-2025:8411", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-32.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MQVSqfx3uP9HdGFmxGNcpQ==": { "id": "MQVSqfx3uP9HdGFmxGNcpQ==", "updater": "osv/go", "name": "GO-2023-1702", "description": "Infinite loop in parsing in go/scanner", "issued": "2023-04-05T21:05:07Z", "links": "https://go.dev/issue/59180 https://go.dev/cl/482078 https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8 https://osv.dev/vulnerability/BIT-golang-2023-24537 https://osv.dev/vulnerability/CVE-2023-24537", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MTn6Pv097F39x9jLZcCyTg==": { "id": "MTn6Pv097F39x9jLZcCyTg==", "updater": "rhel-vex", "name": "CVE-2025-13601", "description": "A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.", "issued": "2025-11-24T13:00:15Z", "links": "https://access.redhat.com/security/cve/CVE-2025-13601 https://bugzilla.redhat.com/show_bug.cgi?id=2416741 https://www.cve.org/CVERecord?id=CVE-2025-13601 https://nvd.nist.gov/vuln/detail/CVE-2025-13601 https://gitlab.gnome.org/GNOME/glib/-/issues/3827 https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4914 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13601.json https://access.redhat.com/errata/RHSA-2026:0991", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.56.4-168.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MnunaZEdl7GYfOnz9f27HQ==": { "id": "MnunaZEdl7GYfOnz9f27HQ==", "updater": "rhel-vex", "name": "CVE-2023-5981", "description": "A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.", "issued": "2023-11-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-5981 https://bugzilla.redhat.com/show_bug.cgi?id=2248445 https://www.cve.org/CVERecord?id=CVE-2023-5981 https://nvd.nist.gov/vuln/detail/CVE-2023-5981 https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-5981.json https://access.redhat.com/errata/RHSA-2024:0155", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NPOC1wgf2oOveHlbXsMcNQ==": { "id": "NPOC1wgf2oOveHlbXsMcNQ==", "updater": "rhel-vex", "name": "CVE-2026-5450", "description": "A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.", "issued": "2026-04-20T20:55:41Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33126", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.38", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NaCKxQTduHOCF6oo1VNczw==": { "id": "NaCKxQTduHOCF6oo1VNczw==", "updater": "rhel-vex", "name": "CVE-2025-14831", "description": "A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).", "issued": "2026-02-09T14:26:34Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14831 https://bugzilla.redhat.com/show_bug.cgi?id=2423177 https://www.cve.org/CVERecord?id=CVE-2025-14831 https://nvd.nist.gov/vuln/detail/CVE-2025-14831 https://gitlab.com/gnutls/gnutls/-/issues/1773 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14831.json https://access.redhat.com/errata/RHSA-2026:5585", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.5", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NgcYbK+fPZpcG776Ewaysg==": { "id": "NgcYbK+fPZpcG776Ewaysg==", "updater": "rhel-vex", "name": "CVE-2024-37371", "description": "A vulnerability was found in the MIT Kerberos 5 GSS krb5 wrap token, where an attacker can modify the plaintext Extra Count field, causing the unwrapped token to appear truncated to the application, occurs when the attacker alters the token data during transmission which can lead to improper handling of authentication tokens.", "issued": "2024-06-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-37371 https://bugzilla.redhat.com/show_bug.cgi?id=2294676 https://www.cve.org/CVERecord?id=CVE-2024-37371 https://nvd.nist.gov/vuln/detail/CVE-2024-37371 https://web.mit.edu/kerberos/www/krb5-1.21/ https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-37371.json https://access.redhat.com/errata/RHSA-2024:5312", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-29.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O20oLjUCvyKcM7mKHtw1kA==": { "id": "O20oLjUCvyKcM7mKHtw1kA==", "updater": "osv/go", "name": "GO-2026-4982", "description": "Bypass of meta content URL escaping causes XSS in html/template", "issued": "2026-05-07T19:21:40Z", "links": "https://go.dev/issue/78913 https://go.dev/cl/769920 https://groups.google.com/g/golang-announce/c/qcCIEXso47M https://osv.dev/vulnerability/BIT-golang-2026-39823 https://osv.dev/vulnerability/CVE-2026-39823", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O8fIVXqcGshIonMWsEH9gA==": { "id": "O8fIVXqcGshIonMWsEH9gA==", "updater": "rhel-vex", "name": "CVE-2025-5916", "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5916 https://bugzilla.redhat.com/show_bug.cgi?id=2370872 https://www.cve.org/CVERecord?id=CVE-2025-5916 https://nvd.nist.gov/vuln/detail/CVE-2025-5916 https://github.com/libarchive/libarchive/pull/2568 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5916.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OFDhfcSCyh89+bVcqy0Bug==": { "id": "OFDhfcSCyh89+bVcqy0Bug==", "updater": "rhel-vex", "name": "CVE-2026-5928", "description": "A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.", "issued": "2026-04-20T20:37:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42733", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.40", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OIxqwllP74OlfGeyl1Yliw==": { "id": "OIxqwllP74OlfGeyl1Yliw==", "updater": "rhel-vex", "name": "CVE-2022-4304", "description": "A timing-based side channel exists in the OpenSSL RSA Decryption implementation, which could be sufficient to recover a ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption, an attacker would have to be able to send a very large number of trial messages for decryption. This issue affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP, and RSASVE.", "issued": "2023-02-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-4304 https://bugzilla.redhat.com/show_bug.cgi?id=2164487 https://www.cve.org/CVERecord?id=CVE-2022-4304 https://nvd.nist.gov/vuln/detail/CVE-2022-4304 https://www.openssl.org/news/secadv/20230207.txt https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-4304.json https://access.redhat.com/errata/RHSA-2023:1405", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-9.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OLKvdPVgT9/lPcflJTxE3Q==": { "id": "OLKvdPVgT9/lPcflJTxE3Q==", "updater": "rhel-vex", "name": "CVE-2025-68160", "description": "A flaw was found in OpenSSL. This vulnerability involves an out-of-bounds write in the line-buffering BIO filter, which can lead to memory corruption. While exploitation is unlikely to be under direct attacker control, a successful attack could cause an application to crash, resulting in a Denial of Service (DoS).", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-68160 https://bugzilla.redhat.com/show_bug.cgi?id=2430380 https://www.cve.org/CVERecord?id=CVE-2025-68160 https://nvd.nist.gov/vuln/detail/CVE-2025-68160 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68160.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OPNDKUsVLJt2v1gO1zvkBA==": { "id": "OPNDKUsVLJt2v1gO1zvkBA==", "updater": "rhel-vex", "name": "CVE-2025-1632", "description": "A flaw was found in the bsdunzip utility of libarchive. In affected versions, a specially crafted file may trigger a null pointer dereference. This issue can lead to an application crash or other unexpected behavior. This bug does not compromise the integrity or availability of the base system.", "issued": "2025-02-24T13:31:08Z", "links": "https://access.redhat.com/security/cve/CVE-2025-1632 https://bugzilla.redhat.com/show_bug.cgi?id=2347309 https://www.cve.org/CVERecord?id=CVE-2025-1632 https://nvd.nist.gov/vuln/detail/CVE-2025-1632 https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc https://vuldb.com/?ctiid.296619 https://vuldb.com/?id.296619 https://vuldb.com/?submit.496460 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1632.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ObCt83i8midan504u4przQ==": { "id": "ObCt83i8midan504u4przQ==", "updater": "osv/go", "name": "GO-2024-3105", "description": "Stack exhaustion in all Parse functions in go/parser", "issued": "2024-09-06T19:15:23Z", "links": "https://go.dev/cl/611238 https://go.dev/issue/69138 https://groups.google.com/g/golang-dev/c/S9POB9NCTdk https://osv.dev/vulnerability/BIT-golang-2024-34155 https://osv.dev/vulnerability/CVE-2024-34155", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.22.7", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OgFGrvrnAoXXvapnatTrxQ==": { "id": "OgFGrvrnAoXXvapnatTrxQ==", "updater": "rhel-vex", "name": "CVE-2026-0965", "description": "A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.", "issued": "2026-02-10T18:47:22Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0965 https://bugzilla.redhat.com/show_bug.cgi?id=2436980 https://www.cve.org/CVERecord?id=CVE-2026-0965 https://nvd.nist.gov/vuln/detail/CVE-2026-0965 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0965.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OjMZhwxdWxE8pAN8xmrYjg==": { "id": "OjMZhwxdWxE8pAN8xmrYjg==", "updater": "osv/go", "name": "GO-2024-3106", "description": "Stack exhaustion in Decoder.Decode in encoding/gob", "issued": "2024-09-06T19:15:23Z", "links": "https://go.dev/cl/611239 https://go.dev/issue/69139 https://groups.google.com/g/golang-dev/c/S9POB9NCTdk https://osv.dev/vulnerability/BIT-golang-2024-34156 https://osv.dev/vulnerability/CVE-2024-34156", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.22.7", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Op09biNdGX0n0Vlix1J9nA==": { "id": "Op09biNdGX0n0Vlix1J9nA==", "updater": "rhel-vex", "name": "CVE-2023-27536", "description": "A flaw was found in the Curl package. Libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, the GSS delegation setting was left out from the configuration match checks, making them match too easily, affecting krb5/kerberos/negotiate/GSSAPI transfers.", "issued": "2023-03-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-27536 https://bugzilla.redhat.com/show_bug.cgi?id=2179092 https://www.cve.org/CVERecord?id=CVE-2023-27536 https://nvd.nist.gov/vuln/detail/CVE-2023-27536 https://curl.se/docs/CVE-2023-27536.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27536.json https://access.redhat.com/errata/RHSA-2023:4523", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-30.el8_8.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OpUahpCA4oBceG962KxTMA==": { "id": "OpUahpCA4oBceG962KxTMA==", "updater": "rhel-vex", "name": "CVE-2026-22796", "description": "A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a denial of service (DoS) by providing specially crafted PKCS#7 data to an application that performs signature verification. The vulnerability occurs because the application accesses an ASN1_TYPE union member without proper type validation, leading to an invalid or NULL pointer dereference and a crash.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-22796 https://bugzilla.redhat.com/show_bug.cgi?id=2430390 https://www.cve.org/CVERecord?id=CVE-2026-22796 https://nvd.nist.gov/vuln/detail/CVE-2026-22796 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22796.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OyM2FAnj5ih/yf34RyzScw==": { "id": "OyM2FAnj5ih/yf34RyzScw==", "updater": "osv/go", "name": "GO-2023-2185", "description": "Insecure parsing of Windows paths with a \\??\\ prefix in path/filepath", "issued": "2023-11-08T22:42:14Z", "links": "https://go.dev/issue/63713 https://go.dev/cl/540277 https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY https://go.dev/issue/64028 https://go.dev/cl/541175 https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ https://osv.dev/vulnerability/BIT-golang-2023-45283 https://osv.dev/vulnerability/CVE-2023-45283", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.20.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "P9XTUYbTD1cGaDl1B19OdQ==": { "id": "P9XTUYbTD1cGaDl1B19OdQ==", "updater": "rhel-vex", "name": "CVE-2026-45447", "description": "A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-45447 https://bugzilla.redhat.com/show_bug.cgi?id=2481898 https://www.cve.org/CVERecord?id=CVE-2026-45447 https://nvd.nist.gov/vuln/detail/CVE-2026-45447 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json https://access.redhat.com/errata/RHSA-2026:26275", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-16.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PDAKSDN44Xjzz2yknyU/sQ==": { "id": "PDAKSDN44Xjzz2yknyU/sQ==", "updater": "rhel-vex", "name": "CVE-2022-32891", "description": "A vulnerability was found in webkitgtk, where an issue was addressed with improved UI handling. Visiting a website that frames malicious content may lead to UI spoofing.", "issued": "2022-09-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-32891 https://bugzilla.redhat.com/show_bug.cgi?id=2128647 https://www.cve.org/CVERecord?id=CVE-2022-32891 https://nvd.nist.gov/vuln/detail/CVE-2022-32891 https://webkitgtk.org/security/WSA-2022-0009.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-32891.json https://access.redhat.com/errata/RHSA-2022:7704", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.56.4-159.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PKZnOUqZ09NHTQCk4Bz5AQ==": { "id": "PKZnOUqZ09NHTQCk4Bz5AQ==", "updater": "osv/go", "name": "GO-2022-1039", "description": "Memory exhaustion when compiling regular expressions in regexp/syntax", "issued": "2022-10-06T16:42:07Z", "links": "https://go.dev/issue/55949 https://go.dev/cl/439356 https://groups.google.com/g/golang-announce/c/xtuG5faxtaU https://osv.dev/vulnerability/BIT-golang-2022-41715 https://osv.dev/vulnerability/CVE-2022-41715", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.18.7", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PRkbEOx7V6ePRT/WUyklHg==": { "id": "PRkbEOx7V6ePRT/WUyklHg==", "updater": "rhel-vex", "name": "CVE-2026-8927", "description": "A flaw was found in libcurl. When reusing a libcurl handle for sequential transfers with environment-variable proxy configuration, the library does not properly clear the proxy authentication state. This oversight can lead to the unintended disclosure of `Proxy-Authorization` headers to an incorrect proxy, potentially exposing sensitive authentication information to an unauthorized entity. This is an information disclosure vulnerability.", "issued": "2026-07-03T06:16:06Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8927 https://bugzilla.redhat.com/show_bug.cgi?id=2496769 https://www.cve.org/CVERecord?id=CVE-2026-8927 https://nvd.nist.gov/vuln/detail/CVE-2026-8927 https://curl.se/docs/CVE-2026-8927.html https://curl.se/docs/CVE-2026-8927.json https://hackerone.com/reports/3744543 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8927.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "High", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PYrECm01712wfbeM6lQgVA==": { "id": "PYrECm01712wfbeM6lQgVA==", "updater": "rhel-vex", "name": "CVE-2023-28484", "description": "A NULL pointer dereference vulnerability was found in libxml2. This issue occurs when parsing (invalid) XML schemas.", "issued": "2023-04-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-28484 https://bugzilla.redhat.com/show_bug.cgi?id=2185994 https://www.cve.org/CVERecord?id=CVE-2023-28484 https://nvd.nist.gov/vuln/detail/CVE-2023-28484 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-28484.json https://access.redhat.com/errata/RHSA-2023:4529", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-16.el8_8.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PcNbuWOo0ahqjfbOQhXvvQ==": { "id": "PcNbuWOo0ahqjfbOQhXvvQ==", "updater": "rhel-vex", "name": "CVE-2024-41996", "description": "A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations.", "issued": "2024-08-26T06:15:04Z", "links": "https://access.redhat.com/security/cve/CVE-2024-41996 https://bugzilla.redhat.com/show_bug.cgi?id=2307826 https://www.cve.org/CVERecord?id=CVE-2024-41996 https://nvd.nist.gov/vuln/detail/CVE-2024-41996 https://dheatattack.gitlab.io/details/ https://dheatattack.gitlab.io/faq/ https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1 https://github.com/openssl/openssl/issues/17374 https://openssl-library.org/post/2022-10-21-tls-groups-configuration/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-41996.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Pe4IHqZpuBtuSkrgd2HMEg==": { "id": "Pe4IHqZpuBtuSkrgd2HMEg==", "updater": "rhel-vex", "name": "CVE-2025-13034", "description": "A flaw was found in curl. When configured to use public key pinning with QUIC connections and GnuTLS, and with standard certificate verification explicitly disabled, curl could bypass the intended public key check. This oversight allows a malicious server to impersonate a legitimate one, potentially leading to unauthorized access or information disclosure due to a failure in verifying the server's identity.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-13034 https://bugzilla.redhat.com/show_bug.cgi?id=2426406 https://www.cve.org/CVERecord?id=CVE-2025-13034 https://nvd.nist.gov/vuln/detail/CVE-2025-13034 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13034.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QLbtrH2NAW6yNTOAlwjUsg==": { "id": "QLbtrH2NAW6yNTOAlwjUsg==", "updater": "osv/go", "name": "GO-2022-0969", "description": "Denial of service in net/http and golang.org/x/net/http2", "issued": "2022-09-12T20:23:06Z", "links": "https://groups.google.com/g/golang-announce/c/x49AQzIVX-s https://go.dev/issue/54658 https://go.dev/cl/428735 https://osv.dev/vulnerability/BIT-golang-2022-27664 https://osv.dev/vulnerability/CVE-2022-27664 https://osv.dev/vulnerability/GHSA-69cg-p879-7622", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.18.6", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QRjOpbzsYIicMf8kpKoMnA==": { "id": "QRjOpbzsYIicMf8kpKoMnA==", "updater": "rhel-vex", "name": "CVE-2024-33600", "description": "A flaw was found in the glibc netgroup cache. After a failed cache insertion, addgetnetgrentX tries to send the non-existing response after the not-found header. This can lead to a null pointer dereference that causes a crash or exit.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33600 https://bugzilla.redhat.com/show_bug.cgi?id=2277204 https://www.cve.org/CVERecord?id=CVE-2024-33600 https://nvd.nist.gov/vuln/detail/CVE-2024-33600 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33600.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QUtTYJuHdkAOgtveagWUfA==": { "id": "QUtTYJuHdkAOgtveagWUfA==", "updater": "rhel-vex", "name": "CVE-2023-0466", "description": "A flaw was found in OpenSSL. The X509_VERIFY_PARAM_add0_policy() function is documented to enable the certificate policy check when doing certificate verification implicitly. However, implementing the function does not enable the check, allowing certificates with invalid or incorrect policies to pass the certificate verification. Suddenly enabling the policy check could break existing deployments, so it was decided to keep the existing behavior of the X509_VERIFY_PARAM_add0_policy() function. The applications that require OpenSSL to perform certificate policy check need to use X509_VERIFY_PARAM_set1_policies() or explicitly enable the policy check by calling X509_VERIFY_PARAM_set_flags() with the X509_V_FLAG_POLICY_CHECK flag argument. Certificate policy checks are disabled by default in OpenSSL and are not commonly used by applications.", "issued": "2023-03-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-0466 https://bugzilla.redhat.com/show_bug.cgi?id=2182565 https://www.cve.org/CVERecord?id=CVE-2023-0466 https://nvd.nist.gov/vuln/detail/CVE-2023-0466 https://www.openssl.org/news/secadv/20230328.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0466.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Qf35dl+554myaMtzHWghjQ==": { "id": "Qf35dl+554myaMtzHWghjQ==", "updater": "rhel-vex", "name": "CVE-2025-32988", "description": "A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure.\n\nThis vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.", "issued": "2025-07-10T07:55:14Z", "links": "https://access.redhat.com/security/cve/CVE-2025-32988 https://bugzilla.redhat.com/show_bug.cgi?id=2359622 https://www.cve.org/CVERecord?id=CVE-2025-32988 https://nvd.nist.gov/vuln/detail/CVE-2025-32988 https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-32988.json https://access.redhat.com/errata/RHSA-2025:17415", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.4", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Qf3ehynA9eSLxEmKdgPWzA==": { "id": "Qf3ehynA9eSLxEmKdgPWzA==", "updater": "osv/go", "name": "GO-2026-5856", "description": "Invoking Encrypted Client Hello privacy leak in crypto/tls", "issued": "2026-07-07T21:34:47Z", "links": "https://go.dev/cl/775960 https://go.dev/issue/79282 https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc https://osv.dev/vulnerability/BIT-golang-2026-42505 https://osv.dev/vulnerability/CVE-2026-42505", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Qmz0nOmPr2Gi30IOiKJW0A==": { "id": "Qmz0nOmPr2Gi30IOiKJW0A==", "updater": "rhel-vex", "name": "CVE-2025-4373", "description": "A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.", "issued": "2025-05-06T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-4373 https://bugzilla.redhat.com/show_bug.cgi?id=2364265 https://www.cve.org/CVERecord?id=CVE-2025-4373 https://nvd.nist.gov/vuln/detail/CVE-2025-4373 https://gitlab.gnome.org/GNOME/glib/-/issues/3677 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4373.json https://access.redhat.com/errata/RHSA-2025:11327", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.56.4-166.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QwBnC+2unbl7BaURui6Tng==": { "id": "QwBnC+2unbl7BaURui6Tng==", "updater": "rhel-vex", "name": "CVE-2026-3832", "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.", "issued": "2026-04-30T17:29:25Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3832 https://bugzilla.redhat.com/show_bug.cgi?id=2445762 https://www.cve.org/CVERecord?id=CVE-2026-3832 https://nvd.nist.gov/vuln/detail/CVE-2026-3832 https://gitlab.com/gnutls/gnutls/-/issues/1801 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3832.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "gnutls", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QwE+GnarHqQPSOEo3aCrZw==": { "id": "QwE+GnarHqQPSOEo3aCrZw==", "updater": "rhel-vex", "name": "CVE-2023-4806", "description": "A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.", "issued": "2023-09-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4806 https://bugzilla.redhat.com/show_bug.cgi?id=2237782 https://www.cve.org/CVERecord?id=CVE-2023-4806 https://nvd.nist.gov/vuln/detail/CVE-2023-4806 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4806.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R0kLLh/19P/mLd+t6ufaFg==": { "id": "R0kLLh/19P/mLd+t6ufaFg==", "updater": "rhel-vex", "name": "CVE-2026-40553", "description": "A flaw was found in gawk. A buffer overflow vulnerability exists in the `ftype()` routine, located in the `extension/readdir.c` program file. This vulnerability could allow an attacker to crash the program, resulting in a denial of service. It may also potentially lead to arbitrary code execution, though this has not been definitively confirmed.", "issued": "2026-07-13T12:07:56Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40553 https://bugzilla.redhat.com/show_bug.cgi?id=2499657 https://www.cve.org/CVERecord?id=CVE-2026-40553 https://nvd.nist.gov/vuln/detail/CVE-2026-40553 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40553.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R1p9seVH9iMH1JLw33Ofrw==": { "id": "R1p9seVH9iMH1JLw33Ofrw==", "updater": "rhel-vex", "name": "CVE-2024-33599", "description": "A stack-based buffer overflow flaw was found in the glibc netgroup cache. In certain conditions, its possible to trigger a stack-based buffer overflow condition that can lead to a denial of service and potentially other malicious actions that impact confidentiality and integrity.", "issued": "2024-04-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33599 https://bugzilla.redhat.com/show_bug.cgi?id=2277202 https://www.cve.org/CVERecord?id=CVE-2024-33599 https://nvd.nist.gov/vuln/detail/CVE-2024-33599 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33599.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R7Y+1EAHNMj7+xQ3iSua8A==": { "id": "R7Y+1EAHNMj7+xQ3iSua8A==", "updater": "osv/go", "name": "GO-2023-2043", "description": "Improper handling of special tags within script contexts in html/template", "issued": "2023-09-07T16:11:59Z", "links": "https://go.dev/issue/62197 https://go.dev/cl/526157 https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ https://osv.dev/vulnerability/BIT-golang-2023-39319 https://osv.dev/vulnerability/CVE-2023-39319", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.20.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R8DPcPvbg81z+eUw+ykYig==": { "id": "R8DPcPvbg81z+eUw+ykYig==", "updater": "rhel-vex", "name": "CVE-2024-33602", "description": "A flaw was found in the glibc netgroup cache. The buffer-resizing code in addgetnetgrentX assumes that all string pointers point into the supplied buffer. This can potentially lead to memory corruption and cause a crash.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33602 https://bugzilla.redhat.com/show_bug.cgi?id=2277206 https://www.cve.org/CVERecord?id=CVE-2024-33602 https://nvd.nist.gov/vuln/detail/CVE-2024-33602 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33602.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R90VfdEewbj2ZB0bKqbhNA==": { "id": "R90VfdEewbj2ZB0bKqbhNA==", "updater": "rhel-vex", "name": "CVE-2026-0966", "description": "A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.", "issued": "2026-02-10T18:47:15Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0966 https://bugzilla.redhat.com/show_bug.cgi?id=2433121 https://www.cve.org/CVERecord?id=CVE-2026-0966 https://nvd.nist.gov/vuln/detail/CVE-2026-0966 https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0966.json", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RISSeC/EvrM60Yku1wKENQ==": { "id": "RISSeC/EvrM60Yku1wKENQ==", "updater": "rhel-vex", "name": "CVE-2025-13151", "description": "A flaw was found in libtasn1. A remote attacker could exploit a stack-based buffer overflow vulnerability in the `asn1_expend_octet_string` function. This occurs due to a failure in validating the size of input data. Successful exploitation can lead to a Denial of Service (DoS) condition, making the affected system or application unavailable.", "issued": "2026-01-07T21:14:05Z", "links": "https://access.redhat.com/security/cve/CVE-2025-13151 https://bugzilla.redhat.com/show_bug.cgi?id=2427698 https://www.cve.org/CVERecord?id=CVE-2025-13151 https://nvd.nist.gov/vuln/detail/CVE-2025-13151 https://gitlab.com/gnutls/libtasn1 https://gitlab.com/gnutls/libtasn1/-/merge_requests/121 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13151.json https://access.redhat.com/errata/RHSA-2026:36728", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libtasn1", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:4.13-6.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RITj6RMTk7dAExWxjkhkvg==": { "id": "RITj6RMTk7dAExWxjkhkvg==", "updater": "rhel-vex", "name": "CVE-2022-27782", "description": "A vulnerability was found in curl. This issue occurs because curl can reuse a previously created connection even when a TLS or SSH-related option is changed that should have prohibited reuse. This flaw leads to an authentication bypass, either by mistake or by a malicious actor.", "issued": "2022-05-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-27782 https://bugzilla.redhat.com/show_bug.cgi?id=2082215 https://www.cve.org/CVERecord?id=CVE-2022-27782 https://nvd.nist.gov/vuln/detail/CVE-2022-27782 https://curl.se/docs/CVE-2022-27782.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-27782.json https://access.redhat.com/errata/RHSA-2022:5313", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RXjd5U95osIGXnqCa34Jkg==": { "id": "RXjd5U95osIGXnqCa34Jkg==", "updater": "rhel-vex", "name": "CVE-2026-0989", "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested \u003cinclude\u003e directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0989 https://bugzilla.redhat.com/show_bug.cgi?id=2429933 https://www.cve.org/CVERecord?id=CVE-2026-0989 https://nvd.nist.gov/vuln/detail/CVE-2026-0989 https://gitlab.gnome.org/GNOME/libxml2/-/issues/998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0989.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RYgdOTk5snrzxeLvC7Ui4A==": { "id": "RYgdOTk5snrzxeLvC7Ui4A==", "updater": "rhel-vex", "name": "CVE-2021-40528", "description": "A flaw was found in libgcrypt's ElGamal implementation, where it allows plain text recovery. During the interaction between two cryptographic libraries, a certain combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP. The highest threat from this vulnerability is to confidentiality.", "issued": "2021-07-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-40528 https://bugzilla.redhat.com/show_bug.cgi?id=2002816 https://www.cve.org/CVERecord?id=CVE-2021-40528 https://nvd.nist.gov/vuln/detail/CVE-2021-40528 https://dev.gnupg.org/rCb118681ebc4c9ea4b9da79b0f9541405a64f4c13 https://eprint.iacr.org/2021/923 https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1 https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-40528.json https://access.redhat.com/errata/RHSA-2022:5311", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.8.5-7.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Rfm1tD+QxSP/TVjKFDNabg==": { "id": "Rfm1tD+QxSP/TVjKFDNabg==", "updater": "rhel-vex", "name": "CVE-2026-0967", "description": "A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.", "issued": "2026-02-10T18:47:09Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0967 https://bugzilla.redhat.com/show_bug.cgi?id=2436981 https://www.cve.org/CVERecord?id=CVE-2026-0967 https://nvd.nist.gov/vuln/detail/CVE-2026-0967 https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0967.json", "severity": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RjFmZiccRAHOcTfXhttaHw==": { "id": "RjFmZiccRAHOcTfXhttaHw==", "updater": "rhel-vex", "name": "CVE-2025-8058", "description": "A double-free vulnerability has been discovered in glibc (GNU C Library). This flaw occurs during bracket expression parsing within the regcomp function, specifically when a memory allocation failure takes place. Exploitation of a double-free vulnerability can lead to memory corruption, which could enable an attacker to achieve arbitrary code execution or a denial of service condition.", "issued": "2025-07-23T19:57:17Z", "links": "https://access.redhat.com/security/cve/CVE-2025-8058 https://bugzilla.redhat.com/show_bug.cgi?id=2383146 https://www.cve.org/CVERecord?id=CVE-2025-8058 https://nvd.nist.gov/vuln/detail/CVE-2025-8058 https://sourceware.org/bugzilla/show_bug.cgi?id=33185 https://sourceware.org/git/?p=glibc.git;a=commit;h=3ff17af18c38727b88d9115e536c069e6b5d601f https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-8058.json https://access.redhat.com/errata/RHSA-2025:12980", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.25", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RsX/3pJwmZI4sym3ZDA/fw==": { "id": "RsX/3pJwmZI4sym3ZDA/fw==", "updater": "rhel-vex", "name": "CVE-2025-9714", "description": "A flaw was found in libxstl/libxml2. The 'exsltDynMapFunction' function in libexslt/dynamic.c does not contain a recursion depth check, which may cause an infinite loop via a specially crafted XSLT document while handling 'dyn:map()', leading to stack exhaustion and a local denial of service.", "issued": "2025-09-02T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-9714 https://bugzilla.redhat.com/show_bug.cgi?id=2392605 https://www.cve.org/CVERecord?id=CVE-2025-9714 https://nvd.nist.gov/vuln/detail/CVE-2025-9714 https://gitlab.gnome.org/GNOME/libxml2/-/commit/677a42645ef22b5a50741bad5facf9d8a8bc6d21 https://gitlab.gnome.org/GNOME/libxslt/-/issues/148 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9714.json https://access.redhat.com/errata/RHSA-2026:11349", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-21.el8_10.4", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "S5Bw/81ixhFX3PO8tegz3g==": { "id": "S5Bw/81ixhFX3PO8tegz3g==", "updater": "rhel-vex", "name": "CVE-2022-37434", "description": "A security vulnerability was found in zlib. The flaw triggered a heap-based buffer in inflate in the inflate.c function via a large gzip header extra field. This flaw is only applicable in the call inflateGetHeader.", "issued": "2022-08-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-37434 https://bugzilla.redhat.com/show_bug.cgi?id=2116639 https://www.cve.org/CVERecord?id=CVE-2022-37434 https://nvd.nist.gov/vuln/detail/CVE-2022-37434 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-37434.json https://access.redhat.com/errata/RHSA-2022:7106", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "zlib", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.2.11-19.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SAbLfsfvEYCEKFQYbD0xVw==": { "id": "SAbLfsfvEYCEKFQYbD0xVw==", "updater": "rhel-vex", "name": "CVE-2021-35939", "description": "It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "issued": "2021-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-35939 https://bugzilla.redhat.com/show_bug.cgi?id=1964129 https://www.cve.org/CVERecord?id=CVE-2021-35939 https://nvd.nist.gov/vuln/detail/CVE-2021-35939 https://rpm.org/wiki/Releases/4.18.0 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-35939.json https://access.redhat.com/errata/RHSA-2024:0647", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "rpm", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:4.14.3-28.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SHxE0qXbBmDEp/LL1ieJeA==": { "id": "SHxE0qXbBmDEp/LL1ieJeA==", "updater": "rhel-vex", "name": "CVE-2020-19189", "description": "A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19189 https://bugzilla.redhat.com/show_bug.cgi?id=2234926 https://www.cve.org/CVERecord?id=CVE-2020-19189 https://nvd.nist.gov/vuln/detail/CVE-2020-19189 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19189.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SzmYO03Ci8Y2lXH/guHOmQ==": { "id": "SzmYO03Ci8Y2lXH/guHOmQ==", "updater": "rhel-vex", "name": "CVE-2023-6004", "description": "A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.", "issued": "2023-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-6004 https://bugzilla.redhat.com/show_bug.cgi?id=2251110 https://www.cve.org/CVERecord?id=CVE-2023-6004 https://nvd.nist.gov/vuln/detail/CVE-2023-6004 https://www.libssh.org/security/advisories/CVE-2023-6004.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6004.json https://access.redhat.com/errata/RHSA-2024:3233", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-14.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TYK4EhmbkLsiNuamdoZ23w==": { "id": "TYK4EhmbkLsiNuamdoZ23w==", "updater": "osv/go", "name": "GO-2026-4986", "description": "Quadratic string concatentation in consumeComment in net/mail", "issued": "2026-05-07T19:21:40Z", "links": "https://go.dev/issue/78566 https://go.dev/cl/759940 https://groups.google.com/g/golang-announce/c/qcCIEXso47M https://osv.dev/vulnerability/BIT-golang-2026-39820 https://osv.dev/vulnerability/CVE-2026-39820", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TapvA/WPAxpiLfGqTfgs4A==": { "id": "TapvA/WPAxpiLfGqTfgs4A==", "updater": "rhel-vex", "name": "CVE-2022-1271", "description": "An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.", "issued": "2022-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-1271 https://bugzilla.redhat.com/show_bug.cgi?id=2073310 https://www.cve.org/CVERecord?id=CVE-2022-1271 https://nvd.nist.gov/vuln/detail/CVE-2022-1271 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-1271.json https://access.redhat.com/errata/RHSA-2022:4991", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "xz-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:5.2.4-4.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TuBnhFrkwMqIcYtYYgNGNQ==": { "id": "TuBnhFrkwMqIcYtYYgNGNQ==", "updater": "rhel-vex", "name": "CVE-2026-3784", "description": "A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user.", "issued": "2026-03-11T10:09:21Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3784 https://bugzilla.redhat.com/show_bug.cgi?id=2446449 https://www.cve.org/CVERecord?id=CVE-2026-3784 https://nvd.nist.gov/vuln/detail/CVE-2026-3784 http://www.openwall.com/lists/oss-security/2026/03/11/3 https://curl.se/docs/CVE-2026-3784.html https://curl.se/docs/CVE-2026-3784.json https://hackerone.com/reports/3584903 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3784.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "U8up9/ZYW+CTO5UcJB1hZQ==": { "id": "U8up9/ZYW+CTO5UcJB1hZQ==", "updater": "rhel-vex", "name": "CVE-2025-5278", "description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.", "issued": "2025-05-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5278 https://bugzilla.redhat.com/show_bug.cgi?id=2368764 https://www.cve.org/CVERecord?id=CVE-2025-5278 https://nvd.nist.gov/vuln/detail/CVE-2025-5278 https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633 https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5278.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "U9OAekt5rMrp2NfnN1hexA==": { "id": "U9OAekt5rMrp2NfnN1hexA==", "updater": "rhel-vex", "name": "CVE-2024-2961", "description": "An out-of-bounds write flaw was found in the ISO-2022-CN-EXT plugin for glibc's iconv library. When converting from UCS4 charset, adding certain escape charterers is required to indicate where the charset was changed to the library. During this process, iconv improperly checks the boundaries of internal buffers, leading to a buffer overflow, which allows writing up to 3 bytes outside the desired memory location. This issue may allow an attacker to craft a malicious characters sequence that will trigger the out-of-bounds write and perform remote code execution, presenting a high impact to the Integrity, Confidentiality, and Availability triad.", "issued": "2024-04-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2961 https://bugzilla.redhat.com/show_bug.cgi?id=2273404 https://www.cve.org/CVERecord?id=CVE-2024-2961 https://nvd.nist.gov/vuln/detail/CVE-2024-2961 https://www.openwall.com/lists/oss-security/2024/04/17/9 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2961.json https://access.redhat.com/errata/RHSA-2024:2722", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-236.el8_9.13", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UPzTyNn8ZLXlb+bwRFPPTA==": { "id": "UPzTyNn8ZLXlb+bwRFPPTA==", "updater": "rhel-vex", "name": "CVE-2023-2650", "description": "A flaw was found in OpenSSL resulting in a possible denial of service while translating ASN.1 object identifiers. Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience long delays when processing messages, which may lead to a denial of service.", "issued": "2023-05-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-2650 https://bugzilla.redhat.com/show_bug.cgi?id=2207947 https://www.cve.org/CVERecord?id=CVE-2023-2650 https://nvd.nist.gov/vuln/detail/CVE-2023-2650 https://www.openssl.org/news/secadv/20230530.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-2650.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UUIKm7f4jyfDWGKvptUQ8Q==": { "id": "UUIKm7f4jyfDWGKvptUQ8Q==", "updater": "rhel-vex", "name": "CVE-2025-8277", "description": "A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability.", "issued": "2025-09-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-8277 https://bugzilla.redhat.com/show_bug.cgi?id=2383888 https://www.cve.org/CVERecord?id=CVE-2025-8277 https://nvd.nist.gov/vuln/detail/CVE-2025-8277 https://www.libssh.org/security/advisories/CVE-2025-8277.txt https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-8277.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UbmdE2pHXRFccv8l1e02Jw==": { "id": "UbmdE2pHXRFccv8l1e02Jw==", "updater": "rhel-vex", "name": "CVE-2023-4156", "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.", "issued": "2023-06-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4156 https://bugzilla.redhat.com/show_bug.cgi?id=2215930 https://www.cve.org/CVERecord?id=CVE-2023-4156 https://nvd.nist.gov/vuln/detail/CVE-2023-4156 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4156.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UmdXLUcUrfF679npg1+prQ==": { "id": "UmdXLUcUrfF679npg1+prQ==", "updater": "osv/go", "name": "GO-2024-2598", "description": "Verify panics on certificates with an unknown public key algorithm in crypto/x509", "issued": "2024-03-05T22:14:58Z", "links": "https://go.dev/issue/65390 https://go.dev/cl/569339 https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg https://osv.dev/vulnerability/BIT-golang-2024-24783 https://osv.dev/vulnerability/CVE-2024-24783", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.21.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Uwr0G7T1uD9pkPe9v3QhhA==": { "id": "Uwr0G7T1uD9pkPe9v3QhhA==", "updater": "rhel-vex", "name": "CVE-2025-49794", "description": "A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the \u003csch:name path=\"...\"/\u003e schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.", "issued": "2025-06-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-49794 https://bugzilla.redhat.com/show_bug.cgi?id=2372373 https://www.cve.org/CVERecord?id=CVE-2025-49794 https://nvd.nist.gov/vuln/detail/CVE-2025-49794 https://gitlab.gnome.org/GNOME/libxml2/-/issues/931 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-49794.json https://access.redhat.com/errata/RHSA-2025:10698", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-21.el8_10.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VKqdogZsa9um4xK5rHpQyw==": { "id": "VKqdogZsa9um4xK5rHpQyw==", "updater": "rhel-vex", "name": "CVE-2026-0915", "description": "A flaw was found in glibc, the GNU C Library. When an application calls the `getnetbyaddr` or `getnetbyaddr_r` functions to resolve a network address, and the system's `nsswitch.conf` file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system.", "issued": "2026-01-15T22:08:41Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0915 https://bugzilla.redhat.com/show_bug.cgi?id=2430201 https://www.cve.org/CVERecord?id=CVE-2026-0915 https://nvd.nist.gov/vuln/detail/CVE-2026-0915 https://sourceware.org/bugzilla/show_bug.cgi?id=33802 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0915.json https://access.redhat.com/errata/RHSA-2026:4772", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.31", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VLzwKVDYC7fQrtcpCzjXjA==": { "id": "VLzwKVDYC7fQrtcpCzjXjA==", "updater": "rhel-vex", "name": "CVE-2025-69418", "description": "A flaw was found in OpenSSL. When applications directly call the low-level CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions with non-block-aligned lengths in a single call on hardware-accelerated builds, the trailing 1-15 bytes of a message may be exposed in cleartext. These exposed bytes are not covered by the authentication tag, allowing an attacker to read or tamper with them without detection.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-69418 https://bugzilla.redhat.com/show_bug.cgi?id=2430381 https://www.cve.org/CVERecord?id=CVE-2025-69418 https://nvd.nist.gov/vuln/detail/CVE-2025-69418 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69418.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VNVOmhP5E/G5E7BnsCVH3g==": { "id": "VNVOmhP5E/G5E7BnsCVH3g==", "updater": "rhel-vex", "name": "CVE-2024-2408", "description": "The RSA decryption implementation using PKCS#1 v1.5 padding in OpenSSL is vulnerable to a timing side-channel attack known as the Marvin Attack. This vulnerability arises because the execution time of the openssl_private_decrypt() function in PHP with OpenSSL varies based on whether a valid message is returned. This flaw allows an attacker to use these timing differences to decrypt captured ciphertexts or forge signatures, compromising the security of the encrypted data. \r\n\r\nThe vulnerability has been demonstrated through statistical analysis of execution times, confirming the presence of a side channel that can be leveraged in a Bleichenbacher-style attack.", "issued": "2024-06-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2408 https://bugzilla.redhat.com/show_bug.cgi?id=2270358 https://www.cve.org/CVERecord?id=CVE-2024-2408 https://nvd.nist.gov/vuln/detail/CVE-2024-2408 https://github.com/php/php-src/security/advisories/GHSA-hh26-4ppw-5864 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2408.json https://access.redhat.com/errata/RHSA-2023:7877", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-12.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VQJ+FoX0f/k7ipxHBnV3LQ==": { "id": "VQJ+FoX0f/k7ipxHBnV3LQ==", "updater": "rhel-vex", "name": "CVE-2025-14087", "description": "A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.", "issued": "2025-12-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14087 https://bugzilla.redhat.com/show_bug.cgi?id=2419093 https://www.cve.org/CVERecord?id=CVE-2025-14087 https://nvd.nist.gov/vuln/detail/CVE-2025-14087 https://gitlab.gnome.org/GNOME/glib/-/issues/3834 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14087.json https://access.redhat.com/errata/RHSA-2026:15953", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.56.4-169.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VZCOEnyMf3WnLTUY78ecYw==": { "id": "VZCOEnyMf3WnLTUY78ecYw==", "updater": "osv/go", "name": "GO-2025-4008", "description": "ALPN negotiation error contains attacker controlled information in crypto/tls", "issued": "2025-10-29T21:49:53Z", "links": "https://go.dev/cl/707776 https://go.dev/issue/75652 https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI https://osv.dev/vulnerability/BIT-golang-2025-58189 https://osv.dev/vulnerability/CVE-2025-58189", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VmsOBc3mY7KTk37gMHLcBA==": { "id": "VmsOBc3mY7KTk37gMHLcBA==", "updater": "rhel-vex", "name": "CVE-2026-3833", "description": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.", "issued": "2026-04-30T17:26:28Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3833 https://bugzilla.redhat.com/show_bug.cgi?id=2445763 https://www.cve.org/CVERecord?id=CVE-2026-3833 https://nvd.nist.gov/vuln/detail/CVE-2026-3833 https://gitlab.com/gnutls/gnutls/-/issues/1803 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3833.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VnX21Pl9qSPoKfQfhuQUfQ==": { "id": "VnX21Pl9qSPoKfQfhuQUfQ==", "updater": "osv/go", "name": "GO-2025-4007", "description": "Quadratic complexity when checking name constraints in crypto/x509", "issued": "2025-10-29T21:49:50Z", "links": "https://go.dev/issue/75681 https://go.dev/cl/709854 https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI https://osv.dev/vulnerability/BIT-golang-2025-58187 https://osv.dev/vulnerability/CVE-2025-58187", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VsocCwaFpF6PzdX5PxR+sQ==": { "id": "VsocCwaFpF6PzdX5PxR+sQ==", "updater": "rhel-vex", "name": "CVE-2020-19185", "description": "A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash, causing denial of service.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19185 https://bugzilla.redhat.com/show_bug.cgi?id=2234924 https://www.cve.org/CVERecord?id=CVE-2020-19185 https://nvd.nist.gov/vuln/detail/CVE-2020-19185 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19185.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W/d4trZ7jb2yxjrq4cNOWA==": { "id": "W/d4trZ7jb2yxjrq4cNOWA==", "updater": "rhel-vex", "name": "CVE-2022-3219", "description": "A vulnerability was found in GnuPG. GnuPG can spin on a relatively small input by crafting a public key with thousands of signatures attached and compressed down to a few kilobytes. This issue can potentially cause a denial of service.", "issued": "2022-09-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-3219 https://bugzilla.redhat.com/show_bug.cgi?id=2127010 https://www.cve.org/CVERecord?id=CVE-2022-3219 https://nvd.nist.gov/vuln/detail/CVE-2022-3219 https://dev.gnupg.org/D556 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3219.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W0HHl6nwR8cHTX8V+Igpag==": { "id": "W0HHl6nwR8cHTX8V+Igpag==", "updater": "osv/go", "name": "GO-2023-2041", "description": "Improper handling of HTML-like comments in script contexts in html/template", "issued": "2023-09-07T16:11:17Z", "links": "https://go.dev/issue/62196 https://go.dev/cl/526156 https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ https://osv.dev/vulnerability/BIT-golang-2023-39318 https://osv.dev/vulnerability/CVE-2023-39318", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.20.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W0l4QAgarxrOkTlGvtp0uA==": { "id": "W0l4QAgarxrOkTlGvtp0uA==", "updater": "rhel-vex", "name": "CVE-2026-59846", "description": "A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.", "issued": "2026-07-21T12:46:04Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59846 https://bugzilla.redhat.com/show_bug.cgi?id=2498179 https://www.cve.org/CVERecord?id=CVE-2026-59846 https://nvd.nist.gov/vuln/detail/CVE-2026-59846 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59846.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W29H3Qu4TKCFE3tgIeo7pQ==": { "id": "W29H3Qu4TKCFE3tgIeo7pQ==", "updater": "osv/go", "name": "GO-2024-2600", "description": "Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http", "issued": "2024-03-05T22:15:02Z", "links": "https://go.dev/issue/65065 https://go.dev/cl/569340 https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg https://osv.dev/vulnerability/BIT-golang-2023-45289 https://osv.dev/vulnerability/CVE-2023-45289", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.21.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W3WDVv515yQ/d0v0j5vcgw==": { "id": "W3WDVv515yQ/d0v0j5vcgw==", "updater": "rhel-vex", "name": "CVE-2022-42898", "description": "A vulnerability was found in MIT krb5. This flaw allows an authenticated attacker to cause a KDC or kadmind process to crash by reading beyond the bounds of allocated memory, creating a denial of service. A privileged attacker may similarly be able to cause a Kerberos or GSS application service to crash.", "issued": "2022-11-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-42898 https://bugzilla.redhat.com/show_bug.cgi?id=2140960 https://www.cve.org/CVERecord?id=CVE-2022-42898 https://nvd.nist.gov/vuln/detail/CVE-2022-42898 https://mailman.mit.edu/pipermail/krbdev/2022-November/013576.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-42898.json https://access.redhat.com/errata/RHSA-2022:8638", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-22.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WGOq+rhe3/NaL51WCyZSeA==": { "id": "WGOq+rhe3/NaL51WCyZSeA==", "updater": "rhel-vex", "name": "CVE-2026-5419", "description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5419 https://bugzilla.redhat.com/show_bug.cgi?id=2467686 https://www.cve.org/CVERecord?id=CVE-2026-5419 https://nvd.nist.gov/vuln/detail/CVE-2026-5419 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5419.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "gnutls", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WGvgNwrW2u5APZcidQ6v1Q==": { "id": "WGvgNwrW2u5APZcidQ6v1Q==", "updater": "rhel-vex", "name": "CVE-2026-27456", "description": "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.", "issued": "2026-04-03T21:23:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-27456 https://bugzilla.redhat.com/show_bug.cgi?id=2454956 https://www.cve.org/CVERecord?id=CVE-2026-27456 https://nvd.nist.gov/vuln/detail/CVE-2026-27456 https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4 https://github.com/util-linux/util-linux/releases/tag/v2.41.4 https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27456.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WHdlDKqisJJ9fRsM9LxySA==": { "id": "WHdlDKqisJJ9fRsM9LxySA==", "updater": "rhel-vex", "name": "CVE-2026-33846", "description": "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.", "issued": "2026-05-04T08:53:59Z", "links": "https://access.redhat.com/security/cve/CVE-2026-33846 https://bugzilla.redhat.com/show_bug.cgi?id=2450625 https://www.cve.org/CVERecord?id=CVE-2026-33846 https://nvd.nist.gov/vuln/detail/CVE-2026-33846 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33846.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WWV/wgl5XOJ1g4XsbmHtdw==": { "id": "WWV/wgl5XOJ1g4XsbmHtdw==", "updater": "rhel-vex", "name": "CVE-2023-28321", "description": "A flaw was found in the Curl package. An incorrect International Domain Name (IDN) wildcard match may lead to improper certificate validation.", "issued": "2023-05-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-28321 https://bugzilla.redhat.com/show_bug.cgi?id=2196786 https://www.cve.org/CVERecord?id=CVE-2023-28321 https://nvd.nist.gov/vuln/detail/CVE-2023-28321 https://curl.se/docs/CVE-2023-28321.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-28321.json https://access.redhat.com/errata/RHSA-2023:4523", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-30.el8_8.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WZpyztsbN64kzxjO5mCNCA==": { "id": "WZpyztsbN64kzxjO5mCNCA==", "updater": "osv/go", "name": "GO-2020-0036", "description": "Excessive resource consumption in YAML parsing in gopkg.in/yaml.v2", "issued": "2021-04-14T20:04:52Z", "links": "https://github.com/go-yaml/yaml/pull/555 https://github.com/go-yaml/yaml/commit/53403b58ad1b561927d19068c655246f2db79d48 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18496 https://osv.dev/vulnerability/CVE-2019-11254 https://osv.dev/vulnerability/GHSA-wxc4-f4m6-wwqv", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "gopkg.in/yaml.v2", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "2.2.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WcChSpNAL6V9Xfxc9AqW7g==": { "id": "WcChSpNAL6V9Xfxc9AqW7g==", "updater": "rhel-vex", "name": "CVE-2025-15469", "description": "A flaw was found in openssl. When a user signs or verifies files larger than 16MB using the `openssl dgst` command with one-shot algorithms, the tool silently truncates the input to 16MB. This creates an integrity gap, allowing trailing data beyond the initial 16MB to be modified without detection because it remains unauthenticated. This vulnerability primarily impacts workflows that both sign and verify files using the affected `openssl dgst` command.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15469 https://bugzilla.redhat.com/show_bug.cgi?id=2430378 https://www.cve.org/CVERecord?id=CVE-2025-15469 https://nvd.nist.gov/vuln/detail/CVE-2025-15469 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15469.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WgM6qkbffWr4Ffsfxk0RDg==": { "id": "WgM6qkbffWr4Ffsfxk0RDg==", "updater": "osv/go", "name": "GO-2025-4155", "description": "Excessive resource consumption when printing error string for host certificate validation in crypto/x509", "issued": "2025-12-02T18:30:24Z", "links": "https://go.dev/cl/725920 https://go.dev/issue/76445 https://groups.google.com/g/golang-announce/c/8FJoBkPddm4 https://osv.dev/vulnerability/BIT-golang-2025-61729 https://osv.dev/vulnerability/CVE-2025-61729", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WkABThbDkGVWsBJZ8miT1w==": { "id": "WkABThbDkGVWsBJZ8miT1w==", "updater": "rhel-vex", "name": "CVE-2024-26461", "description": "A memory leak flaw was found in krb5 in /krb5/src/lib/gssapi/krb5/k5sealv3.c. This issue can lead to a denial of service through memory exhaustion.", "issued": "2024-02-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-26461 https://bugzilla.redhat.com/show_bug.cgi?id=2266740 https://www.cve.org/CVERecord?id=CVE-2024-26461 https://nvd.nist.gov/vuln/detail/CVE-2024-26461 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-26461.json https://access.redhat.com/errata/RHSA-2024:3268", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-27.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WkHqdnp8D70QvbkNJlkMDQ==": { "id": "WkHqdnp8D70QvbkNJlkMDQ==", "updater": "rhel-vex", "name": "CVE-2022-43552", "description": "A vulnerability was found in curl. In this issue, curl can be asked to tunnel all protocols virtually it supports through an HTTP proxy. HTTP proxies can deny these tunnel operations using an appropriate HTTP error response code. When getting denied to tunnel the specific SMB or TELNET protocols, curl can use a heap-allocated struct after it has been freed and shut down the code path in its transfer.", "issued": "2022-12-21T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-43552 https://bugzilla.redhat.com/show_bug.cgi?id=2152652 https://www.cve.org/CVERecord?id=CVE-2022-43552 https://nvd.nist.gov/vuln/detail/CVE-2022-43552 https://curl.se/docs/CVE-2022-43552.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-43552.json https://access.redhat.com/errata/RHSA-2023:2963", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-30.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WnU62DA2fwlfQLbeba0AYA==": { "id": "WnU62DA2fwlfQLbeba0AYA==", "updater": "rhel-vex", "name": "CVE-2026-56391", "description": "A flaw was found in GNU coreutils uniq. When processing specially crafted multibyte input with the --check-chars option, an attacker can trigger an out-of-bounds read. This vulnerability can lead to a denial of service (DoS) due to an application crash and potentially expose sensitive information from adjacent memory.", "issued": "2026-07-24T07:44:45Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56391 https://bugzilla.redhat.com/show_bug.cgi?id=2506691 https://www.cve.org/CVERecord?id=CVE-2026-56391 https://nvd.nist.gov/vuln/detail/CVE-2026-56391 https://cert.pl/en/posts/2026/07/CVE-2026-56391 https://git.savannah.gnu.org/cgit/coreutils.git/ https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56391.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Wp4+QBQm4nhI8rQxVklEXw==": { "id": "Wp4+QBQm4nhI8rQxVklEXw==", "updater": "rhel-vex", "name": "CVE-2025-4878", "description": "A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.", "issued": "2025-06-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-4878 https://bugzilla.redhat.com/show_bug.cgi?id=2376184 https://www.cve.org/CVERecord?id=CVE-2025-4878 https://nvd.nist.gov/vuln/detail/CVE-2025-4878 https://git.libssh.org/projects/libssh.git/commit/?id=697650caa97eaf7623924c75f9fcfec6dd423cd1 https://git.libssh.org/projects/libssh.git/commit/?id=b35ee876adc92a208d47194772e99f9c71e0bedb https://www.libssh.org/security/advisories/CVE-2025-4878.txt https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4878.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WqRrObt09T7C3IJPaLipRw==": { "id": "WqRrObt09T7C3IJPaLipRw==", "updater": "rhel-vex", "name": "CVE-2024-56171", "description": "A flaw was found in libxml2. This vulnerability allows a use-after-free via a crafted XML document validated against an XML schema with certain identity constraints or a crafted XML schema.", "issued": "2025-02-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-56171 https://bugzilla.redhat.com/show_bug.cgi?id=2346416 https://www.cve.org/CVERecord?id=CVE-2024-56171 https://nvd.nist.gov/vuln/detail/CVE-2024-56171 https://gitlab.gnome.org/GNOME/libxml2/-/issues/828 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-56171.json https://access.redhat.com/errata/RHSA-2025:2686", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-19.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Wy+NCeepWTSiKEZIMSlFrw==": { "id": "Wy+NCeepWTSiKEZIMSlFrw==", "updater": "rhel-vex", "name": "CVE-2025-6170", "description": "A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.", "issued": "2025-06-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-6170 https://bugzilla.redhat.com/show_bug.cgi?id=2372952 https://www.cve.org/CVERecord?id=CVE-2025-6170 https://nvd.nist.gov/vuln/detail/CVE-2025-6170 https://gitlab.gnome.org/GNOME/libxml2/-/issues/941 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6170.json https://access.redhat.com/errata/RHSA-2026:36734", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-21.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WzKr+vOS+cHO5ydxI18BFQ==": { "id": "WzKr+vOS+cHO5ydxI18BFQ==", "updater": "rhel-vex", "name": "CVE-2023-0361", "description": "A timing side-channel vulnerability was found in RSA ClientKeyExchange messages in GnuTLS. This side-channel may be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption, the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.", "issued": "2023-02-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-0361 https://bugzilla.redhat.com/show_bug.cgi?id=2162596 https://www.cve.org/CVERecord?id=CVE-2023-0361 https://nvd.nist.gov/vuln/detail/CVE-2023-0361 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0361.json https://access.redhat.com/errata/RHSA-2023:1569", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-6.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XOJZGmeZwsebobAglmEIzA==": { "id": "XOJZGmeZwsebobAglmEIzA==", "updater": "rhel-vex", "name": "CVE-2023-2283", "description": "A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,` which is initialized to SSH_ERROR and later rewritten to save the return value of the function call `pki_key_check_hash_compatible.` The value of the variable is not changed between this point and the cryptographic verification. Therefore any error between them calls `goto error` returning SSH_OK.", "issued": "2023-05-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-2283 https://bugzilla.redhat.com/show_bug.cgi?id=2189736 https://www.cve.org/CVERecord?id=CVE-2023-2283 https://nvd.nist.gov/vuln/detail/CVE-2023-2283 https://www.libssh.org/security/advisories/CVE-2023-2283.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-2283.json https://access.redhat.com/errata/RHSA-2023:3839", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-10.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XPV+5ujjQUNW+tos3Q+v/w==": { "id": "XPV+5ujjQUNW+tos3Q+v/w==", "updater": "rhel-vex", "name": "CVE-2026-40356", "description": "A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit an integer underflow and an out-of-bounds read vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the process terminating, resulting in a Denial of Service (DoS).", "issued": "2026-04-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40356 https://bugzilla.redhat.com/show_bug.cgi?id=2463368 https://www.cve.org/CVERecord?id=CVE-2026-40356 https://nvd.nist.gov/vuln/detail/CVE-2026-40356 https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f https://web.mit.edu/kerberos/advisories/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40356.json https://access.redhat.com/errata/RHSA-2026:16799", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-34.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XbpXfbeApuDuIKvY0/qWiA==": { "id": "XbpXfbeApuDuIKvY0/qWiA==", "updater": "rhel-vex", "name": "CVE-2026-3731", "description": "A flaw was found in libssh. A remote attacker could trigger an out-of-bounds read vulnerability in the SFTP Extension Name Handler by manipulating the `idx` argument in the `sftp_extensions_get_name` or `sftp_extensions_get_data` functions. This could lead to a Denial of Service (DoS), making the affected system unresponsive.", "issued": "2026-03-08T10:32:19Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3731 https://bugzilla.redhat.com/show_bug.cgi?id=2445579 https://www.cve.org/CVERecord?id=CVE-2026-3731 https://nvd.nist.gov/vuln/detail/CVE-2026-3731 https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60 https://vuldb.com/?ctiid.349709 https://vuldb.com/?id.349709 https://vuldb.com/?submit.767120 https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3731.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XkYYkW68UK2NwhLI/UmYUg==": { "id": "XkYYkW68UK2NwhLI/UmYUg==", "updater": "rhel-vex", "name": "CVE-2026-28390", "description": "A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS).", "issued": "2026-04-07T22:00:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-28390 https://bugzilla.redhat.com/show_bug.cgi?id=2456314 https://www.cve.org/CVERecord?id=CVE-2026-28390 https://nvd.nist.gov/vuln/detail/CVE-2026-28390 https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6 https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4 https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788 https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28390.json https://access.redhat.com/errata/RHSA-2026:38503", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-17.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XmzaV+28ObadSObJQlWH4A==": { "id": "XmzaV+28ObadSObJQlWH4A==", "updater": "rhel-vex", "name": "CVE-2024-33599", "description": "A stack-based buffer overflow flaw was found in the glibc netgroup cache. In certain conditions, its possible to trigger a stack-based buffer overflow condition that can lead to a denial of service and potentially other malicious actions that impact confidentiality and integrity.", "issued": "2024-04-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33599 https://bugzilla.redhat.com/show_bug.cgi?id=2277202 https://www.cve.org/CVERecord?id=CVE-2024-33599 https://nvd.nist.gov/vuln/detail/CVE-2024-33599 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33599.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XxIx1rZYfvSQo5y9eoFYqA==": { "id": "XxIx1rZYfvSQo5y9eoFYqA==", "updater": "osv/go", "name": "GO-2025-4012", "description": "Lack of limit when parsing cookies can cause memory exhaustion in net/http", "issued": "2025-10-29T21:50:05Z", "links": "https://go.dev/issue/75672 https://go.dev/cl/709855 https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI https://osv.dev/vulnerability/BIT-golang-2025-58186 https://osv.dev/vulnerability/CVE-2025-58186", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XygysGe2kdlyCRQHM1fu3w==": { "id": "XygysGe2kdlyCRQHM1fu3w==", "updater": "rhel-vex", "name": "CVE-2025-5917", "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5917 https://bugzilla.redhat.com/show_bug.cgi?id=2370874 https://www.cve.org/CVERecord?id=CVE-2025-5917 https://nvd.nist.gov/vuln/detail/CVE-2025-5917 https://github.com/libarchive/libarchive/pull/2588 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5917.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XzpR/ASE/VqV+Ft/wiA6Qw==": { "id": "XzpR/ASE/VqV+Ft/wiA6Qw==", "updater": "rhel-vex", "name": "CVE-2023-3817", "description": "A vulnerability was found in OpenSSL. This security issue occurs because the applications that use the DH_check(), DH_check_ex(), or EVP_PKEY_param_check() functions to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source may lead to a denial of service.", "issued": "2023-07-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-3817 https://bugzilla.redhat.com/show_bug.cgi?id=2227852 https://www.cve.org/CVERecord?id=CVE-2023-3817 https://nvd.nist.gov/vuln/detail/CVE-2023-3817 https://www.openssl.org/news/secadv/20230731.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-3817.json https://access.redhat.com/errata/RHSA-2023:7877", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-12.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Y/82v7jgmp9WbPyh6zXAqA==": { "id": "Y/82v7jgmp9WbPyh6zXAqA==", "updater": "rhel-vex", "name": "CVE-2023-4527", "description": "A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.", "issued": "2023-09-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4527 https://bugzilla.redhat.com/show_bug.cgi?id=2234712 https://www.cve.org/CVERecord?id=CVE-2023-4527 https://nvd.nist.gov/vuln/detail/CVE-2023-4527 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4527.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Y/DtnQFC7l5be2CCZ8YFhw==": { "id": "Y/DtnQFC7l5be2CCZ8YFhw==", "updater": "rhel-vex", "name": "CVE-2026-5928", "description": "A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.", "issued": "2026-04-20T20:37:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42733", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.40", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Y0QvAMtz9tlzAMfAFLbgjw==": { "id": "Y0QvAMtz9tlzAMfAFLbgjw==", "updater": "rhel-vex", "name": "CVE-2025-8058", "description": "A double-free vulnerability has been discovered in glibc (GNU C Library). This flaw occurs during bracket expression parsing within the regcomp function, specifically when a memory allocation failure takes place. Exploitation of a double-free vulnerability can lead to memory corruption, which could enable an attacker to achieve arbitrary code execution or a denial of service condition.", "issued": "2025-07-23T19:57:17Z", "links": "https://access.redhat.com/security/cve/CVE-2025-8058 https://bugzilla.redhat.com/show_bug.cgi?id=2383146 https://www.cve.org/CVERecord?id=CVE-2025-8058 https://nvd.nist.gov/vuln/detail/CVE-2025-8058 https://sourceware.org/bugzilla/show_bug.cgi?id=33185 https://sourceware.org/git/?p=glibc.git;a=commit;h=3ff17af18c38727b88d9115e536c069e6b5d601f https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-8058.json https://access.redhat.com/errata/RHSA-2025:12980", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.25", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YNVn4/OBbQHajyVtshrL3Q==": { "id": "YNVn4/OBbQHajyVtshrL3Q==", "updater": "rhel-vex", "name": "CVE-2022-22576", "description": "A vulnerability was found in curl. This security flaw allows reusing OAUTH2-authenticated connections without properly ensuring that the connection was authenticated with the same credentials set for this transfer. This issue leads to an authentication bypass, either by mistake or by a malicious actor.", "issued": "2022-04-27T06:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-22576 https://bugzilla.redhat.com/show_bug.cgi?id=2077541 https://www.cve.org/CVERecord?id=CVE-2022-22576 https://nvd.nist.gov/vuln/detail/CVE-2022-22576 https://curl.se/docs/CVE-2022-22576.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-22576.json https://access.redhat.com/errata/RHSA-2022:5313", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YOjk++xRTh9VXO273YBySg==": { "id": "YOjk++xRTh9VXO273YBySg==", "updater": "rhel-vex", "name": "CVE-2026-59845", "description": "A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.", "issued": "2026-07-21T11:23:44Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59845 https://bugzilla.redhat.com/show_bug.cgi?id=2498178 https://www.cve.org/CVERecord?id=CVE-2026-59845 https://nvd.nist.gov/vuln/detail/CVE-2026-59845 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59845.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YV4pdpWlOQp4ENY4WBgu+A==": { "id": "YV4pdpWlOQp4ENY4WBgu+A==", "updater": "osv/go", "name": "GO-2022-1038", "description": "Incorrect sanitization of forwarded query parameters in net/http/httputil", "issued": "2022-10-06T16:42:43Z", "links": "https://go.dev/issue/54663 https://go.dev/cl/432976 https://groups.google.com/g/golang-announce/c/xtuG5faxtaU https://osv.dev/vulnerability/BIT-golang-2022-2880 https://osv.dev/vulnerability/CVE-2022-2880", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.18.7", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YY1AnmNdojeTQaO/z5gGTA==": { "id": "YY1AnmNdojeTQaO/z5gGTA==", "updater": "rhel-vex", "name": "CVE-2023-28322", "description": "A use-after-free flaw was found in the Curl package. This issue may lead to unintended information disclosure by the application.", "issued": "2023-05-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-28322 https://bugzilla.redhat.com/show_bug.cgi?id=2196793 https://www.cve.org/CVERecord?id=CVE-2023-28322 https://nvd.nist.gov/vuln/detail/CVE-2023-28322 https://curl.se/docs/CVE-2023-28322.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-28322.json https://access.redhat.com/errata/RHSA-2024:1601", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-33.el8_9.5", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YYbr54PEl4J1NET9C1dPhg==": { "id": "YYbr54PEl4J1NET9C1dPhg==", "updater": "rhel-vex", "name": "CVE-2023-46218", "description": "A flaw was found in curl that verifies a given cookie domain against the Public Suffix List. This issue could allow a malicious HTTP server to set \"super cookies\" in curl that are passed back to more origins than what is otherwise allowed or possible.", "issued": "2023-12-06T07:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-46218 https://bugzilla.redhat.com/show_bug.cgi?id=2252030 https://www.cve.org/CVERecord?id=CVE-2023-46218 https://nvd.nist.gov/vuln/detail/CVE-2023-46218 https://curl.se/docs/CVE-2023-46218.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-46218.json https://access.redhat.com/errata/RHSA-2024:1601", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-33.el8_9.5", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YbAnIQEqWeedb46YJk3cBg==": { "id": "YbAnIQEqWeedb46YJk3cBg==", "updater": "rhel-vex", "name": "CVE-2026-58012", "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.", "issued": "2026-03-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58012 https://bugzilla.redhat.com/show_bug.cgi?id=2492247 https://www.cve.org/CVERecord?id=CVE-2026-58012 https://nvd.nist.gov/vuln/detail/CVE-2026-58012 https://gitlab.gnome.org/GNOME/glib/-/issues/3918 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58012.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YiJlkUTKf0/7+ORZMmQ2cw==": { "id": "YiJlkUTKf0/7+ORZMmQ2cw==", "updater": "rhel-vex", "name": "CVE-2025-25724", "description": "A flaw was found in the libarchive package. Affected versions of libarchive do not check a strftime return value, which can lead to a denial of service or unspecified other impacts via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.", "issued": "2025-03-02T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-25724 https://bugzilla.redhat.com/show_bug.cgi?id=2349221 https://www.cve.org/CVERecord?id=CVE-2025-25724 https://nvd.nist.gov/vuln/detail/CVE-2025-25724 https://gist.github.com/Ekkosun/a83870ce7f3b7813b9b462a395e8ad92 https://github.com/Ekkosun/pocs/blob/main/bsdtarbug https://github.com/libarchive/libarchive/blob/b439d586f53911c84be5e380445a8a259e19114c/tar/util.c#L751-L752 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-25724.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YjceJLqUKf33ztRXUlgI/Q==": { "id": "YjceJLqUKf33ztRXUlgI/Q==", "updater": "rhel-vex", "name": "CVE-2024-12243", "description": "A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.", "issued": "2025-02-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-12243 https://bugzilla.redhat.com/show_bug.cgi?id=2344615 https://www.cve.org/CVERecord?id=CVE-2024-12243 https://nvd.nist.gov/vuln/detail/CVE-2024-12243 https://gitlab.com/gnutls/gnutls/-/issues/1553 https://gitlab.com/gnutls/libtasn1/-/issues/52 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-12243.json https://access.redhat.com/errata/RHSA-2025:4051", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Yruwfu4Vkg/KNSmhqw2VEg==": { "id": "Yruwfu4Vkg/KNSmhqw2VEg==", "updater": "rhel-vex", "name": "CVE-2026-58015", "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.", "issued": "2026-04-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58015 https://bugzilla.redhat.com/show_bug.cgi?id=2492256 https://www.cve.org/CVERecord?id=CVE-2026-58015 https://nvd.nist.gov/vuln/detail/CVE-2026-58015 https://gitlab.gnome.org/GNOME/glib/-/issues/3931 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58015.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z4UHDiA4rMNuHhox79Bz/A==": { "id": "Z4UHDiA4rMNuHhox79Bz/A==", "updater": "rhel-vex", "name": "CVE-2024-33600", "description": "A flaw was found in the glibc netgroup cache. After a failed cache insertion, addgetnetgrentX tries to send the non-existing response after the not-found header. This can lead to a null pointer dereference that causes a crash or exit.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33600 https://bugzilla.redhat.com/show_bug.cgi?id=2277204 https://www.cve.org/CVERecord?id=CVE-2024-33600 https://nvd.nist.gov/vuln/detail/CVE-2024-33600 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33600.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z58BGKrYmp9sLvyqZKyMHQ==": { "id": "Z58BGKrYmp9sLvyqZKyMHQ==", "updater": "rhel-vex", "name": "CVE-2025-5318", "description": "A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.", "issued": "2025-06-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5318 https://bugzilla.redhat.com/show_bug.cgi?id=2369131 https://www.cve.org/CVERecord?id=CVE-2025-5318 https://nvd.nist.gov/vuln/detail/CVE-2025-5318 https://www.libssh.org/security/advisories/CVE-2025-5318.txt https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5318.json https://access.redhat.com/errata/RHSA-2025:18286", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh-config", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-15.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z9bgaNEOWbDMyC8kgQZMlw==": { "id": "Z9bgaNEOWbDMyC8kgQZMlw==", "updater": "rhel-vex", "name": "CVE-2026-27135", "description": "A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 frame, leading to an assertion failure and a denial of service (DoS).", "issued": "2026-03-18T17:59:02Z", "links": "https://access.redhat.com/security/cve/CVE-2026-27135 https://bugzilla.redhat.com/show_bug.cgi?id=2448754 https://www.cve.org/CVERecord?id=CVE-2026-27135 https://nvd.nist.gov/vuln/detail/CVE-2026-27135 https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1 https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json https://access.redhat.com/errata/RHSA-2026:7667", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "libnghttp2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.33.0-6.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZBcxIahHT2sOHcT4kdlprw==": { "id": "ZBcxIahHT2sOHcT4kdlprw==", "updater": "rhel-vex", "name": "CVE-2025-15281", "description": "A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service.", "issued": "2026-01-20T13:22:46Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15281 https://bugzilla.redhat.com/show_bug.cgi?id=2431196 https://www.cve.org/CVERecord?id=CVE-2025-15281 https://nvd.nist.gov/vuln/detail/CVE-2025-15281 https://sourceware.org/bugzilla/show_bug.cgi?id=33814 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15281.json https://access.redhat.com/errata/RHSA-2026:4772", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.31", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZE8z5pZigQ6zR3DrST6XmA==": { "id": "ZE8z5pZigQ6zR3DrST6XmA==", "updater": "osv/go", "name": "GO-2026-4864", "description": "TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix", "issued": "2026-04-07T22:53:49Z", "links": "https://go.dev/cl/763761 https://go.dev/issue/78293 https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU https://osv.dev/vulnerability/BIT-golang-2026-32282 https://osv.dev/vulnerability/CVE-2026-32282", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZRzqQ+u1wA21Iiq1JiWScw==": { "id": "ZRzqQ+u1wA21Iiq1JiWScw==", "updater": "rhel-vex", "name": "CVE-2021-35937", "description": "A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "issued": "2021-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-35937 https://bugzilla.redhat.com/show_bug.cgi?id=1964125 https://www.cve.org/CVERecord?id=CVE-2021-35937 https://nvd.nist.gov/vuln/detail/CVE-2021-35937 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-35937.json https://access.redhat.com/errata/RHSA-2024:0647", "severity": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "rpm-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:4.14.3-28.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZTGiJlkqcqrCLJSY/Sq8lA==": { "id": "ZTGiJlkqcqrCLJSY/Sq8lA==", "updater": "rhel-vex", "name": "CVE-2020-19186", "description": "A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a buffer over-read, resulting in an application crash.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19186 https://bugzilla.redhat.com/show_bug.cgi?id=2234908 https://www.cve.org/CVERecord?id=CVE-2020-19186 https://nvd.nist.gov/vuln/detail/CVE-2020-19186 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19186.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZkEez7f24VNVhTaTCDhuEg==": { "id": "ZkEez7f24VNVhTaTCDhuEg==", "updater": "rhel-vex", "name": "CVE-2025-15468", "description": "A flaw was found in openssl. A remote attacker could trigger a NULL pointer dereference by sending an unknown or unsupported cipher ID during the client hello callback in applications using the QUIC (Quick UDP Internet Connections) protocol. This vulnerability, occurring when the SSL_CIPHER_find() function is called in this specific context, leads to an abnormal termination of the running process, causing a Denial of Service (DoS).", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15468 https://bugzilla.redhat.com/show_bug.cgi?id=2430377 https://www.cve.org/CVERecord?id=CVE-2025-15468 https://nvd.nist.gov/vuln/detail/CVE-2025-15468 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15468.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Znm2hdK/FULQhTTGTVX59Q==": { "id": "Znm2hdK/FULQhTTGTVX59Q==", "updater": "rhel-vex", "name": "CVE-2026-3783", "description": "A flaw was found in curl. When an OAuth2 bearer token is used for an HTTP(S) transfer that redirects to a second URL, curl could unintentionally leak the token. This occurs if the second hostname has entries in the `.netrc` file, allowing the bearer token intended for the first host to be sent to the redirected host. This information disclosure could allow an attacker to gain unauthorized access.", "issued": "2026-03-11T10:09:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3783 https://bugzilla.redhat.com/show_bug.cgi?id=2446450 https://www.cve.org/CVERecord?id=CVE-2026-3783 https://nvd.nist.gov/vuln/detail/CVE-2026-3783 http://www.openwall.com/lists/oss-security/2026/03/11/2 https://curl.se/docs/CVE-2026-3783.html https://curl.se/docs/CVE-2026-3783.json https://hackerone.com/reports/3583983 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3783.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "a+awkS0u3U9BN7LTYpKUTg==": { "id": "a+awkS0u3U9BN7LTYpKUTg==", "updater": "rhel-vex", "name": "CVE-2026-5450", "description": "A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.", "issued": "2026-04-20T20:55:41Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33126", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.38", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "a0/2S5H7zlzjqVN38pRbOg==": { "id": "a0/2S5H7zlzjqVN38pRbOg==", "updater": "rhel-vex", "name": "CVE-2025-7425", "description": "A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.", "issued": "2025-07-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-7425 https://bugzilla.redhat.com/show_bug.cgi?id=2379274 https://www.cve.org/CVERecord?id=CVE-2025-7425 https://nvd.nist.gov/vuln/detail/CVE-2025-7425 https://gitlab.gnome.org/GNOME/libxslt/-/issues/140 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-7425.json https://access.redhat.com/errata/RHSA-2025:12450", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-21.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "a067YUjLHWzR99JNl/RtGQ==": { "id": "a067YUjLHWzR99JNl/RtGQ==", "updater": "rhel-vex", "name": "CVE-2025-4598", "description": "A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.", "issued": "2025-05-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-4598 https://bugzilla.redhat.com/show_bug.cgi?id=2369242 https://www.cve.org/CVERecord?id=CVE-2025-4598 https://nvd.nist.gov/vuln/detail/CVE-2025-4598 https://www.openwall.com/lists/oss-security/2025/05/29/3 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4598.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "a1JZMpXS/ssjLYCl17uNJA==": { "id": "a1JZMpXS/ssjLYCl17uNJA==", "updater": "rhel-vex", "name": "CVE-2021-35939", "description": "It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "issued": "2021-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-35939 https://bugzilla.redhat.com/show_bug.cgi?id=1964129 https://www.cve.org/CVERecord?id=CVE-2021-35939 https://nvd.nist.gov/vuln/detail/CVE-2021-35939 https://rpm.org/wiki/Releases/4.18.0 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-35939.json https://access.redhat.com/errata/RHSA-2024:0647", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "rpm-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:4.14.3-28.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "a9FCHpokzVfpw+gdnrzSXg==": { "id": "a9FCHpokzVfpw+gdnrzSXg==", "updater": "rhel-vex", "name": "CVE-2026-59850", "description": "A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.", "issued": "2026-07-21T14:08:16Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59850 https://bugzilla.redhat.com/show_bug.cgi?id=2498183 https://www.cve.org/CVERecord?id=CVE-2026-59850 https://nvd.nist.gov/vuln/detail/CVE-2026-59850 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59850.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aAOnNh+E2AVONwzbe0X/HA==": { "id": "aAOnNh+E2AVONwzbe0X/HA==", "updater": "osv/go", "name": "GO-2026-4342", "description": "Excessive CPU consumption when building archive index in archive/zip", "issued": "2026-01-28T19:08:28Z", "links": "https://go.dev/cl/736713 https://go.dev/issue/77102 https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc https://osv.dev/vulnerability/BIT-golang-2025-61728 https://osv.dev/vulnerability/CVE-2025-61728", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aT/aXsmladAgxlVRxWQriw==": { "id": "aT/aXsmladAgxlVRxWQriw==", "updater": "rhel-vex", "name": "CVE-2025-14104", "description": "A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.", "issued": "2025-12-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1852", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libuuid", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.32.1-48.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aVMgTmw8gvaYP/OjqlHeVA==": { "id": "aVMgTmw8gvaYP/OjqlHeVA==", "updater": "rhel-vex", "name": "CVE-2025-24928", "description": "A flaw was found in libxml2. This vulnerability allows a stack-based buffer overflow via DTD validation of an untrusted document or untrusted DTD.", "issued": "2025-02-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-24928 https://bugzilla.redhat.com/show_bug.cgi?id=2346421 https://www.cve.org/CVERecord?id=CVE-2025-24928 https://nvd.nist.gov/vuln/detail/CVE-2025-24928 https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 https://issues.oss-fuzz.com/issues/392687022 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24928.json https://access.redhat.com/errata/RHSA-2025:2686", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-19.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aetFzlYufXdv42s6KFBXcA==": { "id": "aetFzlYufXdv42s6KFBXcA==", "updater": "rhel-vex", "name": "CVE-2025-5914", "description": "A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5914 https://bugzilla.redhat.com/show_bug.cgi?id=2370861 https://www.cve.org/CVERecord?id=CVE-2025-5914 https://nvd.nist.gov/vuln/detail/CVE-2025-5914 https://github.com/libarchive/libarchive/pull/2598 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5914.json https://access.redhat.com/errata/RHSA-2025:14135", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "libarchive", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.3.3-6.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "afLJ2TrcMPRJL8v9fyt5hg==": { "id": "afLJ2TrcMPRJL8v9fyt5hg==", "updater": "rhel-vex", "name": "CVE-2026-5260", "description": "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5260 https://bugzilla.redhat.com/show_bug.cgi?id=2467450 https://www.cve.org/CVERecord?id=CVE-2026-5260 https://nvd.nist.gov/vuln/detail/CVE-2026-5260 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-10 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5260.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "assnsOgZ19ItYfuh/iKLMA==": { "id": "assnsOgZ19ItYfuh/iKLMA==", "updater": "rhel-vex", "name": "CVE-2026-59844", "description": "A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.", "issued": "2026-07-21T11:17:49Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59844 https://bugzilla.redhat.com/show_bug.cgi?id=2498177 https://www.cve.org/CVERecord?id=CVE-2026-59844 https://nvd.nist.gov/vuln/detail/CVE-2026-59844 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59844.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "avvi/YxG3J40ZK3NTLgmcQ==": { "id": "avvi/YxG3J40ZK3NTLgmcQ==", "updater": "rhel-vex", "name": "CVE-2023-3446", "description": "A vulnerability was found in OpenSSL. This security flaw occurs because the applications that use the DH_check(), DH_check_ex(), or EVP_PKEY_param_check() functions to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source may lead to a denial of service.", "issued": "2023-07-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-3446 https://bugzilla.redhat.com/show_bug.cgi?id=2224962 https://www.cve.org/CVERecord?id=CVE-2023-3446 https://nvd.nist.gov/vuln/detail/CVE-2023-3446 https://www.openssl.org/news/secadv/20230719.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-3446.json https://access.redhat.com/errata/RHSA-2023:7877", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-12.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ayNNRQmygz9tBo/oxR437A==": { "id": "ayNNRQmygz9tBo/oxR437A==", "updater": "rhel-vex", "name": "CVE-2026-33845", "description": "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.", "issued": "2026-04-30T17:28:41Z", "links": "https://access.redhat.com/security/cve/CVE-2026-33845 https://bugzilla.redhat.com/show_bug.cgi?id=2450624 https://www.cve.org/CVERecord?id=CVE-2026-33845 https://nvd.nist.gov/vuln/detail/CVE-2026-33845 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33845.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ayb0xDdrI1KzUFqnB2YdlQ==": { "id": "ayb0xDdrI1KzUFqnB2YdlQ==", "updater": "osv/go", "name": "GO-2026-4403", "description": "Improper access to parent directory of root in os", "issued": "2026-02-04T22:42:26Z", "links": "https://go.dev/cl/670036 https://go.dev/issue/73555 https://groups.google.com/g/golang-announce/c/UZoIkUT367A/m/5WDxKizJAQAJ https://osv.dev/vulnerability/BIT-golang-2025-22873 https://osv.dev/vulnerability/CVE-2025-22873", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.23.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "b4sDCRZC0dyaz+kllMgRKQ==": { "id": "b4sDCRZC0dyaz+kllMgRKQ==", "updater": "osv/go", "name": "GO-2022-1144", "description": "Excessive memory growth in net/http and golang.org/x/net/http2", "issued": "2022-12-08T19:01:21Z", "links": "https://go.dev/issue/56350 https://go.dev/cl/455717 https://go.dev/cl/455635 https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ https://osv.dev/vulnerability/BIT-golang-2022-41717 https://osv.dev/vulnerability/CVE-2022-41717 https://osv.dev/vulnerability/GHSA-xrjj-mj9h-534m", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.18.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bLEcs4XYapNmeTM4WLeVAw==": { "id": "bLEcs4XYapNmeTM4WLeVAw==", "updater": "rhel-vex", "name": "CVE-2022-32206", "description": "A vulnerability was found in curl. This issue occurs because the number of acceptable \"links\" in the \"decompression chain\" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps. This flaw leads to a denial of service, either by mistake or by a malicious actor.", "issued": "2022-06-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-32206 https://bugzilla.redhat.com/show_bug.cgi?id=2099300 https://www.cve.org/CVERecord?id=CVE-2022-32206 https://nvd.nist.gov/vuln/detail/CVE-2022-32206 https://curl.se/docs/CVE-2022-32206.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-32206.json https://access.redhat.com/errata/RHSA-2022:6159", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.4", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bYhoAXNcXAJxD4C8u0Ulpw==": { "id": "bYhoAXNcXAJxD4C8u0Ulpw==", "updater": "osv/go", "name": "GO-2025-4015", "description": "Excessive CPU consumption in Reader.ReadResponse in net/textproto", "issued": "2025-10-29T21:51:07Z", "links": "https://go.dev/cl/709859 https://go.dev/issue/75716 https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI https://osv.dev/vulnerability/BIT-golang-2025-61724 https://osv.dev/vulnerability/CVE-2025-61724", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bmNCCgFZ5KNaxCzyrOTM3g==": { "id": "bmNCCgFZ5KNaxCzyrOTM3g==", "updater": "rhel-vex", "name": "CVE-2024-5535", "description": "A flaw was found in OpenSSL. Affected versions of this package are vulnerable to Information Exposure through the SSL_select_next_proto function. This flaw allows an attacker to cause unexpected application behavior or a crash by exploiting the buffer overread condition when the function is called with a zero-length client list. This issue is only exploitable if the application is misconfigured to use a zero-length server list and mishandles the 'no overlap' response in ALPN or uses the output as the opportunistic protocol in NPN.", "issued": "2024-06-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-5535 https://bugzilla.redhat.com/show_bug.cgi?id=2294581 https://www.cve.org/CVERecord?id=CVE-2024-5535 https://nvd.nist.gov/vuln/detail/CVE-2024-5535 https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-5535.json https://access.redhat.com/errata/RHSA-2024:7848", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-14.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "btVUVAYdH5P1NknLO1YvNA==": { "id": "btVUVAYdH5P1NknLO1YvNA==", "updater": "osv/go", "name": "GO-2025-4013", "description": "Panic when validating certificates with DSA public keys in crypto/x509", "issued": "2025-10-29T21:50:08Z", "links": "https://go.dev/cl/709853 https://go.dev/issue/75675 https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI https://osv.dev/vulnerability/BIT-golang-2025-58188 https://osv.dev/vulnerability/CVE-2025-58188", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bzF8eDWfH3908SM3uW7W4Q==": { "id": "bzF8eDWfH3908SM3uW7W4Q==", "updater": "osv/go", "name": "GO-2026-5039", "description": "Arbitrary inputs are included in errors without any escaping in net/textproto", "issued": "2026-06-02T21:39:47Z", "links": "https://go.dev/issue/79346 https://go.dev/cl/777060 https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw https://osv.dev/vulnerability/BIT-golang-2026-42507 https://osv.dev/vulnerability/CVE-2026-42507", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cBE7uXJww3nGI7rdDj7t+Q==": { "id": "cBE7uXJww3nGI7rdDj7t+Q==", "updater": "rhel-vex", "name": "CVE-2024-33600", "description": "A flaw was found in the glibc netgroup cache. After a failed cache insertion, addgetnetgrentX tries to send the non-existing response after the not-found header. This can lead to a null pointer dereference that causes a crash or exit.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33600 https://bugzilla.redhat.com/show_bug.cgi?id=2277204 https://www.cve.org/CVERecord?id=CVE-2024-33600 https://nvd.nist.gov/vuln/detail/CVE-2024-33600 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33600.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cERFf1oFvXQnx4BPCz9RhA==": { "id": "cERFf1oFvXQnx4BPCz9RhA==", "updater": "rhel-vex", "name": "CVE-2026-42768", "description": "A flaw was found in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim's private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application's error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42768 https://bugzilla.redhat.com/show_bug.cgi?id=2481892 https://www.cve.org/CVERecord?id=CVE-2026-42768 https://nvd.nist.gov/vuln/detail/CVE-2026-42768 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42768.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cqYWiTibDLM7aibErMKang==": { "id": "cqYWiTibDLM7aibErMKang==", "updater": "rhel-vex", "name": "CVE-2026-4437", "description": "A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.", "issued": "2026-03-20T19:59:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4437 https://bugzilla.redhat.com/show_bug.cgi?id=2449777 https://www.cve.org/CVERecord?id=CVE-2026-4437 https://nvd.nist.gov/vuln/detail/CVE-2026-4437 https://sourceware.org/bugzilla/show_bug.cgi?id=34014 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4437.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "crmilTSJ/pTSPBKY9EJmZg==": { "id": "crmilTSJ/pTSPBKY9EJmZg==", "updater": "rhel-vex", "name": "CVE-2025-14524", "description": "A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14524 https://bugzilla.redhat.com/show_bug.cgi?id=2426407 https://www.cve.org/CVERecord?id=CVE-2025-14524 https://nvd.nist.gov/vuln/detail/CVE-2025-14524 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14524.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d80wPIXiop25QcH362PUgw==": { "id": "d80wPIXiop25QcH362PUgw==", "updater": "osv/go", "name": "GO-2026-4869", "description": "Unbounded allocation for old GNU sparse in archive/tar", "issued": "2026-04-07T22:53:49Z", "links": "https://go.dev/cl/763766 https://go.dev/issue/78301 https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU https://osv.dev/vulnerability/BIT-golang-2026-32288 https://osv.dev/vulnerability/CVE-2026-32288", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dGtImtgXxemdBTM1vCCLUg==": { "id": "dGtImtgXxemdBTM1vCCLUg==", "updater": "rhel-vex", "name": "CVE-2019-8905", "description": "A vulnerability was found in the \"File\" project where a stack-based buffer over-read exists in the do_core_note function within readelf.c of libmagic.a, by using a specially crafted file the attacker could access sensitive information or cause a denial of service.", "issued": "2019-02-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-8905 https://bugzilla.redhat.com/show_bug.cgi?id=1679181 https://www.cve.org/CVERecord?id=CVE-2019-8905 https://nvd.nist.gov/vuln/detail/CVE-2019-8905 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-8905.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "file", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dLBwvrbHvvMzC4tdzDzNMw==": { "id": "dLBwvrbHvvMzC4tdzDzNMw==", "updater": "rhel-vex", "name": "CVE-2026-11850", "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len \u003c 2, triggering the underflow when the KDC or kadmind reads principal data.", "issued": "2026-06-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11850 https://bugzilla.redhat.com/show_bug.cgi?id=2459970 https://www.cve.org/CVERecord?id=CVE-2026-11850 https://nvd.nist.gov/vuln/detail/CVE-2026-11850 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11850.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "krb5", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dYe0cnQs909yjJScdhxi8g==": { "id": "dYe0cnQs909yjJScdhxi8g==", "updater": "rhel-vex", "name": "CVE-2021-35937", "description": "A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "issued": "2021-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-35937 https://bugzilla.redhat.com/show_bug.cgi?id=1964125 https://www.cve.org/CVERecord?id=CVE-2021-35937 https://nvd.nist.gov/vuln/detail/CVE-2021-35937 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-35937.json https://access.redhat.com/errata/RHSA-2024:0647", "severity": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "rpm", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:4.14.3-28.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dYucp/SettSQd/Hpukj6pA==": { "id": "dYucp/SettSQd/Hpukj6pA==", "updater": "rhel-vex", "name": "CVE-2026-5545", "description": "A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5545 https://bugzilla.redhat.com/show_bug.cgi?id=2461204 https://www.cve.org/CVERecord?id=CVE-2026-5545 https://nvd.nist.gov/vuln/detail/CVE-2026-5545 https://curl.se/docs/CVE-2026-5545.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5545.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dcE/xJAn45jFiks4WqmKbQ==": { "id": "dcE/xJAn45jFiks4WqmKbQ==", "updater": "rhel-vex", "name": "CVE-2024-33600", "description": "A flaw was found in the glibc netgroup cache. After a failed cache insertion, addgetnetgrentX tries to send the non-existing response after the not-found header. This can lead to a null pointer dereference that causes a crash or exit.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33600 https://bugzilla.redhat.com/show_bug.cgi?id=2277204 https://www.cve.org/CVERecord?id=CVE-2024-33600 https://nvd.nist.gov/vuln/detail/CVE-2024-33600 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33600.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dtogVDvmA8tsAGvyEPjPQA==": { "id": "dtogVDvmA8tsAGvyEPjPQA==", "updater": "rhel-vex", "name": "CVE-2025-0395", "description": "A flaw was found in the GNU C Library (glibc). A buffer overflow condition via the `assert()` function may be triggered due to glibc not allocating enough space for the assertion failure message string and size information. In certain conditions, a local attacker can exploit this, potentially leading to an application crash or other undefined behavior.", "issued": "2025-01-22T13:11:30Z", "links": "https://access.redhat.com/security/cve/CVE-2025-0395 https://bugzilla.redhat.com/show_bug.cgi?id=2339460 https://www.cve.org/CVERecord?id=CVE-2025-0395 https://nvd.nist.gov/vuln/detail/CVE-2025-0395 https://sourceware.org/bugzilla/show_bug.cgi?id=32582 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-0395.json https://access.redhat.com/errata/RHSA-2025:3828", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.16", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dvRjQ6BpPMHoRj/7w9dv/g==": { "id": "dvRjQ6BpPMHoRj/7w9dv/g==", "updater": "rhel-vex", "name": "CVE-2025-68973", "description": "A flaw was found in GnuPG. An attacker can provide crafted input to the `armor_filter` function, which incorrectly increments an index variable, leading to an out-of-bounds write. This memory corruption vulnerability may allow for information disclosure and could potentially lead to arbitrary code execution.", "issued": "2025-12-28T16:19:11Z", "links": "https://access.redhat.com/security/cve/CVE-2025-68973 https://bugzilla.redhat.com/show_bug.cgi?id=2425966 https://www.cve.org/CVERecord?id=CVE-2025-68973 https://nvd.nist.gov/vuln/detail/CVE-2025-68973 https://github.com/gpg/gnupg/blob/ff30683418695f5d2cc9e6cf8c9418e09378ebe4/g10/armor.c#L1305-L1306 https://github.com/gpg/gnupg/commit/115d138ba599328005c5321c0ef9f00355838ca9 https://gpg.fail/memcpy https://news.ycombinator.com/item?id=46403200 https://www.openwall.com/lists/oss-security/2025/12/28/5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68973.json https://access.redhat.com/errata/RHSA-2026:0728", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.2.20-4.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eFkHRGAjSFu9sbgr+RArOA==": { "id": "eFkHRGAjSFu9sbgr+RArOA==", "updater": "rhel-vex", "name": "CVE-2026-56392", "description": "A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a heap-based buffer overflow, occurs due to an integer overflow when `unexpand` processes unusually large tab stop values provided by a local attacker. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries. Successful exploitation can cause the `unexpand` utility to crash, potentially resulting in a denial of service or enabling further memory manipulation.", "issued": "2026-07-24T07:44:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56392 https://bugzilla.redhat.com/show_bug.cgi?id=2506694 https://www.cve.org/CVERecord?id=CVE-2026-56392 https://nvd.nist.gov/vuln/detail/CVE-2026-56392 https://cert.pl/en/posts/2026/07/CVE-2026-56391 https://git.savannah.gnu.org/cgit/coreutils.git/ https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56392.json https://access.redhat.com/errata/RHBA-2026:47115", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "coreutils-single", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:8.30-20.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eKx2b/57ZENrxVKuRWfmwQ==": { "id": "eKx2b/57ZENrxVKuRWfmwQ==", "updater": "osv/go", "name": "GHSA-wxc4-f4m6-wwqv", "description": "Excessive Platform Resource Consumption within a Loop in Kubernetes", "issued": "2021-12-20T16:55:06Z", "links": "https://nvd.nist.gov/vuln/detail/CVE-2019-11254 https://github.com/kubernetes/kubernetes/issues/89535 https://github.com/go-yaml/yaml/pull/555 https://github.com/kubernetes/kubernetes/pull/87467/commits/b86df2bec4f377afc0ca03482ffad2f0a49a83b8 https://github.com/go-yaml/yaml/commit/53403b58ad1b561927d19068c655246f2db79d48 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18496 https://groups.google.com/d/msg/kubernetes-announce/ALL9s73E5ck/4yHe8J-PBAAJ https://pkg.go.dev/vuln/GO-2020-0036 https://security.netapp.com/advisory/ntap-20200413-0003 https://osv.dev/vulnerability/CVE-2019-11254 https://osv.dev/vulnerability/GO-2020-0036", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gopkg.in/yaml.v2", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "2.2.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eSKL36MlZ1HyqAeoxF6NSA==": { "id": "eSKL36MlZ1HyqAeoxF6NSA==", "updater": "rhel-vex", "name": "CVE-2022-32792", "description": "A vulnerability was found in webkit. This issue occurs when processing maliciously crafted web content which may lead to arbitrary code execution.", "issued": "2022-07-04T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-32792 https://bugzilla.redhat.com/show_bug.cgi?id=2238973 https://www.cve.org/CVERecord?id=CVE-2022-32792 https://nvd.nist.gov/vuln/detail/CVE-2022-32792 https://wpewebkit.org/security/WSA-2022-0007.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-32792.json https://access.redhat.com/errata/RHSA-2022:7704", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.56.4-159.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ef6DhO/UZ786aZ02XWCNqQ==": { "id": "ef6DhO/UZ786aZ02XWCNqQ==", "updater": "rhel-vex", "name": "CVE-2026-42015", "description": "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42015 https://bugzilla.redhat.com/show_bug.cgi?id=2467678 https://www.cve.org/CVERecord?id=CVE-2026-42015 https://nvd.nist.gov/vuln/detail/CVE-2026-42015 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-11 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42015.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ehV42Kf4mNxkwEnYSPYF5A==": { "id": "ehV42Kf4mNxkwEnYSPYF5A==", "updater": "rhel-vex", "name": "CVE-2023-4911", "description": "A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.", "issued": "2023-10-03T17:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4911 https://bugzilla.redhat.com/show_bug.cgi?id=2238352 https://www.cve.org/CVERecord?id=CVE-2023-4911 https://nvd.nist.gov/vuln/detail/CVE-2023-4911 https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt https://www.qualys.com/cve-2023-4911/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4911.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f3P/kawtCGYCSTroATyzAw==": { "id": "f3P/kawtCGYCSTroATyzAw==", "updater": "rhel-vex", "name": "CVE-2024-2961", "description": "An out-of-bounds write flaw was found in the ISO-2022-CN-EXT plugin for glibc's iconv library. When converting from UCS4 charset, adding certain escape charterers is required to indicate where the charset was changed to the library. During this process, iconv improperly checks the boundaries of internal buffers, leading to a buffer overflow, which allows writing up to 3 bytes outside the desired memory location. This issue may allow an attacker to craft a malicious characters sequence that will trigger the out-of-bounds write and perform remote code execution, presenting a high impact to the Integrity, Confidentiality, and Availability triad.", "issued": "2024-04-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2961 https://bugzilla.redhat.com/show_bug.cgi?id=2273404 https://www.cve.org/CVERecord?id=CVE-2024-2961 https://nvd.nist.gov/vuln/detail/CVE-2024-2961 https://www.openwall.com/lists/oss-security/2024/04/17/9 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2961.json https://access.redhat.com/errata/RHSA-2024:2722", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-236.el8_9.13", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f6JqroM9DAPFPzLvkr6TsA==": { "id": "f6JqroM9DAPFPzLvkr6TsA==", "updater": "rhel-vex", "name": "CVE-2022-43552", "description": "A vulnerability was found in curl. In this issue, curl can be asked to tunnel all protocols virtually it supports through an HTTP proxy. HTTP proxies can deny these tunnel operations using an appropriate HTTP error response code. When getting denied to tunnel the specific SMB or TELNET protocols, curl can use a heap-allocated struct after it has been freed and shut down the code path in its transfer.", "issued": "2022-12-21T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-43552 https://bugzilla.redhat.com/show_bug.cgi?id=2152652 https://www.cve.org/CVERecord?id=CVE-2022-43552 https://nvd.nist.gov/vuln/detail/CVE-2022-43552 https://curl.se/docs/CVE-2022-43552.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-43552.json https://access.redhat.com/errata/RHSA-2023:2963", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-30.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f8CIZ65CD/f6e9Mdmn8vXg==": { "id": "f8CIZ65CD/f6e9Mdmn8vXg==", "updater": "rhel-vex", "name": "CVE-2024-28834", "description": "A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.", "issued": "2024-03-21T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-28834 https://bugzilla.redhat.com/show_bug.cgi?id=2269228 https://www.cve.org/CVERecord?id=CVE-2024-28834 https://nvd.nist.gov/vuln/detail/CVE-2024-28834 https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html https://minerva.crocs.fi.muni.cz/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-28834.json https://access.redhat.com/errata/RHSA-2024:1784", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_9.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fM/S1lXLzT3yP+sZqhNB0g==": { "id": "fM/S1lXLzT3yP+sZqhNB0g==", "updater": "rhel-vex", "name": "CVE-2022-1304", "description": "An out-of-bounds read/write vulnerability was found in e2fsprogs. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.", "issued": "2022-03-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-1304 https://bugzilla.redhat.com/show_bug.cgi?id=2069726 https://www.cve.org/CVERecord?id=CVE-2022-1304 https://nvd.nist.gov/vuln/detail/CVE-2022-1304 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-1304.json https://access.redhat.com/errata/RHSA-2022:7720", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libcom_err", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.45.6-5.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fOQmU56iPUBV8Qguc6zUjg==": { "id": "fOQmU56iPUBV8Qguc6zUjg==", "updater": "rhel-vex", "name": "CVE-2024-2398", "description": "A flaw was found in curl. When an application configures libcurl to use HTTP/2 server push and the amount of received headers for the push surpasses the maximum allowed limit, libcurl aborts the server push. When aborting, libcurl does not free all the previously allocated headers, resulting in a memory leak.", "issued": "2024-03-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2398 https://bugzilla.redhat.com/show_bug.cgi?id=2270498 https://www.cve.org/CVERecord?id=CVE-2024-2398 https://nvd.nist.gov/vuln/detail/CVE-2024-2398 https://curl.se/docs/CVE-2024-2398.html https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2398.json https://access.redhat.com/errata/RHSA-2024:5654", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-34.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fPSdx84mD5ZpVIqkzEY7lw==": { "id": "fPSdx84mD5ZpVIqkzEY7lw==", "updater": "rhel-vex", "name": "CVE-2022-27774", "description": "A vulnerability was found in curl. This security flaw allows leaking credentials to other servers when it follows redirects from auth-protected HTTP(S) URLs to other protocols and port numbers.", "issued": "2022-04-27T06:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-27774 https://bugzilla.redhat.com/show_bug.cgi?id=2077547 https://www.cve.org/CVERecord?id=CVE-2022-27774 https://nvd.nist.gov/vuln/detail/CVE-2022-27774 https://curl.se/docs/CVE-2022-27774.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-27774.json https://access.redhat.com/errata/RHSA-2022:5313", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fT6cIVRM+743nfHJKo4yuQ==": { "id": "fT6cIVRM+743nfHJKo4yuQ==", "updater": "rhel-vex", "name": "CVE-2026-6429", "description": "A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6429 https://bugzilla.redhat.com/show_bug.cgi?id=2461205 https://www.cve.org/CVERecord?id=CVE-2026-6429 https://nvd.nist.gov/vuln/detail/CVE-2026-6429 https://curl.se/docs/CVE-2026-6429.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6429.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fTM3JBmBHsfnwLNG4gJHRQ==": { "id": "fTM3JBmBHsfnwLNG4gJHRQ==", "updater": "rhel-vex", "name": "CVE-2026-4046", "description": "A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).", "issued": "2026-03-30T17:16:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20587", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.37", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fXpWtuXNPi3tb2edhk37bw==": { "id": "fXpWtuXNPi3tb2edhk37bw==", "updater": "rhel-vex", "name": "CVE-2024-2236", "description": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.", "issued": "2024-03-06T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2236 https://bugzilla.redhat.com/show_bug.cgi?id=2245218 https://www.cve.org/CVERecord?id=CVE-2024-2236 https://nvd.nist.gov/vuln/detail/CVE-2024-2236 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2236.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fYMNFu0xQxp0Z7y2lb9Aog==": { "id": "fYMNFu0xQxp0Z7y2lb9Aog==", "updater": "rhel-vex", "name": "CVE-2026-6238", "description": "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.", "issued": "2026-04-28T16:43:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42733", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.40", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fayrPya6DVXP9weWvA6obQ==": { "id": "fayrPya6DVXP9weWvA6obQ==", "updater": "rhel-vex", "name": "CVE-2024-7264", "description": "A flaw was found in libcurl, where libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the length of the *time fraction*, leading to a `strlen()` performed on a pointer to a heap buffer area that is not purposely NULL terminated.", "issued": "2024-07-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-7264 https://bugzilla.redhat.com/show_bug.cgi?id=2301888 https://www.cve.org/CVERecord?id=CVE-2024-7264 https://nvd.nist.gov/vuln/detail/CVE-2024-7264 https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-7264.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fpkJVe/KmtRv+bBXsYsIcg==": { "id": "fpkJVe/KmtRv+bBXsYsIcg==", "updater": "osv/go", "name": "GO-2023-1568", "description": "Path traversal on Windows in path/filepath", "issued": "2023-02-16T19:49:19Z", "links": "https://go.dev/issue/57274 https://go.dev/cl/468123 https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E https://osv.dev/vulnerability/BIT-golang-2022-41722 https://osv.dev/vulnerability/CVE-2022-41722", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.6", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fvGjL9hw9hDQockMTb7lrA==": { "id": "fvGjL9hw9hDQockMTb7lrA==", "updater": "rhel-vex", "name": "CVE-2021-4209", "description": "A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.", "issued": "2021-12-22T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-4209 https://bugzilla.redhat.com/show_bug.cgi?id=2044156 https://www.cve.org/CVERecord?id=CVE-2021-4209 https://nvd.nist.gov/vuln/detail/CVE-2021-4209 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-4209.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gnutls", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fyxlf06S6rMafIj672gFrg==": { "id": "fyxlf06S6rMafIj672gFrg==", "updater": "osv/go", "name": "GO-2023-2186", "description": "Incorrect detection of reserved device names on Windows in path/filepath", "issued": "2023-11-08T22:42:19Z", "links": "https://go.dev/issue/63713 https://go.dev/cl/540277 https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY https://osv.dev/vulnerability/BIT-golang-2023-45284 https://osv.dev/vulnerability/CVE-2023-45284", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.20.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gJbhqv40+/JI6bs5ENVcow==": { "id": "gJbhqv40+/JI6bs5ENVcow==", "updater": "rhel-vex", "name": "CVE-2025-0395", "description": "A flaw was found in the GNU C Library (glibc). A buffer overflow condition via the `assert()` function may be triggered due to glibc not allocating enough space for the assertion failure message string and size information. In certain conditions, a local attacker can exploit this, potentially leading to an application crash or other undefined behavior.", "issued": "2025-01-22T13:11:30Z", "links": "https://access.redhat.com/security/cve/CVE-2025-0395 https://bugzilla.redhat.com/show_bug.cgi?id=2339460 https://www.cve.org/CVERecord?id=CVE-2025-0395 https://nvd.nist.gov/vuln/detail/CVE-2025-0395 https://sourceware.org/bugzilla/show_bug.cgi?id=32582 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-0395.json https://access.redhat.com/errata/RHSA-2025:3828", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.16", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gQZBNz/hUjPyqafsGVQi7g==": { "id": "gQZBNz/hUjPyqafsGVQi7g==", "updater": "rhel-vex", "name": "CVE-2019-12900", "description": "A data integrity error was found in the bzip2 (User-space package) functionality when decompressing. This issue occurs when a user decompresses a particular kind of .bz2 files. A local user could get unexpected results (or corrupted data) as result of decompressing these files.", "issued": "2024-11-15T10:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-12900 https://bugzilla.redhat.com/show_bug.cgi?id=2332075 https://www.cve.org/CVERecord?id=CVE-2019-12900 https://nvd.nist.gov/vuln/detail/CVE-2019-12900 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-12900.json https://access.redhat.com/errata/RHSA-2024:8922", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "bzip2-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.0.6-27.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gWWpK4sdhrZSUeW3Sm8ORA==": { "id": "gWWpK4sdhrZSUeW3Sm8ORA==", "updater": "rhel-vex", "name": "CVE-2024-33601", "description": "A flaw was found in the glibc netgroup cache. The netgroup cache uses xmalloc/xrealloc and may terminate the process due to a memory allocation failure.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33601 https://bugzilla.redhat.com/show_bug.cgi?id=2277205 https://www.cve.org/CVERecord?id=CVE-2024-33601 https://nvd.nist.gov/vuln/detail/CVE-2024-33601 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33601.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gX9OFbpxSsqG4i5HYpODaA==": { "id": "gX9OFbpxSsqG4i5HYpODaA==", "updater": "rhel-vex", "name": "CVE-2024-33602", "description": "A flaw was found in the glibc netgroup cache. The buffer-resizing code in addgetnetgrentX assumes that all string pointers point into the supplied buffer. This can potentially lead to memory corruption and cause a crash.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33602 https://bugzilla.redhat.com/show_bug.cgi?id=2277206 https://www.cve.org/CVERecord?id=CVE-2024-33602 https://nvd.nist.gov/vuln/detail/CVE-2024-33602 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33602.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gagftKXuSuh9pi4dRu9yPQ==": { "id": "gagftKXuSuh9pi4dRu9yPQ==", "updater": "rhel-vex", "name": "CVE-2024-2511", "description": "A flaw was found in OpenSSL. A malicious client can trigger an uncontrolled memory consumption, resulting in a Denial of Service. This issue occurs due to OpenSSL's TLSv1.3 session cache going into an incorrect state, leading to it failing to flush properly as it fills. OpenSSL must be configured with the non-default SSL_OP_NO_TICKET option enabled to be vulnerable. This issue only affects TLSv1.3 servers, while TLS clients are not affected.", "issued": "2024-04-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2511 https://bugzilla.redhat.com/show_bug.cgi?id=2274020 https://www.cve.org/CVERecord?id=CVE-2024-2511 https://nvd.nist.gov/vuln/detail/CVE-2024-2511 https://www.openssl.org/news/vulnerabilities.html https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2511.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gbxzM63S/+/q05197cVzwA==": { "id": "gbxzM63S/+/q05197cVzwA==", "updater": "rhel-vex", "name": "CVE-2022-27774", "description": "A vulnerability was found in curl. This security flaw allows leaking credentials to other servers when it follows redirects from auth-protected HTTP(S) URLs to other protocols and port numbers.", "issued": "2022-04-27T06:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-27774 https://bugzilla.redhat.com/show_bug.cgi?id=2077547 https://www.cve.org/CVERecord?id=CVE-2022-27774 https://nvd.nist.gov/vuln/detail/CVE-2022-27774 https://curl.se/docs/CVE-2022-27774.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-27774.json https://access.redhat.com/errata/RHSA-2022:5313", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "geTtkmTtPDxSAjfZEBGWfQ==": { "id": "geTtkmTtPDxSAjfZEBGWfQ==", "updater": "rhel-vex", "name": "CVE-2020-11023", "description": "A flaw was found in jQuery. HTML containing \\\u003coption\\\u003e elements from untrusted sources are passed, even after sanitizing, to one of jQuery's DOM manipulation methods, which may execute untrusted code. The highest threat from this vulnerability is to data confidentiality and integrity.", "issued": "2020-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-11023 https://bugzilla.redhat.com/show_bug.cgi?id=1850004 https://www.cve.org/CVERecord?id=CVE-2020-11023 https://nvd.nist.gov/vuln/detail/CVE-2020-11023 https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-11023.json https://access.redhat.com/errata/RHSA-2025:1301", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libgcc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:8.5.0-23.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gqNlp+zMbwHq1FhCyd5krQ==": { "id": "gqNlp+zMbwHq1FhCyd5krQ==", "updater": "rhel-vex", "name": "CVE-2023-48795", "description": "A flaw was found in the SSH channel integrity. By manipulating sequence numbers during the handshake, an attacker can remove the initial messages on the secure channel without causing a MAC failure. For example, an attacker could disable the ping extension and thus disable the new countermeasure in OpenSSH 9.5 against keystroke timing attacks.", "issued": "2023-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-48795 https://bugzilla.redhat.com/show_bug.cgi?id=2254210 https://www.cve.org/CVERecord?id=CVE-2023-48795 https://nvd.nist.gov/vuln/detail/CVE-2023-48795 https://access.redhat.com/solutions/7071748 https://terrapin-attack.com/ https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-48795.json https://access.redhat.com/errata/RHSA-2024:0628", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh-config", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-13.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gqZgaapoEbnm+Oj7iPZ37w==": { "id": "gqZgaapoEbnm+Oj7iPZ37w==", "updater": "rhel-vex", "name": "CVE-2022-2509", "description": "A vulnerability was found in gnutls. This issue is due to a double-free error that occurs during the verification of pkcs7 signatures in the gnutls_pkcs7_verify function.", "issued": "2022-07-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-2509 https://bugzilla.redhat.com/show_bug.cgi?id=2108977 https://www.cve.org/CVERecord?id=CVE-2022-2509 https://nvd.nist.gov/vuln/detail/CVE-2022-2509 https://gnutls.org/security-new.html#GNUTLS-SA-2022-07-07 https://lists.gnupg.org/pipermail/gnutls-help/2022-July/004746.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2509.json https://access.redhat.com/errata/RHSA-2022:7105", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-5.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hJlWqZ7n1IINkFnSLUe61w==": { "id": "hJlWqZ7n1IINkFnSLUe61w==", "updater": "rhel-vex", "name": "CVE-2023-46218", "description": "A flaw was found in curl that verifies a given cookie domain against the Public Suffix List. This issue could allow a malicious HTTP server to set \"super cookies\" in curl that are passed back to more origins than what is otherwise allowed or possible.", "issued": "2023-12-06T07:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-46218 https://bugzilla.redhat.com/show_bug.cgi?id=2252030 https://www.cve.org/CVERecord?id=CVE-2023-46218 https://nvd.nist.gov/vuln/detail/CVE-2023-46218 https://curl.se/docs/CVE-2023-46218.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-46218.json https://access.redhat.com/errata/RHSA-2024:1601", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-33.el8_9.5", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hfBpyVezkUAf98QWnlvzIA==": { "id": "hfBpyVezkUAf98QWnlvzIA==", "updater": "rhel-vex", "name": "CVE-2026-34743", "description": "A flaw was found in XZ Utils. When the `lzma_index_decoder()` function processes an empty index, and a subsequent `lzma_index_append()` operation is performed, insufficient memory is allocated. This can lead to a buffer overflow, potentially causing a denial of service (DoS) for affected systems.", "issued": "2026-04-02T18:36:37Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34743 https://bugzilla.redhat.com/show_bug.cgi?id=2454589 https://www.cve.org/CVERecord?id=CVE-2026-34743 https://nvd.nist.gov/vuln/detail/CVE-2026-34743 https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87 https://github.com/tukaani-project/xz/releases/tag/v5.8.3 https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34743.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "xz", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "i/DIhomKIBWLQ9viL//FXQ==": { "id": "i/DIhomKIBWLQ9viL//FXQ==", "updater": "rhel-vex", "name": "CVE-2024-33600", "description": "A flaw was found in the glibc netgroup cache. After a failed cache insertion, addgetnetgrentX tries to send the non-existing response after the not-found header. This can lead to a null pointer dereference that causes a crash or exit.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33600 https://bugzilla.redhat.com/show_bug.cgi?id=2277204 https://www.cve.org/CVERecord?id=CVE-2024-33600 https://nvd.nist.gov/vuln/detail/CVE-2024-33600 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33600.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iEGZHZXt8HWPSM5eJesddQ==": { "id": "iEGZHZXt8HWPSM5eJesddQ==", "updater": "rhel-vex", "name": "CVE-2025-7039", "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.", "issued": "2025-07-02T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-7039 https://bugzilla.redhat.com/show_bug.cgi?id=2392423 https://www.cve.org/CVERecord?id=CVE-2025-7039 https://nvd.nist.gov/vuln/detail/CVE-2025-7039 https://gitlab.gnome.org/GNOME/glib/-/issues/3716 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-7039.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iFFhT3GCX+mTkglBusKyXw==": { "id": "iFFhT3GCX+mTkglBusKyXw==", "updater": "rhel-vex", "name": "CVE-2023-5981", "description": "A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.", "issued": "2023-11-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-5981 https://bugzilla.redhat.com/show_bug.cgi?id=2248445 https://www.cve.org/CVERecord?id=CVE-2023-5981 https://nvd.nist.gov/vuln/detail/CVE-2023-5981 https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-5981.json https://access.redhat.com/errata/RHSA-2024:0155", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iFSzJrooziqfdj1JNPZnuw==": { "id": "iFSzJrooziqfdj1JNPZnuw==", "updater": "osv/go", "name": "GO-2025-4011", "description": "Parsing DER payload can cause memory exhaustion in encoding/asn1", "issued": "2025-10-29T21:50:00Z", "links": "https://go.dev/issue/75671 https://go.dev/cl/709856 https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI https://osv.dev/vulnerability/BIT-golang-2025-58185 https://osv.dev/vulnerability/CVE-2025-58185", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iFhWPnp6w/VV9hJa/b0oig==": { "id": "iFhWPnp6w/VV9hJa/b0oig==", "updater": "rhel-vex", "name": "CVE-2026-42770", "description": "A flaw was found in OpenSSL. A malicious peer can exploit this vulnerability by presenting a specially crafted DHX (X9.42) peer key. Due to improper validation of the peer key's subgroup membership, an attacker can recover the victim's private key after a small number of key exchange attempts. This information disclosure can lead to unauthorized access or further compromise of affected systems.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42770 https://bugzilla.redhat.com/show_bug.cgi?id=2481894 https://www.cve.org/CVERecord?id=CVE-2026-42770 https://nvd.nist.gov/vuln/detail/CVE-2026-42770 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42770.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iXEopm+7p5ZQvLickgqvJQ==": { "id": "iXEopm+7p5ZQvLickgqvJQ==", "updater": "rhel-vex", "name": "CVE-2025-32414", "description": "A flaw was found in libxml2. This vulnerability allows out-of-bounds memory access due to incorrect handling of return values in xmlPythonFileRead and xmlPythonFileReadRaw. This is caused by a mismatch between the length of the file in bytes vs the length in characters, as unicode characters can occupy up to 4 bytes per character.", "issued": "2025-04-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-32414 https://bugzilla.redhat.com/show_bug.cgi?id=2358121 https://www.cve.org/CVERecord?id=CVE-2025-32414 https://nvd.nist.gov/vuln/detail/CVE-2025-32414 https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-32414.json https://access.redhat.com/errata/RHSA-2025:8958", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-20.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "icj6a8bc4dYK/DJNvkU0+A==": { "id": "icj6a8bc4dYK/DJNvkU0+A==", "updater": "rhel-vex", "name": "CVE-2022-41409", "description": "A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack.", "issued": "2023-07-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-41409 https://bugzilla.redhat.com/show_bug.cgi?id=2260814 https://www.cve.org/CVERecord?id=CVE-2022-41409 https://nvd.nist.gov/vuln/detail/CVE-2022-41409 https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35 https://github.com/PCRE2Project/pcre2/issues/141 https://github.com/advisories/GHSA-4qfx-v7wh-3q4j https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-41409.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "pcre2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ieASPdYzGxWke8nZZhE02Q==": { "id": "ieASPdYzGxWke8nZZhE02Q==", "updater": "rhel-vex", "name": "CVE-2018-20657", "description": "A vulnerability was found in the demangle_template function in GNU libiberty, as distributed in GNU Binutils, where a memory leak could occur, a specially crafted file could cause the application to consume excessive memory, potentially leading to a crash.", "issued": "2018-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-20657 https://bugzilla.redhat.com/show_bug.cgi?id=1664708 https://www.cve.org/CVERecord?id=CVE-2018-20657 https://nvd.nist.gov/vuln/detail/CVE-2018-20657 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-20657.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gcc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ilhK+Ap+h5mZVKmQX7nDwg==": { "id": "ilhK+Ap+h5mZVKmQX7nDwg==", "updater": "rhel-vex", "name": "CVE-2023-6918", "description": "A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.", "issued": "2023-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-6918 https://bugzilla.redhat.com/show_bug.cgi?id=2254997 https://www.cve.org/CVERecord?id=CVE-2023-6918 https://nvd.nist.gov/vuln/detail/CVE-2023-6918 https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases/ https://www.libssh.org/security/advisories/CVE-2023-6918.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6918.json https://access.redhat.com/errata/RHSA-2024:3233", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-14.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "imeJafHbpMchyG3ddsecRg==": { "id": "imeJafHbpMchyG3ddsecRg==", "updater": "osv/go", "name": "GO-2024-2599", "description": "Memory exhaustion in multipart form parsing in net/textproto and net/http", "issued": "2024-03-05T22:15:00Z", "links": "https://go.dev/issue/65383 https://go.dev/cl/569341 https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg https://osv.dev/vulnerability/BIT-golang-2023-45290 https://osv.dev/vulnerability/CVE-2023-45290", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.21.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jKke6Txz52GXq3xidnEMgg==": { "id": "jKke6Txz52GXq3xidnEMgg==", "updater": "rhel-vex", "name": "CVE-2026-8924", "description": "A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity.", "issued": "2026-07-03T06:15:04Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8924 https://bugzilla.redhat.com/show_bug.cgi?id=2496765 https://www.cve.org/CVERecord?id=CVE-2026-8924 https://nvd.nist.gov/vuln/detail/CVE-2026-8924 https://curl.se/docs/CVE-2026-8924.html https://curl.se/docs/CVE-2026-8924.json https://hackerone.com/reports/3733905 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8924.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jO9fUvpFi0R9/mJ1YH7KXA==": { "id": "jO9fUvpFi0R9/mJ1YH7KXA==", "updater": "rhel-vex", "name": "CVE-2026-59847", "description": "A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.", "issued": "2026-07-21T13:02:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59847 https://bugzilla.redhat.com/show_bug.cgi?id=2498180 https://www.cve.org/CVERecord?id=CVE-2026-59847 https://nvd.nist.gov/vuln/detail/CVE-2026-59847 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59847.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jRUkZ6iXWKQuY8AdCpy0kw==": { "id": "jRUkZ6iXWKQuY8AdCpy0kw==", "updater": "rhel-vex", "name": "CVE-2024-33601", "description": "A flaw was found in the glibc netgroup cache. The netgroup cache uses xmalloc/xrealloc and may terminate the process due to a memory allocation failure.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33601 https://bugzilla.redhat.com/show_bug.cgi?id=2277205 https://www.cve.org/CVERecord?id=CVE-2024-33601 https://nvd.nist.gov/vuln/detail/CVE-2024-33601 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33601.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jT+SdCGpoEoaiFxD0YzhlA==": { "id": "jT+SdCGpoEoaiFxD0YzhlA==", "updater": "rhel-vex", "name": "CVE-2023-7104", "description": "A vulnerability has been identified in SQLite3. This issue affects the sessionReadRecord function of the ext/session/sqlite3session.c function in the make alltest Handler component. Manipulation may cause a heap-based buffer overflow to occur.", "issued": "2023-12-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-7104 https://bugzilla.redhat.com/show_bug.cgi?id=2256194 https://www.cve.org/CVERecord?id=CVE-2023-7104 https://nvd.nist.gov/vuln/detail/CVE-2023-7104 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-7104.json https://access.redhat.com/errata/RHSA-2024:0253", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "sqlite-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.26.0-19.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jh7m9hFQE/K2fRaz3f3VoQ==": { "id": "jh7m9hFQE/K2fRaz3f3VoQ==", "updater": "osv/go", "name": "GO-2026-4971", "description": "Panic in Dial and LookupPort when handling NUL byte on Windows in net", "issued": "2026-05-07T19:21:40Z", "links": "https://go.dev/issue/79006 https://groups.google.com/g/golang-announce/c/qcCIEXso47M https://go.dev/cl/775320 https://osv.dev/vulnerability/BIT-golang-2026-39836 https://osv.dev/vulnerability/CVE-2026-39836", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jw1ZiDut5Ot+DyVFjCrixg==": { "id": "jw1ZiDut5Ot+DyVFjCrixg==", "updater": "rhel-vex", "name": "CVE-2020-19188", "description": "A flaw was found in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a stack-based buffer overflow, resulting in an application crash, leading to a denial of service.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19188 https://bugzilla.redhat.com/show_bug.cgi?id=2234913 https://www.cve.org/CVERecord?id=CVE-2020-19188 https://nvd.nist.gov/vuln/detail/CVE-2020-19188 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19188.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "k3o+5yuHivArIfBtIXx02Q==": { "id": "k3o+5yuHivArIfBtIXx02Q==", "updater": "rhel-vex", "name": "CVE-2026-5958", "description": "A Time-of-Check Time-of-Use (TOCTOU) race condition was found in GNU sed. When the -i (in-place) and --follow-symlinks options are used together, sed resolves the symlink but reopens the path for writing. An attacker with write access to the directory containing the symlink can swap it between the check and the open operations. If a privileged user executes sed in this manner on a path influenced by the attacker, it can lead to arbitrary file overwrites and potential privilege escalation.", "issued": "2026-04-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5958 https://bugzilla.redhat.com/show_bug.cgi?id=2458960 https://www.cve.org/CVERecord?id=CVE-2026-5958 https://nvd.nist.gov/vuln/detail/CVE-2026-5958 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5958.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "sed", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "k8qh5HUHIEX/Inga/xEVgA==": { "id": "k8qh5HUHIEX/Inga/xEVgA==", "updater": "rhel-vex", "name": "CVE-2021-35938", "description": "A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "issued": "2021-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-35938 https://bugzilla.redhat.com/show_bug.cgi?id=1964114 https://www.cve.org/CVERecord?id=CVE-2021-35938 https://nvd.nist.gov/vuln/detail/CVE-2021-35938 https://rpm.org/wiki/Releases/4.18.0 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-35938.json https://access.redhat.com/errata/RHSA-2024:0647", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "rpm-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:4.14.3-28.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kKJCXd0zC8/mIMuSsDoNSw==": { "id": "kKJCXd0zC8/mIMuSsDoNSw==", "updater": "rhel-vex", "name": "CVE-2023-27535", "description": "A flaw was found in the Curl package. Libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, several FTP settings were left out from the configuration match checks, making them match too easily. The problematic settings are `CURLOPT_FTP_ACCOUNT`, `CURLOPT_FTP_ALTERNATIVE_TO_USER`, `CURLOPT_FTP_SSL_CCC` and `CURLOPT_USE_SSL` level.", "issued": "2023-03-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-27535 https://bugzilla.redhat.com/show_bug.cgi?id=2179073 https://www.cve.org/CVERecord?id=CVE-2023-27535 https://nvd.nist.gov/vuln/detail/CVE-2023-27535 https://curl.se/docs/CVE-2023-27535.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27535.json https://access.redhat.com/errata/RHSA-2023:3106", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-30.el8_8.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kXAUkPZpve1iwCUaBskqEg==": { "id": "kXAUkPZpve1iwCUaBskqEg==", "updater": "rhel-vex", "name": "CVE-2025-4802", "description": "A flaw was found in the glibc library. A statically linked setuid binary that calls dlopen(), including internal dlopen() calls after setlocale() or calls to NSS functions such as getaddrinfo(), may incorrectly search LD_LIBRARY_PATH to determine which library to load, allowing a local attacker to load malicious shared libraries, escalate privileges and execute arbitrary code.", "issued": "2025-05-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-4802 https://bugzilla.redhat.com/show_bug.cgi?id=2367468 https://www.cve.org/CVERecord?id=CVE-2025-4802 https://nvd.nist.gov/vuln/detail/CVE-2025-4802 https://inbox.sourceware.org/libc-announce/3ac997b0-28a5-4129-af53-675efe4c2dec@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=32976 https://www.openwall.com/lists/oss-security/2025/05/16/7 https://www.openwall.com/lists/oss-security/2025/05/17/2 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4802.json https://access.redhat.com/errata/RHSA-2025:8686", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.22", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kZwQRex+JNO11iMZ0Kg+IQ==": { "id": "kZwQRex+JNO11iMZ0Kg+IQ==", "updater": "rhel-vex", "name": "CVE-2022-2068", "description": "A flaw was found in OpenSSL. The issue in CVE-2022-1292 did not find other places in the `c_rehash` script where it possibly passed the file names of certificates being hashed to a command executed through the shell. Some operating systems distribute this script in a manner where it is automatically executed. On these operating systems, this flaw allows an attacker to execute arbitrary commands with the privileges of the script.", "issued": "2022-06-21T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-2068 https://bugzilla.redhat.com/show_bug.cgi?id=2097310 https://www.cve.org/CVERecord?id=CVE-2022-2068 https://nvd.nist.gov/vuln/detail/CVE-2022-2068 https://www.openssl.org/news/secadv/20220621.txt https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2068.json https://access.redhat.com/errata/RHSA-2022:5818", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-7.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kiHW82C3wKDYOBbnq/LPIw==": { "id": "kiHW82C3wKDYOBbnq/LPIw==", "updater": "rhel-vex", "name": "CVE-2023-2603", "description": "A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.", "issued": "2023-05-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-2603 https://bugzilla.redhat.com/show_bug.cgi?id=2209113 https://www.cve.org/CVERecord?id=CVE-2023-2603 https://nvd.nist.gov/vuln/detail/CVE-2023-2603 https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-2603.json https://access.redhat.com/errata/RHSA-2023:4524", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libcap", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.48-5.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kkf66xuZDAfA1HsGQnywJQ==": { "id": "kkf66xuZDAfA1HsGQnywJQ==", "updater": "rhel-vex", "name": "CVE-2026-6238", "description": "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.", "issued": "2026-04-28T16:43:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42733", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.40", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kl+nHl+uiNLzyLIPmJZ+2A==": { "id": "kl+nHl+uiNLzyLIPmJZ+2A==", "updater": "rhel-vex", "name": "CVE-2023-29491", "description": "A vulnerability was found in ncurses and occurs when used by a setuid application. This flaw allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.", "issued": "2023-04-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-29491 https://bugzilla.redhat.com/show_bug.cgi?id=2191704 https://www.cve.org/CVERecord?id=CVE-2023-29491 https://nvd.nist.gov/vuln/detail/CVE-2023-29491 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-29491.json https://access.redhat.com/errata/RHSA-2023:5249", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "ncurses-base", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:6.1-9.20180224.el8_8.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "klCkJxhhNVG564GOUQMh+Q==": { "id": "klCkJxhhNVG564GOUQMh+Q==", "updater": "rhel-vex", "name": "CVE-2026-5745", "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5745 https://bugzilla.redhat.com/show_bug.cgi?id=2455921 https://www.cve.org/CVERecord?id=CVE-2026-5745 https://nvd.nist.gov/vuln/detail/CVE-2026-5745 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5745.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "klDSadzoRr4q59QuvFGaTA==": { "id": "klDSadzoRr4q59QuvFGaTA==", "updater": "rhel-vex", "name": "CVE-2022-22576", "description": "A vulnerability was found in curl. This security flaw allows reusing OAUTH2-authenticated connections without properly ensuring that the connection was authenticated with the same credentials set for this transfer. This issue leads to an authentication bypass, either by mistake or by a malicious actor.", "issued": "2022-04-27T06:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-22576 https://bugzilla.redhat.com/show_bug.cgi?id=2077541 https://www.cve.org/CVERecord?id=CVE-2022-22576 https://nvd.nist.gov/vuln/detail/CVE-2022-22576 https://curl.se/docs/CVE-2022-22576.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-22576.json https://access.redhat.com/errata/RHSA-2022:5313", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "koSTqHLTqKovq9PuCx4+LQ==": { "id": "koSTqHLTqKovq9PuCx4+LQ==", "updater": "osv/go", "name": "GO-2026-4947", "description": "Unexpected work during chain building in crypto/x509", "issued": "2026-04-07T22:53:49Z", "links": "https://go.dev/cl/758320 https://go.dev/issue/78282 https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU https://osv.dev/vulnerability/BIT-golang-2026-32280 https://osv.dev/vulnerability/CVE-2026-32280", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kp1TXQCpIxEQ9QttfHMWZg==": { "id": "kp1TXQCpIxEQ9QttfHMWZg==", "updater": "rhel-vex", "name": "CVE-2025-14104", "description": "A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.", "issued": "2025-12-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1852", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libsmartcols", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.32.1-48.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "l8OX/JvX/6Phr3whXXIPdg==": { "id": "l8OX/JvX/6Phr3whXXIPdg==", "updater": "rhel-vex", "name": "CVE-2022-27776", "description": "A vulnerability was found in curl. This security flaw allows leak authentication or cookie header data on HTTP redirects to the same host but another port number. Sending the same set of headers to a server on a different port number is a problem for applications that pass on custom `Authorization:` or `Cookie:`headers. Those headers often contain privacy-sensitive information or data.", "issued": "2022-04-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-27776 https://bugzilla.redhat.com/show_bug.cgi?id=2078408 https://www.cve.org/CVERecord?id=CVE-2022-27776 https://nvd.nist.gov/vuln/detail/CVE-2022-27776 https://curl.se/docs/CVE-2022-27776.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-27776.json https://access.redhat.com/errata/RHSA-2022:5313", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "l9dHBEfcpD6dMVlWOwL4HA==": { "id": "l9dHBEfcpD6dMVlWOwL4HA==", "updater": "rhel-vex", "name": "CVE-2024-0553", "description": "A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.", "issued": "2024-01-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-0553 https://bugzilla.redhat.com/show_bug.cgi?id=2258412 https://www.cve.org/CVERecord?id=CVE-2024-0553 https://nvd.nist.gov/vuln/detail/CVE-2024-0553 https://gitlab.com/gnutls/gnutls/-/issues/1522 https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0553.json https://access.redhat.com/errata/RHSA-2024:0627", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_9.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lek/1FI0HdClJgWDNVsHsw==": { "id": "lek/1FI0HdClJgWDNVsHsw==", "updater": "osv/go", "name": "GO-2022-1143", "description": "Restricted file access on Windows in os and net/http", "issued": "2022-12-07T16:08:45Z", "links": "https://go.dev/issue/56694 https://go.dev/cl/455716 https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ https://osv.dev/vulnerability/BIT-golang-2022-41720 https://osv.dev/vulnerability/CVE-2022-41720", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.18.9", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lrvnALLPkIyVQziuSGQ9qQ==": { "id": "lrvnALLPkIyVQziuSGQ9qQ==", "updater": "rhel-vex", "name": "CVE-2026-6238", "description": "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.", "issued": "2026-04-28T16:43:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42733", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.40", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lyJMJpTk90SdK260W3kmpA==": { "id": "lyJMJpTk90SdK260W3kmpA==", "updater": "osv/go", "name": "GO-2026-5038", "description": "Quadratic complexity in WordDecoder.DecodeHeader in mime", "issued": "2026-06-02T21:39:47Z", "links": "https://go.dev/issue/79217 https://go.dev/cl/774481 https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw https://osv.dev/vulnerability/BIT-golang-2026-42504 https://osv.dev/vulnerability/CVE-2026-42504", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lyuzCm7wHQVS8pCLzKOsig==": { "id": "lyuzCm7wHQVS8pCLzKOsig==", "updater": "osv/go", "name": "GO-2023-1704", "description": "Excessive memory allocation in net/http and net/textproto", "issued": "2023-04-05T21:04:28Z", "links": "https://go.dev/issue/58975 https://go.dev/cl/481994 https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8 https://osv.dev/vulnerability/BIT-golang-2023-24534 https://osv.dev/vulnerability/CVE-2023-24534", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "m0IJGRf61cMaVU+GJnWBLg==": { "id": "m0IJGRf61cMaVU+GJnWBLg==", "updater": "osv/go", "name": "GO-2026-4337", "description": "Unexpected session resumption in crypto/tls", "issued": "2026-02-05T17:23:09Z", "links": "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk https://go.dev/cl/737700 https://go.dev/issue/77217 https://osv.dev/vulnerability/BIT-golang-2025-68121 https://osv.dev/vulnerability/CVE-2025-68121", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.13", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "m8lo1EAeizRLnboLT9DGmw==": { "id": "m8lo1EAeizRLnboLT9DGmw==", "updater": "osv/go", "name": "GO-2023-1878", "description": "Insufficient sanitization of Host header in net/http", "issued": "2023-07-11T19:19:08Z", "links": "https://go.dev/issue/60374 https://go.dev/cl/506996 https://groups.google.com/g/golang-announce/c/2q13H6LEEx0 https://osv.dev/vulnerability/BIT-golang-2023-29406 https://osv.dev/vulnerability/CVE-2023-29406", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mQtrNhzMQ9mAh/coURV/3g==": { "id": "mQtrNhzMQ9mAh/coURV/3g==", "updater": "rhel-vex", "name": "CVE-2026-40467", "description": "A flaw was found in gawk. A Use After Free vulnerability exists in the do_getline_redir() routine within the io.c program file. This vulnerability can be triggered by an attacker, potentially leading to a system crash and causing a Denial of Service (DoS).", "issued": "2026-07-13T12:07:52Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40467 https://bugzilla.redhat.com/show_bug.cgi?id=2499658 https://www.cve.org/CVERecord?id=CVE-2026-40467 https://nvd.nist.gov/vuln/detail/CVE-2026-40467 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40467.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mR4NMMASPMeRLF/0aGWMcQ==": { "id": "mR4NMMASPMeRLF/0aGWMcQ==", "updater": "osv/go", "name": "GO-2025-3420", "description": "Sensitive headers incorrectly sent after cross-domain redirect in net/http", "issued": "2025-01-28T00:47:30Z", "links": "https://go.dev/cl/643100 https://go.dev/issue/70530 https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ https://osv.dev/vulnerability/BIT-golang-2024-45336 https://osv.dev/vulnerability/CVE-2024-45336", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.22.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mS0YOFVdBeDRbPVhCEovGQ==": { "id": "mS0YOFVdBeDRbPVhCEovGQ==", "updater": "rhel-vex", "name": "CVE-2026-51298", "description": "A flaw was found in SQLite. A remote attacker could exploit a use-after-free vulnerability in the JSON extraction function. This occurs when the program attempts to access memory after it has been freed, specifically within the `JsonParse` object. Successful exploitation of this vulnerability can lead to a service crash and a denial of service (DoS) for affected systems.", "issued": "2026-07-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-51298 https://bugzilla.redhat.com/show_bug.cgi?id=2507556 https://www.cve.org/CVERecord?id=CVE-2026-51298 https://nvd.nist.gov/vuln/detail/CVE-2026-51298 https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51298 https://github.com/sqlite/sqlite/blob/master/src/json.c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-51298.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mVDdLszud8eQGKbdS4PWJA==": { "id": "mVDdLszud8eQGKbdS4PWJA==", "updater": "rhel-vex", "name": "CVE-2023-5678", "description": "A flaw was found in OpenSSL, which caused the generation or checking of long X9.42 DH keys or parameters to be much slower than expected. This issue could lead to a denial of service.", "issued": "2023-10-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-5678 https://bugzilla.redhat.com/show_bug.cgi?id=2248616 https://www.cve.org/CVERecord?id=CVE-2023-5678 https://nvd.nist.gov/vuln/detail/CVE-2023-5678 https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055 https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017 https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6 https://www.openssl.org/news/secadv/20231106.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-5678.json https://access.redhat.com/errata/RHSA-2023:7877", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-12.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mVZw6HfBeWMeBMbQ3QI3eQ==": { "id": "mVZw6HfBeWMeBMbQ3QI3eQ==", "updater": "rhel-vex", "name": "CVE-2026-6791", "description": "A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application.", "issued": "2026-08-10T18:41:25Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6791 https://bugzilla.redhat.com/show_bug.cgi?id=2513603 https://www.cve.org/CVERecord?id=CVE-2026-6791 https://nvd.nist.gov/vuln/detail/CVE-2026-6791 https://sourceware.org/bugzilla/show_bug.cgi?id=34091 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6791.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mouoWVvs12H8FynnB5qIsQ==": { "id": "mouoWVvs12H8FynnB5qIsQ==", "updater": "rhel-vex", "name": "CVE-2019-14250", "description": "This issue resides on libiberty code, a part of binutils, distributed with different versions of RH software. The vulnerability is triggered when the shstrndx (Section Header String Table Index) is zero in the ELF file. This specific condition leads to the integer overflow and subsequent buffer overflow.", "issued": "2019-08-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-14250 https://bugzilla.redhat.com/show_bug.cgi?id=1739490 https://www.cve.org/CVERecord?id=CVE-2019-14250 https://nvd.nist.gov/vuln/detail/CVE-2019-14250 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-14250.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gcc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mxiKo6Gct+15cqo3Q07Ufw==": { "id": "mxiKo6Gct+15cqo3Q07Ufw==", "updater": "rhel-vex", "name": "CVE-2024-33599", "description": "A stack-based buffer overflow flaw was found in the glibc netgroup cache. In certain conditions, its possible to trigger a stack-based buffer overflow condition that can lead to a denial of service and potentially other malicious actions that impact confidentiality and integrity.", "issued": "2024-04-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33599 https://bugzilla.redhat.com/show_bug.cgi?id=2277202 https://www.cve.org/CVERecord?id=CVE-2024-33599 https://nvd.nist.gov/vuln/detail/CVE-2024-33599 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33599.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "my/DHKGJeRxjSNNUPhqPsQ==": { "id": "my/DHKGJeRxjSNNUPhqPsQ==", "updater": "osv/go", "name": "GO-2023-1571", "description": "Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net", "issued": "2023-02-16T22:31:36Z", "links": "https://go.dev/issue/57855 https://go.dev/cl/468135 https://go.dev/cl/468295 https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E https://osv.dev/vulnerability/BIT-golang-2022-41723 https://osv.dev/vulnerability/CVE-2022-41723 https://osv.dev/vulnerability/GHSA-vvpx-j8f3-3w6h", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.6", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "n5updgcs+J/K/GkxnmDRXQ==": { "id": "n5updgcs+J/K/GkxnmDRXQ==", "updater": "rhel-vex", "name": "CVE-2025-9086", "description": "An out of bounds read flaw has been discovered in the curl project. Under specific conditions the path comparison logic makes curl read outside a heap buffer boundary. This bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.", "issued": "2025-09-12T05:10:03Z", "links": "https://access.redhat.com/security/cve/CVE-2025-9086 https://bugzilla.redhat.com/show_bug.cgi?id=2394750 https://www.cve.org/CVERecord?id=CVE-2025-9086 https://nvd.nist.gov/vuln/detail/CVE-2025-9086 https://curl.se/docs/CVE-2025-9086.html https://curl.se/docs/CVE-2025-9086.json https://github.com/curl/curl/commit/c6ae07c6a541e0e96d0040afb6 https://hackerone.com/reports/3294999 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9086.json https://access.redhat.com/errata/RHSA-2025:23383", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-34.el8_10.9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "n83jaRl/T6kiaoMyWtX8xw==": { "id": "n83jaRl/T6kiaoMyWtX8xw==", "updater": "rhel-vex", "name": "CVE-2021-24032", "description": "A flaw was found in zstd. While the final file mode is reflective of the input file, when compressing or uncompressing, the file can temporarily gain greater permissions than the input and potentially leading to security issues (especially if large files are being handled).", "issued": "2021-02-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-24032 https://bugzilla.redhat.com/show_bug.cgi?id=1928090 https://www.cve.org/CVERecord?id=CVE-2021-24032 https://nvd.nist.gov/vuln/detail/CVE-2021-24032 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-24032.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "zstd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nK6y/UHclqHxgr5WNtNo3Q==": { "id": "nK6y/UHclqHxgr5WNtNo3Q==", "updater": "osv/go", "name": "GO-2026-4603", "description": "URLs in meta content attribute actions are not escaped in html/template", "issued": "2026-03-06T21:03:42Z", "links": "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk https://go.dev/issue/77954 https://go.dev/cl/752081 https://osv.dev/vulnerability/BIT-golang-2026-27142 https://osv.dev/vulnerability/CVE-2026-27142", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nRvp514SVP42tlHBu46XSQ==": { "id": "nRvp514SVP42tlHBu46XSQ==", "updater": "rhel-vex", "name": "CVE-2026-0915", "description": "A flaw was found in glibc, the GNU C Library. When an application calls the `getnetbyaddr` or `getnetbyaddr_r` functions to resolve a network address, and the system's `nsswitch.conf` file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system.", "issued": "2026-01-15T22:08:41Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0915 https://bugzilla.redhat.com/show_bug.cgi?id=2430201 https://www.cve.org/CVERecord?id=CVE-2026-0915 https://nvd.nist.gov/vuln/detail/CVE-2026-0915 https://sourceware.org/bugzilla/show_bug.cgi?id=33802 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0915.json https://access.redhat.com/errata/RHSA-2026:4772", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.31", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nflhinhjU+osS1TwBk+DFA==": { "id": "nflhinhjU+osS1TwBk+DFA==", "updater": "rhel-vex", "name": "CVE-2026-5435", "description": "A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.", "issued": "2026-04-28T11:58:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42733", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.40", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ngbKDtxhn33NKWC2lhOQNQ==": { "id": "ngbKDtxhn33NKWC2lhOQNQ==", "updater": "rhel-vex", "name": "CVE-2026-1485", "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1485 https://bugzilla.redhat.com/show_bug.cgi?id=2433325 https://www.cve.org/CVERecord?id=CVE-2026-1485 https://nvd.nist.gov/vuln/detail/CVE-2026-1485 https://gitlab.gnome.org/GNOME/glib/-/issues/3871 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1485.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nhjv2yqEDuqmBmg1t/yG5g==": { "id": "nhjv2yqEDuqmBmg1t/yG5g==", "updater": "osv/go", "name": "GO-2023-1840", "description": "Unsafe behavior in setuid/setgid binaries in runtime", "issued": "2023-06-08T20:16:06Z", "links": "https://go.dev/issue/60272 https://go.dev/cl/501223 https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJ https://osv.dev/vulnerability/BIT-golang-2023-29403 https://osv.dev/vulnerability/CVE-2023-29403", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "noXaVqkCbpzn51NS8fKFEA==": { "id": "noXaVqkCbpzn51NS8fKFEA==", "updater": "rhel-vex", "name": "CVE-2026-7168", "description": "A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user.", "issued": "2026-05-13T08:29:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-7168 https://bugzilla.redhat.com/show_bug.cgi?id=2476979 https://www.cve.org/CVERecord?id=CVE-2026-7168 https://nvd.nist.gov/vuln/detail/CVE-2026-7168 http://www.openwall.com/lists/oss-security/2026/04/29/14 https://curl.se/docs/CVE-2026-7168.html https://curl.se/docs/CVE-2026-7168.json https://hackerone.com/reports/3697719 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7168.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "noylE2HydWlbvhrfwI8wdQ==": { "id": "noylE2HydWlbvhrfwI8wdQ==", "updater": "rhel-vex", "name": "CVE-2023-1667", "description": "A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.", "issued": "2023-04-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-1667 https://bugzilla.redhat.com/show_bug.cgi?id=2182199 https://www.cve.org/CVERecord?id=CVE-2023-1667 https://nvd.nist.gov/vuln/detail/CVE-2023-1667 http://www.libssh.org/security/advisories/CVE-2023-1667.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1667.json https://access.redhat.com/errata/RHSA-2023:3839", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-10.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "npBrFSWnZYxq9cizdfDfCQ==": { "id": "npBrFSWnZYxq9cizdfDfCQ==", "updater": "rhel-vex", "name": "CVE-2026-1489", "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1489 https://bugzilla.redhat.com/show_bug.cgi?id=2433348 https://www.cve.org/CVERecord?id=CVE-2026-1489 https://nvd.nist.gov/vuln/detail/CVE-2026-1489 https://gitlab.gnome.org/GNOME/glib/-/issues/3872 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1489.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "npQpPXYG8xMJ1LRSVSnKGA==": { "id": "npQpPXYG8xMJ1LRSVSnKGA==", "updater": "rhel-vex", "name": "CVE-2025-8114", "description": "A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.", "issued": "2025-07-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-8114 https://bugzilla.redhat.com/show_bug.cgi?id=2383220 https://www.cve.org/CVERecord?id=CVE-2025-8114 https://nvd.nist.gov/vuln/detail/CVE-2025-8114 https://git.libssh.org/projects/libssh.git/commit/?id=53ac23ded4cb2c5463f6c4cd1525331bd578812d https://git.libssh.org/projects/libssh.git/commit/?id=65f363c9 https://www.libssh.org/security/advisories/CVE-2025-8114.txt https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-8114.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nrNkqQpKDeKvEoEVMtGvmQ==": { "id": "nrNkqQpKDeKvEoEVMtGvmQ==", "updater": "rhel-vex", "name": "CVE-2022-35252", "description": "A vulnerability found in curl. This security flaw happens when curl is used to retrieve and parse cookies from an HTTP(S) server, where it accepts cookies using control codes (byte values below 32), and also when cookies that contain such control codes are later sent back to an HTTP(S) server, possibly causing the server to return a 400 response. This issue effectively allows a \"sister site\" to deny service to siblings and cause a denial of service attack.", "issued": "2022-08-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-35252 https://bugzilla.redhat.com/show_bug.cgi?id=2120718 https://www.cve.org/CVERecord?id=CVE-2022-35252 https://nvd.nist.gov/vuln/detail/CVE-2022-35252 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-35252.json https://access.redhat.com/errata/RHSA-2023:2963", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-30.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nuZSEkRSJLkLrfITtMWhJA==": { "id": "nuZSEkRSJLkLrfITtMWhJA==", "updater": "osv/go", "name": "GO-2026-4970", "description": "Root escape via symlink plus trailing slash in os", "issued": "2026-07-07T21:34:47Z", "links": "https://go.dev/issue/79005 https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc https://go.dev/cl/797880 https://osv.dev/vulnerability/BIT-golang-2026-39822 https://osv.dev/vulnerability/CVE-2026-39822", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "o8knMpkoquoumaFb+1FM4A==": { "id": "o8knMpkoquoumaFb+1FM4A==", "updater": "rhel-vex", "name": "CVE-2026-58055", "description": "A flaw in nghttp2's nghttpx proxy allows a remote attacker to perform HTTP request smuggling and cross-client response-queue poisoning. This occurs because the proxy ambiguously forwards HTTP/1.1 Upgrade requests that contain a Content-Length header to reusable keep-alive backend connections.", "issued": "2026-06-28T01:32:57Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58055 https://bugzilla.redhat.com/show_bug.cgi?id=2493954 https://www.cve.org/CVERecord?id=CVE-2026-58055 https://nvd.nist.gov/vuln/detail/CVE-2026-58055 https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58055.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nghttp2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oW1RQqehkPmMzMEQAvBytA==": { "id": "oW1RQqehkPmMzMEQAvBytA==", "updater": "rhel-vex", "name": "CVE-2023-4911", "description": "A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.", "issued": "2023-10-03T17:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4911 https://bugzilla.redhat.com/show_bug.cgi?id=2238352 https://www.cve.org/CVERecord?id=CVE-2023-4911 https://nvd.nist.gov/vuln/detail/CVE-2023-4911 https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt https://www.qualys.com/cve-2023-4911/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4911.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oWl6C8goK/FnQDlax8YX9Q==": { "id": "oWl6C8goK/FnQDlax8YX9Q==", "updater": "rhel-vex", "name": "CVE-2026-42771", "description": "A flaw was found in OpenSSL. When an application uses the X509_VERIFY_PARAM_set1_email() function to validate a specially crafted S/MIME (Secure/Multipurpose Internet Mail Extensions) email address, an out-of-bounds read can occur. A remote attacker could exploit this vulnerability by sending a malicious email, leading to an application crash and a Denial of Service (DoS). This issue does not directly expose sensitive data.", "issued": "2026-07-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42771 https://bugzilla.redhat.com/show_bug.cgi?id=2481895 https://www.cve.org/CVERecord?id=CVE-2026-42771 https://nvd.nist.gov/vuln/detail/CVE-2026-42771 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42771.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "obihmRb48WNZ5GURvZjzJQ==": { "id": "obihmRb48WNZ5GURvZjzJQ==", "updater": "rhel-vex", "name": "CVE-2026-0915", "description": "A flaw was found in glibc, the GNU C Library. When an application calls the `getnetbyaddr` or `getnetbyaddr_r` functions to resolve a network address, and the system's `nsswitch.conf` file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system.", "issued": "2026-01-15T22:08:41Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0915 https://bugzilla.redhat.com/show_bug.cgi?id=2430201 https://www.cve.org/CVERecord?id=CVE-2026-0915 https://nvd.nist.gov/vuln/detail/CVE-2026-0915 https://sourceware.org/bugzilla/show_bug.cgi?id=33802 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0915.json https://access.redhat.com/errata/RHSA-2026:4772", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.31", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ofnnqzvHUpmPXQD17CK0Og==": { "id": "ofnnqzvHUpmPXQD17CK0Og==", "updater": "rhel-vex", "name": "CVE-2018-19211", "description": "A vulnerability was found in GNU ncurses due to a NULL pointer dereference in the _nc_parse_entry function within parse_entry.c, where an attacker could exploit this flaw by persuading a victim to open a specially crafted file, leading to a crash and causing a denial of service condition.", "issued": "2018-10-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-19211 https://bugzilla.redhat.com/show_bug.cgi?id=1652600 https://www.cve.org/CVERecord?id=CVE-2018-19211 https://nvd.nist.gov/vuln/detail/CVE-2018-19211 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-19211.json", "severity": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ogQLwI4CKSGkUta+rUUomw==": { "id": "ogQLwI4CKSGkUta+rUUomw==", "updater": "rhel-vex", "name": "CVE-2024-0553", "description": "A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.", "issued": "2024-01-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-0553 https://bugzilla.redhat.com/show_bug.cgi?id=2258412 https://www.cve.org/CVERecord?id=CVE-2024-0553 https://nvd.nist.gov/vuln/detail/CVE-2024-0553 https://gitlab.com/gnutls/gnutls/-/issues/1522 https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0553.json https://access.redhat.com/errata/RHSA-2024:0627", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_9.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ok6DL7Sb+nmxetWVktjVwg==": { "id": "ok6DL7Sb+nmxetWVktjVwg==", "updater": "osv/go", "name": "GO-2024-2888", "description": "Mishandling of corrupt central directory record in archive/zip", "issued": "2024-06-04T22:48:55Z", "links": "https://go.dev/cl/585397 https://go.dev/issue/66869 https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ https://osv.dev/vulnerability/BIT-golang-2024-24789 https://osv.dev/vulnerability/CVE-2024-24789", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.21.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ol0claZIIaI4jDf0WjYhhw==": { "id": "ol0claZIIaI4jDf0WjYhhw==", "updater": "rhel-vex", "name": "CVE-2025-14512", "description": "A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.", "issued": "2025-12-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14512 https://bugzilla.redhat.com/show_bug.cgi?id=2421339 https://www.cve.org/CVERecord?id=CVE-2025-14512 https://nvd.nist.gov/vuln/detail/CVE-2025-14512 https://gitlab.gnome.org/GNOME/glib/-/issues/3845 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14512.json https://access.redhat.com/errata/RHSA-2026:15953", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.56.4-169.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pNyd3CZwI+UE1lrar0+Tbg==": { "id": "pNyd3CZwI+UE1lrar0+Tbg==", "updater": "rhel-vex", "name": "CVE-2022-3515", "description": "A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.", "issued": "2022-10-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-3515 https://bugzilla.redhat.com/show_bug.cgi?id=2135610 https://www.cve.org/CVERecord?id=CVE-2022-3515 https://nvd.nist.gov/vuln/detail/CVE-2022-3515 https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3515.json https://access.redhat.com/errata/RHSA-2022:7089", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "High", "package": { "id": "", "name": "libksba", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.3.5-8.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pOPPyR+CIc4lpQu0LrmDeA==": { "id": "pOPPyR+CIc4lpQu0LrmDeA==", "updater": "rhel-vex", "name": "CVE-2023-4911", "description": "A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.", "issued": "2023-10-03T17:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4911 https://bugzilla.redhat.com/show_bug.cgi?id=2238352 https://www.cve.org/CVERecord?id=CVE-2023-4911 https://nvd.nist.gov/vuln/detail/CVE-2023-4911 https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt https://www.qualys.com/cve-2023-4911/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4911.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pPCCDOxXrmtalloMkX+jAw==": { "id": "pPCCDOxXrmtalloMkX+jAw==", "updater": "osv/go", "name": "GO-2024-3107", "description": "Stack exhaustion in Parse in go/build/constraint", "issued": "2024-09-06T19:15:23Z", "links": "https://go.dev/cl/611240 https://go.dev/issue/69141 https://groups.google.com/g/golang-dev/c/S9POB9NCTdk https://osv.dev/vulnerability/BIT-golang-2024-34158 https://osv.dev/vulnerability/CVE-2024-34158", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.22.7", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pjhL5VIkXQnq+rpcwS7JRg==": { "id": "pjhL5VIkXQnq+rpcwS7JRg==", "updater": "rhel-vex", "name": "CVE-2023-44487", "description": "A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit.\r\n\r\nCVE-2023-39325 was assigned for the Rapid Reset Attack in the Go language packages.\r\n\r\nSecurity Bulletin\r\nhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003", "issued": "2023-10-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-44487 https://bugzilla.redhat.com/show_bug.cgi?id=2242803 https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 https://www.cve.org/CVERecord?id=CVE-2023-44487 https://nvd.nist.gov/vuln/detail/CVE-2023-44487 https://github.com/dotnet/announcements/issues/277 https://pkg.go.dev/vuln/GO-2023-2102 https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-44487.json https://access.redhat.com/errata/RHSA-2023:5837", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "libnghttp2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.33.0-5.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "q3ulWCbJWdmHCRfeXXzLMA==": { "id": "q3ulWCbJWdmHCRfeXXzLMA==", "updater": "rhel-vex", "name": "CVE-2026-4878", "description": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.", "issued": "2026-04-06T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4878 https://bugzilla.redhat.com/show_bug.cgi?id=2451615 https://www.cve.org/CVERecord?id=CVE-2026-4878 https://nvd.nist.gov/vuln/detail/CVE-2026-4878 https://bugzilla.redhat.com/show_bug.cgi?id=2447554 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4878.json https://access.redhat.com/errata/RHSA-2026:13285", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "libcap", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.48-6.el8_10.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qES6WE3Hn+2j01vEmBBKiQ==": { "id": "qES6WE3Hn+2j01vEmBBKiQ==", "updater": "rhel-vex", "name": "CVE-2021-46848", "description": "An out-of-bounds read flaw was found in Libtasn1 due to an ETYPE_OK off-by-one error in the asn1_encode_simple_der() function. This flaw allows a remote attacker to pass specially crafted data or invalid values to the application, triggering an off-by-one error, corrupting the memory, and possibly performing a denial of service (DoS) attack.", "issued": "2022-10-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-46848 https://bugzilla.redhat.com/show_bug.cgi?id=2140058 https://www.cve.org/CVERecord?id=CVE-2021-46848 https://nvd.nist.gov/vuln/detail/CVE-2021-46848 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-46848.json https://access.redhat.com/errata/RHSA-2023:0116", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libtasn1", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:4.13-4.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qNuYRcgtGClAU0g3zKI5Dg==": { "id": "qNuYRcgtGClAU0g3zKI5Dg==", "updater": "rhel-vex", "name": "CVE-2022-35737", "description": "An array-bounds overflow vulnerability was discovered in SQLite. The vulnerability occurs when handling an overly large input passed as a string argument to some of the C-language APIs provided by SQLite. This flaw allows a remote attacker to pass specially crafted large input to the application and perform a denial of service (DoS) attack.", "issued": "2022-07-22T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-35737 https://bugzilla.redhat.com/show_bug.cgi?id=2110291 https://www.cve.org/CVERecord?id=CVE-2022-35737 https://nvd.nist.gov/vuln/detail/CVE-2022-35737 https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/ https://www.sqlite.org/releaselog/3_39_2.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-35737.json https://access.redhat.com/errata/RHSA-2023:0110", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "sqlite-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.26.0-17.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qWRIUBMC7Yu6aXYW5EzOcQ==": { "id": "qWRIUBMC7Yu6aXYW5EzOcQ==", "updater": "rhel-vex", "name": "CVE-2024-25062", "description": "A use-after-free flaw was found in libxml2. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.", "issued": "2024-02-04T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-25062 https://bugzilla.redhat.com/show_bug.cgi?id=2262726 https://www.cve.org/CVERecord?id=CVE-2024-25062 https://nvd.nist.gov/vuln/detail/CVE-2024-25062 https://gitlab.gnome.org/GNOME/libxml2/-/issues/604 https://gitlab.gnome.org/GNOME/libxml2/-/tags https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-25062.json https://access.redhat.com/errata/RHSA-2024:3626", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-18.el8_10.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qXNASosSuCsudML1MqXPjw==": { "id": "qXNASosSuCsudML1MqXPjw==", "updater": "rhel-vex", "name": "CVE-2023-27534", "description": "A path traversal vulnerability exists in curl \u003c8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.", "issued": "2023-03-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-27534 https://bugzilla.redhat.com/show_bug.cgi?id=2179069 https://www.cve.org/CVERecord?id=CVE-2023-27534 https://nvd.nist.gov/vuln/detail/CVE-2023-27534 https://curl.se/docs/CVE-2023-27534.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27534.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qld8Wk8WGHJZFjcPP6Ptwg==": { "id": "qld8Wk8WGHJZFjcPP6Ptwg==", "updater": "rhel-vex", "name": "CVE-2026-40468", "description": "A flaw was found in gawk. An integer overflow vulnerability could allow a local attacker to cause memory exhaustion, leading to a denial of service. This flaw may also enable an attacker to corrupt gawk's internal memory, potentially leading to system instability.", "issued": "2026-07-13T12:07:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40468 https://bugzilla.redhat.com/show_bug.cgi?id=2499655 https://www.cve.org/CVERecord?id=CVE-2026-40468 https://nvd.nist.gov/vuln/detail/CVE-2026-40468 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40468.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qn7yHwg0TG0L9eYiAmbjIg==": { "id": "qn7yHwg0TG0L9eYiAmbjIg==", "updater": "rhel-vex", "name": "CVE-2022-49043", "description": "A flaw was found in libxml2 where improper handling of memory allocation failures in `libxml2` can lead to crashes, memory leaks, or inconsistent states. While an attacker cannot directly control allocation failures, they may trigger denial-of-service conditions under extreme system stress.", "issued": "2025-01-26T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-49043 https://bugzilla.redhat.com/show_bug.cgi?id=2342118 https://www.cve.org/CVERecord?id=CVE-2022-49043 https://nvd.nist.gov/vuln/detail/CVE-2022-49043 https://github.com/php/php-src/issues/17467 https://gitlab.gnome.org/GNOME/libxml2/-/commit/5a19e21605398cef6a8b1452477a8705cb41562b https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-49043.json https://access.redhat.com/errata/RHSA-2025:1517", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-18.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rEd6JdG2xx5NZ9bcsFRNpw==": { "id": "rEd6JdG2xx5NZ9bcsFRNpw==", "updater": "rhel-vex", "name": "CVE-2026-28388", "description": "A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-28388 https://bugzilla.redhat.com/show_bug.cgi?id=2451097 https://www.cve.org/CVERecord?id=CVE-2026-28388 https://nvd.nist.gov/vuln/detail/CVE-2026-28388 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28388.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rEg00U8+//igCt+0+QBUhA==": { "id": "rEg00U8+//igCt+0+QBUhA==", "updater": "rhel-vex", "name": "CVE-2023-50495", "description": "A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry().", "issued": "2023-12-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-50495 https://bugzilla.redhat.com/show_bug.cgi?id=2254244 https://www.cve.org/CVERecord?id=CVE-2023-50495 https://nvd.nist.gov/vuln/detail/CVE-2023-50495 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-50495.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rKaUBHYppDrz0hfvcwev7Q==": { "id": "rKaUBHYppDrz0hfvcwev7Q==", "updater": "rhel-vex", "name": "CVE-2024-3596", "description": "A vulnerability in the RADIUS (Remote Authentication Dial-In User Service) protocol allows attackers to forge authentication responses when the Message-Authenticator attribute is not enforced. This issue arises from a cryptographically insecure integrity check using MD5, enabling attackers to spoof UDP-based RADIUS response packets. This can result in unauthorized access by modifying an Access-Reject response to an Access-Accept response, thereby compromising the authentication process.", "issued": "2024-07-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-3596 https://bugzilla.redhat.com/show_bug.cgi?id=2263240 https://www.cve.org/CVERecord?id=CVE-2024-3596 https://nvd.nist.gov/vuln/detail/CVE-2024-3596 https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/ https://datatracker.ietf.org/doc/html/rfc2865 https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf https://w1.fi/security/2024-1/hostapd-and-radius-protocol-forgery-attacks.txt https://www.blastradius.fail/ https://www.kb.cert.org/vuls/id/456537 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-3596.json https://access.redhat.com/errata/RHSA-2024:8860", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-30.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rP7oa42+SZpvxen+n93BaQ==": { "id": "rP7oa42+SZpvxen+n93BaQ==", "updater": "rhel-vex", "name": "CVE-2026-58010", "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses \u003e instead of \u003e=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.", "issued": "2026-03-26T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58010 https://bugzilla.redhat.com/show_bug.cgi?id=2492243 https://www.cve.org/CVERecord?id=CVE-2026-58010 https://nvd.nist.gov/vuln/detail/CVE-2026-58010 https://gitlab.gnome.org/GNOME/glib/-/issues/3915 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58010.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rSMeftoxZCXzQYWbyBPriw==": { "id": "rSMeftoxZCXzQYWbyBPriw==", "updater": "rhel-vex", "name": "CVE-2026-42009", "description": "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42009 https://bugzilla.redhat.com/show_bug.cgi?id=2467279 https://www.cve.org/CVERecord?id=CVE-2026-42009 https://nvd.nist.gov/vuln/detail/CVE-2026-42009 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rShXs/LMffX1AYFunGEpaw==": { "id": "rShXs/LMffX1AYFunGEpaw==", "updater": "osv/go", "name": "GO-2023-1705", "description": "Excessive resource consumption in net/http, net/textproto and mime/multipart", "issued": "2023-04-05T21:04:39Z", "links": "https://go.dev/issue/59153 https://go.dev/cl/482076 https://go.dev/cl/482075 https://go.dev/cl/482077 https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8 https://osv.dev/vulnerability/BIT-golang-2023-24536 https://osv.dev/vulnerability/CVE-2023-24536", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rVgBV65FWtFg3jitEqotFA==": { "id": "rVgBV65FWtFg3jitEqotFA==", "updater": "rhel-vex", "name": "CVE-2024-0727", "description": "A flaw was found in OpenSSL. The optional ContentInfo fields can be set to null, even if the \"type\" is a valid value, which can lead to a null dereference error that may cause a denial of service.", "issued": "2024-01-22T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-0727 https://bugzilla.redhat.com/show_bug.cgi?id=2259944 https://www.cve.org/CVERecord?id=CVE-2024-0727 https://nvd.nist.gov/vuln/detail/CVE-2024-0727 https://github.com/openssl/openssl/pull/23362 https://www.openssl.org/news/secadv/20240125.txt https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0727.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rf7KrQE1JIHCxJHtGdy3MQ==": { "id": "rf7KrQE1JIHCxJHtGdy3MQ==", "updater": "rhel-vex", "name": "CVE-2023-26604", "description": "A vulnerability was found in the systemd package. The systemd package does not adequately block local privilege escalation for some sudo configurations, for example, plausible sudoers files, in which the \"systemctl status\" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This issue presents a substantial security risk when running systemctl from Sudo because less executes as root when the terminal size is too small to show the complete systemctl output.", "issued": "2023-03-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-26604 https://bugzilla.redhat.com/show_bug.cgi?id=2175611 https://www.cve.org/CVERecord?id=CVE-2023-26604 https://nvd.nist.gov/vuln/detail/CVE-2023-26604 https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/ https://github.com/systemd/systemd/issues/5666 https://medium.com/@zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-26604.json https://access.redhat.com/errata/RHSA-2023:3837", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:239-74.el8_8.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rkTtYvrd12uyxklXyGzF1A==": { "id": "rkTtYvrd12uyxklXyGzF1A==", "updater": "rhel-vex", "name": "CVE-2023-1667", "description": "A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.", "issued": "2023-04-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-1667 https://bugzilla.redhat.com/show_bug.cgi?id=2182199 https://www.cve.org/CVERecord?id=CVE-2023-1667 https://nvd.nist.gov/vuln/detail/CVE-2023-1667 http://www.libssh.org/security/advisories/CVE-2023-1667.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1667.json https://access.redhat.com/errata/RHSA-2023:3839", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh-config", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-10.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rqCeYOmXHyf6R8tJDRQf3A==": { "id": "rqCeYOmXHyf6R8tJDRQf3A==", "updater": "osv/go", "name": "GO-2026-4980", "description": "Escaper bypass leads to XSS in html/template", "issued": "2026-05-07T19:21:40Z", "links": "https://go.dev/issue/78981 https://go.dev/cl/771180 https://groups.google.com/g/golang-announce/c/qcCIEXso47M https://osv.dev/vulnerability/BIT-golang-2026-39826 https://osv.dev/vulnerability/CVE-2026-39826", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.10", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ruDQdx7OmIsgMCpioWbqOQ==": { "id": "ruDQdx7OmIsgMCpioWbqOQ==", "updater": "rhel-vex", "name": "CVE-2025-5351", "description": "A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.", "issued": "2025-06-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5351 https://bugzilla.redhat.com/show_bug.cgi?id=2369367 https://www.cve.org/CVERecord?id=CVE-2025-5351 https://nvd.nist.gov/vuln/detail/CVE-2025-5351 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5351.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "s3LI+/HXTUE2MugpF0a37g==": { "id": "s3LI+/HXTUE2MugpF0a37g==", "updater": "rhel-vex", "name": "CVE-2022-36227", "description": "A flaw was found in libarchive. A missing check of the return value of the calloc function can cause a NULL pointer dereference in an out-of-memory condition or when a memory allocation limit is reached, resulting in the program linked with libarchive to crash.", "issued": "2022-07-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-36227 https://bugzilla.redhat.com/show_bug.cgi?id=2144972 https://www.cve.org/CVERecord?id=CVE-2022-36227 https://nvd.nist.gov/vuln/detail/CVE-2022-36227 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-36227.json https://access.redhat.com/errata/RHSA-2023:3018", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.3.3-5.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sDJRRD4zdMjd9jt+SpEg1g==": { "id": "sDJRRD4zdMjd9jt+SpEg1g==", "updater": "osv/go", "name": "GO-2024-2610", "description": "Errors returned from JSON marshaling may break template escaping in html/template", "issued": "2024-03-05T22:15:40Z", "links": "https://go.dev/issue/65697 https://go.dev/cl/564196 https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg https://osv.dev/vulnerability/BIT-golang-2024-24785 https://osv.dev/vulnerability/CVE-2024-24785", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.21.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sGPMVAq85tNcvWM0LZLajg==": { "id": "sGPMVAq85tNcvWM0LZLajg==", "updater": "rhel-vex", "name": "CVE-2020-11023", "description": "A flaw was found in jQuery. HTML containing \\\u003coption\\\u003e elements from untrusted sources are passed, even after sanitizing, to one of jQuery's DOM manipulation methods, which may execute untrusted code. The highest threat from this vulnerability is to data confidentiality and integrity.", "issued": "2020-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-11023 https://bugzilla.redhat.com/show_bug.cgi?id=1850004 https://www.cve.org/CVERecord?id=CVE-2020-11023 https://nvd.nist.gov/vuln/detail/CVE-2020-11023 https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-11023.json https://access.redhat.com/errata/RHSA-2025:1301", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libstdc++", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:8.5.0-23.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sOvZn+pqO1JdbX1EL6XdGA==": { "id": "sOvZn+pqO1JdbX1EL6XdGA==", "updater": "rhel-vex", "name": "CVE-2025-14104", "description": "A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.", "issued": "2025-12-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1852", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libmount", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.32.1-48.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sRVcQFAdq4Ll42smqacaCw==": { "id": "sRVcQFAdq4Ll42smqacaCw==", "updater": "rhel-vex", "name": "CVE-2022-27943", "description": "A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service.", "issued": "2022-03-26T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-27943 https://bugzilla.redhat.com/show_bug.cgi?id=2071728 https://www.cve.org/CVERecord?id=CVE-2022-27943 https://nvd.nist.gov/vuln/detail/CVE-2022-27943 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-27943.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gcc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sThg2GGoKqa1RTJ5skEJTA==": { "id": "sThg2GGoKqa1RTJ5skEJTA==", "updater": "rhel-vex", "name": "CVE-2026-24883", "description": "A flaw was found in GnuPG. A remote attacker could provide a specially crafted long signature packet that, when processed, causes the application to crash. This vulnerability leads to a denial of service (DoS), making the GnuPG application unavailable to legitimate users.", "issued": "2026-01-27T18:43:18Z", "links": "https://access.redhat.com/security/cve/CVE-2026-24883 https://bugzilla.redhat.com/show_bug.cgi?id=2433463 https://www.cve.org/CVERecord?id=CVE-2026-24883 https://nvd.nist.gov/vuln/detail/CVE-2026-24883 https://dev.gnupg.org/T8049 https://www.openwall.com/lists/oss-security/2026/01/27/8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24883.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sp6iHe6p/KI1q1gzO+J2Sg==": { "id": "sp6iHe6p/KI1q1gzO+J2Sg==", "updater": "osv/go", "name": "GO-2025-3447", "description": "Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec", "issued": "2025-02-06T16:38:14Z", "links": "https://go.dev/cl/643735 https://go.dev/issue/71383 https://groups.google.com/g/golang-announce/c/xU1ZCHUZw3k https://osv.dev/vulnerability/BIT-golang-2025-22866 https://osv.dev/vulnerability/CVE-2025-22866", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.22.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "srdggAxrYxj8SIe8dBdTNA==": { "id": "srdggAxrYxj8SIe8dBdTNA==", "updater": "rhel-vex", "name": "CVE-2026-11979", "description": "A flaw was found in libxml2, specifically within the xmlcatalog utility when operating in shell mode. An attacker can exploit multiple stack-based buffer overflows by providing an excessively long input line. This leads to memory corruption, which may cause the application to crash or potentially allow the attacker to execute arbitrary code within the context of the xmlcatalog process.", "issued": "2026-06-29T13:21:42Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11979 https://bugzilla.redhat.com/show_bug.cgi?id=2494191 https://www.cve.org/CVERecord?id=CVE-2026-11979 https://nvd.nist.gov/vuln/detail/CVE-2026-11979 https://cert.pl/en/posts/2026/06/CVE-2026-11979 https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11979.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "svSEG/XaetbIWOhLQcy0Rw==": { "id": "svSEG/XaetbIWOhLQcy0Rw==", "updater": "rhel-vex", "name": "CVE-2023-28321", "description": "A flaw was found in the Curl package. An incorrect International Domain Name (IDN) wildcard match may lead to improper certificate validation.", "issued": "2023-05-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-28321 https://bugzilla.redhat.com/show_bug.cgi?id=2196786 https://www.cve.org/CVERecord?id=CVE-2023-28321 https://nvd.nist.gov/vuln/detail/CVE-2023-28321 https://curl.se/docs/CVE-2023-28321.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-28321.json https://access.redhat.com/errata/RHSA-2023:4523", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-30.el8_8.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "t3XJyztcU9aOXTMLI8NRmA==": { "id": "t3XJyztcU9aOXTMLI8NRmA==", "updater": "rhel-vex", "name": "CVE-2026-29111", "description": "A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).", "issued": "2026-03-23T21:03:56Z", "links": "https://access.redhat.com/security/cve/CVE-2026-29111 https://bugzilla.redhat.com/show_bug.cgi?id=2450505 https://www.cve.org/CVERecord?id=CVE-2026-29111 https://nvd.nist.gov/vuln/detail/CVE-2026-29111 https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6 https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8 https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29111.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "t4oe6DBPNf5Ikk93RfTdig==": { "id": "t4oe6DBPNf5Ikk93RfTdig==", "updater": "rhel-vex", "name": "CVE-2019-12904", "description": "[Disputed] A vulnerability has been identified in Libgcrypt due to a flaw in its C implementation of AES. This vulnerability enables a remote attacker to perform a flush-and-reload side-channel attack, potentially accessing sensitive information. The vulnerability arises from the availability of physical addresses to other processes, particularly on platforms lacking an assembly-language implementation.", "issued": "2019-07-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-12904 https://bugzilla.redhat.com/show_bug.cgi?id=1730320 https://www.cve.org/CVERecord?id=CVE-2019-12904 https://nvd.nist.gov/vuln/detail/CVE-2019-12904 https://dev.gnupg.org/T4541 https://lists.gnupg.org/pipermail/gcrypt-devel/2019-July/004760.html https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-12904.html https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-12904.json", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "t8NWvVlCIq8TSmV68diH3w==": { "id": "t8NWvVlCIq8TSmV68diH3w==", "updater": "rhel-vex", "name": "CVE-2023-1667", "description": "A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.", "issued": "2023-04-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-1667 https://bugzilla.redhat.com/show_bug.cgi?id=2182199 https://www.cve.org/CVERecord?id=CVE-2023-1667 https://nvd.nist.gov/vuln/detail/CVE-2023-1667 http://www.libssh.org/security/advisories/CVE-2023-1667.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1667.json https://access.redhat.com/errata/RHSA-2023:3839", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-10.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tGsvzSy2YAolN7IIXG6tpA==": { "id": "tGsvzSy2YAolN7IIXG6tpA==", "updater": "rhel-vex", "name": "CVE-2019-9936", "description": "A vulnerability was found in SQLite, where a heap-based buffer over-read occurs in the fts5HashEntrySort function within sqlite3.c, an attacker could exploit this vulnerability by running specially crafted queries, lead to an information leak.", "issued": "2019-03-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-9936 https://bugzilla.redhat.com/show_bug.cgi?id=1692365 https://www.cve.org/CVERecord?id=CVE-2019-9936 https://nvd.nist.gov/vuln/detail/CVE-2019-9936 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-9936.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tVlxIOZ6F6+EJvRQqpYx4Q==": { "id": "tVlxIOZ6F6+EJvRQqpYx4Q==", "updater": "osv/go", "name": "GO-2023-1703", "description": "Backticks not treated as string delimiters in html/template", "issued": "2023-04-05T21:05:27Z", "links": "https://go.dev/issue/59234 https://go.dev/cl/482079 https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8 https://osv.dev/vulnerability/BIT-golang-2023-24538 https://osv.dev/vulnerability/CVE-2023-24538", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.19.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tlWVK61iOpKPkvmeShS9AQ==": { "id": "tlWVK61iOpKPkvmeShS9AQ==", "updater": "rhel-vex", "name": "CVE-2025-69421", "description": "A flaw was found in OpenSSL. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by providing a specially crafted, malformed PKCS#12 file to an application that processes it. The flaw occurs due to a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function when handling the malformed file, leading to an application crash.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-69421 https://bugzilla.redhat.com/show_bug.cgi?id=2430387 https://www.cve.org/CVERecord?id=CVE-2025-69421 https://nvd.nist.gov/vuln/detail/CVE-2025-69421 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69421.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tnBbKyfWYMq7GMqd8UCfIw==": { "id": "tnBbKyfWYMq7GMqd8UCfIw==", "updater": "rhel-vex", "name": "CVE-2025-70873", "description": "A flaw was found in SQLite. This information disclosure vulnerability exists within the zipfile extension, specifically in the zipfileInflate function. A remote attacker could exploit this by providing a specially crafted ZIP file. Successful exploitation could lead to the disclosure of sensitive heap memory information.", "issued": "2026-03-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-70873 https://bugzilla.redhat.com/show_bug.cgi?id=2447086 https://www.cve.org/CVERecord?id=CVE-2025-70873 https://nvd.nist.gov/vuln/detail/CVE-2025-70873 https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054 https://sqlite.org/forum/forumpost/761eac3c82 https://sqlite.org/src/info/3d459f1fb1bd1b5e https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-70873.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "twdwvAIDqvKiZLoTbg48Eg==": { "id": "twdwvAIDqvKiZLoTbg48Eg==", "updater": "rhel-vex", "name": "CVE-2025-0395", "description": "A flaw was found in the GNU C Library (glibc). A buffer overflow condition via the `assert()` function may be triggered due to glibc not allocating enough space for the assertion failure message string and size information. In certain conditions, a local attacker can exploit this, potentially leading to an application crash or other undefined behavior.", "issued": "2025-01-22T13:11:30Z", "links": "https://access.redhat.com/security/cve/CVE-2025-0395 https://bugzilla.redhat.com/show_bug.cgi?id=2339460 https://www.cve.org/CVERecord?id=CVE-2025-0395 https://nvd.nist.gov/vuln/detail/CVE-2025-0395 https://sourceware.org/bugzilla/show_bug.cgi?id=32582 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-0395.json https://access.redhat.com/errata/RHSA-2025:3828", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.16", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uEggs7thHCRp4eZu5EDH0A==": { "id": "uEggs7thHCRp4eZu5EDH0A==", "updater": "rhel-vex", "name": "CVE-2026-27171", "description": "A flaw was found in zlib. An attacker providing specially crafted input to the `crc32_combine64` or `crc32_combine_gen64` functions could trigger an infinite loop within the `x2nmodp` function. This leads to excessive CPU consumption, which can result in a Denial of Service (DoS) for the affected system.", "issued": "2026-02-18T02:36:19Z", "links": "https://access.redhat.com/security/cve/CVE-2026-27171 https://bugzilla.redhat.com/show_bug.cgi?id=2440530 https://www.cve.org/CVERecord?id=CVE-2026-27171 https://nvd.nist.gov/vuln/detail/CVE-2026-27171 https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/ https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf https://github.com/madler/zlib/issues/904 https://github.com/madler/zlib/releases/tag/v1.3.2 https://ostif.org/zlib-audit-complete/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27171.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "zlib", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uFU7coNmhuYnfXDMEDZ5Wg==": { "id": "uFU7coNmhuYnfXDMEDZ5Wg==", "updater": "osv/go", "name": "GO-2024-2887", "description": "Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip", "issued": "2024-06-04T22:48:55Z", "links": "https://go.dev/cl/590316 https://go.dev/issue/67680 https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ https://osv.dev/vulnerability/BIT-golang-2024-24790 https://osv.dev/vulnerability/CVE-2024-24790", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.21.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uPjRNrHM6KmwqqGnGCODOw==": { "id": "uPjRNrHM6KmwqqGnGCODOw==", "updater": "rhel-vex", "name": "CVE-2023-0361", "description": "A timing side-channel vulnerability was found in RSA ClientKeyExchange messages in GnuTLS. This side-channel may be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption, the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.", "issued": "2023-02-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-0361 https://bugzilla.redhat.com/show_bug.cgi?id=2162596 https://www.cve.org/CVERecord?id=CVE-2023-0361 https://nvd.nist.gov/vuln/detail/CVE-2023-0361 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0361.json https://access.redhat.com/errata/RHSA-2023:1569", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-6.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uf6hvc/hsJ/rGvizo8Merg==": { "id": "uf6hvc/hsJ/rGvizo8Merg==", "updater": "osv/go", "name": "GO-2026-6090", "description": "Limit handshake messages we are willing to accept post-handshake in crypto/tls", "issued": "2026-08-13T21:43:54Z", "links": "https://go.dev/issue/80528 https://go.dev/cl/804261 https://groups.google.com/g/golang-announce/c/94pEornpRlI https://osv.dev/vulnerability/CVE-2026-56862", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.13", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uov0ccZmWpY3SZTYmOkCCw==": { "id": "uov0ccZmWpY3SZTYmOkCCw==", "updater": "rhel-vex", "name": "CVE-2024-33600", "description": "A flaw was found in the glibc netgroup cache. After a failed cache insertion, addgetnetgrentX tries to send the non-existing response after the not-found header. This can lead to a null pointer dereference that causes a crash or exit.", "issued": "2024-04-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33600 https://bugzilla.redhat.com/show_bug.cgi?id=2277204 https://www.cve.org/CVERecord?id=CVE-2024-33600 https://nvd.nist.gov/vuln/detail/CVE-2024-33600 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33600.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "usSOeO0eis4fMxpUrYF1Og==": { "id": "usSOeO0eis4fMxpUrYF1Og==", "updater": "rhel-vex", "name": "CVE-2026-11856", "description": "A flaw was found in curl. When `libcurl` performs a transfer to an HTTP origin using Digest authentication and then reuses the same connection handle for a subsequent transfer to a different origin, it may incorrectly send the authentication header intended for the first origin to the second. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data.", "issued": "2026-07-03T06:13:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11856 https://bugzilla.redhat.com/show_bug.cgi?id=2496767 https://www.cve.org/CVERecord?id=CVE-2026-11856 https://nvd.nist.gov/vuln/detail/CVE-2026-11856 https://curl.se/docs/CVE-2026-11856.html https://curl.se/docs/CVE-2026-11856.json https://hackerone.com/reports/3793260 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11856.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "v+AawDOr4RSUljIzpyfKJg==": { "id": "v+AawDOr4RSUljIzpyfKJg==", "updater": "osv/go", "name": "GO-2022-1095", "description": "Unsanitized NUL in environment variables on Windows in syscall and os/exec", "issued": "2022-11-01T23:55:57Z", "links": "https://go.dev/issue/56284 https://go.dev/cl/446916 https://groups.google.com/g/golang-announce/c/mbHY1UY3BaM/m/hSpmRzk-AgAJ https://osv.dev/vulnerability/BIT-golang-2022-41716 https://osv.dev/vulnerability/CVE-2022-41716", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.18.8", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "v15shMI69zvuf6oTbTQYrA==": { "id": "v15shMI69zvuf6oTbTQYrA==", "updater": "rhel-vex", "name": "CVE-2025-5372", "description": "A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.", "issued": "2025-06-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5372 https://bugzilla.redhat.com/show_bug.cgi?id=2369388 https://www.cve.org/CVERecord?id=CVE-2025-5372 https://nvd.nist.gov/vuln/detail/CVE-2025-5372 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5372.json https://access.redhat.com/errata/RHSA-2025:21977", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-16.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "v1exQXePimNPt3tveLBP9g==": { "id": "v1exQXePimNPt3tveLBP9g==", "updater": "rhel-vex", "name": "CVE-2026-1965", "description": "A flaw was found in curl. When an application uses libcurl to make multiple Negotiate-authenticated HTTP or HTTPS requests to the same server with different credentials, libcurl may incorrectly reuse an existing connection. This logical error can cause a subsequent request to be sent using the authentication of a previous user, leading to an authentication bypass.", "issued": "2026-03-11T10:08:52Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1965 https://bugzilla.redhat.com/show_bug.cgi?id=2446448 https://www.cve.org/CVERecord?id=CVE-2026-1965 https://nvd.nist.gov/vuln/detail/CVE-2026-1965 https://curl.se/docs/CVE-2026-1965.html https://curl.se/docs/CVE-2026-1965.json https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1965.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "v78axfxSunBGHhES6GBw8Q==": { "id": "v78axfxSunBGHhES6GBw8Q==", "updater": "rhel-vex", "name": "CVE-2024-4741", "description": "A use-after-free vulnerability was found in OpenSSL. Calling the OpenSSL API SSL_free_buffers function may cause memory to be accessed that was previously freed in some situations.", "issued": "2024-05-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-4741 https://bugzilla.redhat.com/show_bug.cgi?id=2283757 https://www.cve.org/CVERecord?id=CVE-2024-4741 https://nvd.nist.gov/vuln/detail/CVE-2024-4741 https://www.openssl.org/news/secadv/20240528.txt https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-4741.json https://access.redhat.com/errata/RHSA-2026:26275", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-16.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "v7w6RCU36McEvGLyy4Z/qA==": { "id": "v7w6RCU36McEvGLyy4Z/qA==", "updater": "rhel-vex", "name": "CVE-2016-3709", "description": "A Cross-site scripting (XSS) vulnerability was found in libxml2. A specially crafted input, when serialized and re-parsed by the libxml2 library, will result in a document with element attributes that did not exist in the original document.", "issued": "2016-08-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2016-3709 https://bugzilla.redhat.com/show_bug.cgi?id=2112766 https://www.cve.org/CVERecord?id=CVE-2016-3709 https://nvd.nist.gov/vuln/detail/CVE-2016-3709 https://security.access.redhat.com/data/csaf/v2/vex/2016/cve-2016-3709.json https://access.redhat.com/errata/RHSA-2022:7715", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-15.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vAbtgIwYiyXbMMuErZhftQ==": { "id": "vAbtgIwYiyXbMMuErZhftQ==", "updater": "rhel-vex", "name": "CVE-2025-0395", "description": "A flaw was found in the GNU C Library (glibc). A buffer overflow condition via the `assert()` function may be triggered due to glibc not allocating enough space for the assertion failure message string and size information. In certain conditions, a local attacker can exploit this, potentially leading to an application crash or other undefined behavior.", "issued": "2025-01-22T13:11:30Z", "links": "https://access.redhat.com/security/cve/CVE-2025-0395 https://bugzilla.redhat.com/show_bug.cgi?id=2339460 https://www.cve.org/CVERecord?id=CVE-2025-0395 https://nvd.nist.gov/vuln/detail/CVE-2025-0395 https://sourceware.org/bugzilla/show_bug.cgi?id=32582 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-0395.json https://access.redhat.com/errata/RHSA-2025:3828", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.16", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vJm7eeVZEbnxh/9fxMVxog==": { "id": "vJm7eeVZEbnxh/9fxMVxog==", "updater": "rhel-vex", "name": "CVE-2026-40355", "description": "A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit a NULL pointer dereference vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the termination of the process, resulting in a Denial of Service (DoS).", "issued": "2026-04-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40355 https://bugzilla.redhat.com/show_bug.cgi?id=2463370 https://www.cve.org/CVERecord?id=CVE-2026-40355 https://nvd.nist.gov/vuln/detail/CVE-2026-40355 https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f https://web.mit.edu/kerberos/advisories/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40355.json https://access.redhat.com/errata/RHSA-2026:16799", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-34.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vLyqX/wwXw895kwHvWCMWw==": { "id": "vLyqX/wwXw895kwHvWCMWw==", "updater": "rhel-vex", "name": "CVE-2023-4806", "description": "A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.", "issued": "2023-09-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4806 https://bugzilla.redhat.com/show_bug.cgi?id=2237782 https://www.cve.org/CVERecord?id=CVE-2023-4806 https://nvd.nist.gov/vuln/detail/CVE-2023-4806 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4806.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vTJZ/R8pdcyDbwAwRi8cBw==": { "id": "vTJZ/R8pdcyDbwAwRi8cBw==", "updater": "rhel-vex", "name": "CVE-2025-15079", "description": "A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15079 https://bugzilla.redhat.com/show_bug.cgi?id=2426409 https://www.cve.org/CVERecord?id=CVE-2025-15079 https://nvd.nist.gov/vuln/detail/CVE-2025-15079 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15079.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vamdoTfL2zH+m03imhf9RQ==": { "id": "vamdoTfL2zH+m03imhf9RQ==", "updater": "rhel-vex", "name": "CVE-2025-49796", "description": "A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.", "issued": "2025-06-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-49796 https://bugzilla.redhat.com/show_bug.cgi?id=2372385 https://www.cve.org/CVERecord?id=CVE-2025-49796 https://nvd.nist.gov/vuln/detail/CVE-2025-49796 https://gitlab.gnome.org/GNOME/libxml2/-/issues/933 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-49796.json https://access.redhat.com/errata/RHSA-2025:10698", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.7-21.el8_10.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "veYa/2wgH4+VvZYYHBCfPA==": { "id": "veYa/2wgH4+VvZYYHBCfPA==", "updater": "osv/go", "name": "GO-2026-5972", "description": "Enforce maximum recursion depth in encoding/asn1", "issued": "2026-08-13T21:43:54Z", "links": "https://go.dev/issue/80405 https://groups.google.com/g/golang-announce/c/94pEornpRlI https://go.dev/cl/814980 https://osv.dev/vulnerability/CVE-2026-33818", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.13", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vrmMgxCMgT/Bjrct252HXA==": { "id": "vrmMgxCMgT/Bjrct252HXA==", "updater": "rhel-vex", "name": "CVE-2023-29491", "description": "A vulnerability was found in ncurses and occurs when used by a setuid application. This flaw allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.", "issued": "2023-04-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-29491 https://bugzilla.redhat.com/show_bug.cgi?id=2191704 https://www.cve.org/CVERecord?id=CVE-2023-29491 https://nvd.nist.gov/vuln/detail/CVE-2023-29491 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-29491.json https://access.redhat.com/errata/RHSA-2023:5249", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "ncurses-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:6.1-9.20180224.el8_8.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wB7876bSzFTczOPU8wybVQ==": { "id": "wB7876bSzFTczOPU8wybVQ==", "updater": "rhel-vex", "name": "CVE-2024-33599", "description": "A stack-based buffer overflow flaw was found in the glibc netgroup cache. In certain conditions, its possible to trigger a stack-based buffer overflow condition that can lead to a denial of service and potentially other malicious actions that impact confidentiality and integrity.", "issued": "2024-04-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-33599 https://bugzilla.redhat.com/show_bug.cgi?id=2277202 https://www.cve.org/CVERecord?id=CVE-2024-33599 https://nvd.nist.gov/vuln/detail/CVE-2024-33599 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-33599.json https://access.redhat.com/errata/RHSA-2024:3344", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-251.el8_10.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wNoACM7I52HsdbnfoTfqkQ==": { "id": "wNoACM7I52HsdbnfoTfqkQ==", "updater": "rhel-vex", "name": "CVE-2023-4813", "description": "A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.", "issued": "2022-03-01T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4813 https://bugzilla.redhat.com/show_bug.cgi?id=2237798 https://www.cve.org/CVERecord?id=CVE-2023-4813 https://nvd.nist.gov/vuln/detail/CVE-2023-4813 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4813.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wNoWbGRqNSwxpxvQoLKucA==": { "id": "wNoWbGRqNSwxpxvQoLKucA==", "updater": "rhel-vex", "name": "CVE-2023-27535", "description": "A flaw was found in the Curl package. Libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, several FTP settings were left out from the configuration match checks, making them match too easily. The problematic settings are `CURLOPT_FTP_ACCOUNT`, `CURLOPT_FTP_ALTERNATIVE_TO_USER`, `CURLOPT_FTP_SSL_CCC` and `CURLOPT_USE_SSL` level.", "issued": "2023-03-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-27535 https://bugzilla.redhat.com/show_bug.cgi?id=2179073 https://www.cve.org/CVERecord?id=CVE-2023-27535 https://nvd.nist.gov/vuln/detail/CVE-2023-27535 https://curl.se/docs/CVE-2023-27535.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27535.json https://access.redhat.com/errata/RHSA-2023:3106", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-30.el8_8.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wUhCCQ2TKmxA3z3g0s2FPg==": { "id": "wUhCCQ2TKmxA3z3g0s2FPg==", "updater": "rhel-vex", "name": "CVE-2022-42898", "description": "A vulnerability was found in MIT krb5. This flaw allows an authenticated attacker to cause a KDC or kadmind process to crash by reading beyond the bounds of allocated memory, creating a denial of service. A privileged attacker may similarly be able to cause a Kerberos or GSS application service to crash.", "issued": "2022-11-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-42898 https://bugzilla.redhat.com/show_bug.cgi?id=2140960 https://www.cve.org/CVERecord?id=CVE-2022-42898 https://nvd.nist.gov/vuln/detail/CVE-2022-42898 https://mailman.mit.edu/pipermail/krbdev/2022-November/013576.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-42898.json https://access.redhat.com/errata/RHEA-2023:3850", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-25.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wbBiCPikq6Iz02EPsysTgA==": { "id": "wbBiCPikq6Iz02EPsysTgA==", "updater": "rhel-vex", "name": "CVE-2025-14017", "description": "A flaw was found in curl. When performing multi-threaded LDAPS (Lightweight Directory Access Protocol Secure) transfers, changes to Transport Layer Security (TLS) options in one thread could inadvertently apply globally, affecting other concurrent transfers. This could lead to unintended security posture changes, such as disabling certificate verification for other threads. This vulnerability can result in a security bypass, where expected security checks are not performed.", "issued": "2026-01-08T10:07:05Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14017 https://bugzilla.redhat.com/show_bug.cgi?id=2427870 https://www.cve.org/CVERecord?id=CVE-2025-14017 https://nvd.nist.gov/vuln/detail/CVE-2025-14017 https://curl.se/docs/CVE-2025-14017.html https://curl.se/docs/CVE-2025-14017.json https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14017.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wjNYcQ4jin5xLZ9x3M9snA==": { "id": "wjNYcQ4jin5xLZ9x3M9snA==", "updater": "rhel-vex", "name": "CVE-2022-32206", "description": "A vulnerability was found in curl. This issue occurs because the number of acceptable \"links\" in the \"decompression chain\" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps. This flaw leads to a denial of service, either by mistake or by a malicious actor.", "issued": "2022-06-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-32206 https://bugzilla.redhat.com/show_bug.cgi?id=2099300 https://www.cve.org/CVERecord?id=CVE-2022-32206 https://nvd.nist.gov/vuln/detail/CVE-2022-32206 https://curl.se/docs/CVE-2022-32206.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-32206.json https://access.redhat.com/errata/RHSA-2022:6159", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.4", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wxS+u/uf8o4sT9iSccXQwA==": { "id": "wxS+u/uf8o4sT9iSccXQwA==", "updater": "rhel-vex", "name": "CVE-2026-4426", "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.", "issued": "2026-03-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4426 https://bugzilla.redhat.com/show_bug.cgi?id=2449010 https://www.cve.org/CVERecord?id=CVE-2026-4426 https://nvd.nist.gov/vuln/detail/CVE-2026-4426 https://github.com/libarchive/libarchive/pull/2897 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4426.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wyr3miTYwjwE6qXtpMKFcA==": { "id": "wyr3miTYwjwE6qXtpMKFcA==", "updater": "osv/go", "name": "GO-2026-4341", "description": "Memory exhaustion in query parameter parsing in net/url", "issued": "2026-01-28T19:08:18Z", "links": "https://go.dev/cl/736712 https://go.dev/issue/77101 https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc https://osv.dev/vulnerability/BIT-golang-2025-61726 https://osv.dev/vulnerability/CVE-2025-61726", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.24.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "x3G/eMd1Z0D10r12N+9d3Q==": { "id": "x3G/eMd1Z0D10r12N+9d3Q==", "updater": "rhel-vex", "name": "CVE-2022-34903", "description": "A vulnerability was found in GnuPG. This issue occurs due to an escape detection loop at the write_status_text_and_buffer() function in g10/cpr.c. This flaw allows a malicious actor to bypass access control.", "issued": "2022-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-34903 https://bugzilla.redhat.com/show_bug.cgi?id=2102868 https://www.cve.org/CVERecord?id=CVE-2022-34903 https://nvd.nist.gov/vuln/detail/CVE-2022-34903 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-34903.json https://access.redhat.com/errata/RHSA-2022:6463", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.2.20-3.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "x6UCsSnHrxwMwN3+lSw6Jg==": { "id": "x6UCsSnHrxwMwN3+lSw6Jg==", "updater": "rhel-vex", "name": "CVE-2023-4527", "description": "A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.", "issued": "2023-09-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4527 https://bugzilla.redhat.com/show_bug.cgi?id=2234712 https://www.cve.org/CVERecord?id=CVE-2023-4527 https://nvd.nist.gov/vuln/detail/CVE-2023-4527 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4527.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xCUiEQAH1lfhrKtUxQDIYA==": { "id": "xCUiEQAH1lfhrKtUxQDIYA==", "updater": "rhel-vex", "name": "CVE-2021-39537", "description": "A heap overflow vulnerability has been identified in the ncurses package, particularly in the \"tic\". This flaw results from a lack of proper bounds checking during input processing. By exploiting this boundary error, an attacker can create a malicious file, deceive the victim into opening it using the affected software, and initiate an out-of-bounds write, potentially impacting system availability.", "issued": "2020-08-04T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-39537 https://bugzilla.redhat.com/show_bug.cgi?id=2006978 https://www.cve.org/CVERecord?id=CVE-2021-39537 https://nvd.nist.gov/vuln/detail/CVE-2021-39537 https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-39537.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xLEp4QWNtWRdArvsNX84PA==": { "id": "xLEp4QWNtWRdArvsNX84PA==", "updater": "osv/go", "name": "GO-2026-6089", "description": "Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http", "issued": "2026-08-13T21:43:54Z", "links": "https://go.dev/issue/80205 https://go.dev/cl/795540 https://groups.google.com/g/golang-announce/c/94pEornpRlI https://osv.dev/vulnerability/CVE-2026-56853", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.13", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xLIujTim86EomaRofe4tDg==": { "id": "xLIujTim86EomaRofe4tDg==", "updater": "rhel-vex", "name": "CVE-2023-32611", "description": "A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.", "issued": "2022-12-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-32611 https://bugzilla.redhat.com/show_bug.cgi?id=2211829 https://www.cve.org/CVERecord?id=CVE-2023-32611 https://nvd.nist.gov/vuln/detail/CVE-2023-32611 https://gitlab.gnome.org/GNOME/glib/-/issues/2797 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-32611.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xNexg9DpjcrTRov7qTIFQw==": { "id": "xNexg9DpjcrTRov7qTIFQw==", "updater": "osv/go", "name": "GO-2026-5037", "description": "Inefficient candidate hostname parsing in crypto/x509", "issued": "2026-06-02T21:39:47Z", "links": "https://go.dev/cl/783621 https://go.dev/issue/79694 https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw https://osv.dev/vulnerability/BIT-golang-2026-27145 https://osv.dev/vulnerability/CVE-2026-27145", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.25.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xPWheycLeO7kiluEueY2Ow==": { "id": "xPWheycLeO7kiluEueY2Ow==", "updater": "rhel-vex", "name": "CVE-2023-7104", "description": "A vulnerability has been identified in SQLite3. This issue affects the sessionReadRecord function of the ext/session/sqlite3session.c function in the make alltest Handler component. Manipulation may cause a heap-based buffer overflow to occur.", "issued": "2023-12-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-7104 https://bugzilla.redhat.com/show_bug.cgi?id=2256194 https://www.cve.org/CVERecord?id=CVE-2023-7104 https://nvd.nist.gov/vuln/detail/CVE-2023-7104 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-7104.json https://access.redhat.com/errata/RHSA-2024:0253", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "sqlite-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.26.0-19.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xQWaBVfKJo/zKQEAHLEeBg==": { "id": "xQWaBVfKJo/zKQEAHLEeBg==", "updater": "rhel-vex", "name": "CVE-2025-24528", "description": "A flaw was found in krb5. With incremental propagation enabled, an authenticated attacker can cause kadmind to write beyond the end of the mapped region for the iprop log file. This issue can trigger a process crash and lead to a denial of service.", "issued": "2024-01-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-24528 https://bugzilla.redhat.com/show_bug.cgi?id=2342796 https://www.cve.org/CVERecord?id=CVE-2025-24528 https://nvd.nist.gov/vuln/detail/CVE-2025-24528 https://github.com/krb5/krb5/commit/78ceba024b64d49612375be4a12d1c066b0bfbd0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24528.json https://access.redhat.com/errata/RHSA-2025:2722", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "krb5-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.18.2-31.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xjRJnKlNaH/FGi0NN5VKBQ==": { "id": "xjRJnKlNaH/FGi0NN5VKBQ==", "updater": "rhel-vex", "name": "CVE-2026-0992", "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated \u003cnextCatalog\u003e elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0992 https://bugzilla.redhat.com/show_bug.cgi?id=2429975 https://www.cve.org/CVERecord?id=CVE-2026-0992 https://nvd.nist.gov/vuln/detail/CVE-2026-0992 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0992.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xpe48bYc11r4l1Za0UMTJA==": { "id": "xpe48bYc11r4l1Za0UMTJA==", "updater": "rhel-vex", "name": "CVE-2023-4813", "description": "A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.", "issued": "2022-03-01T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4813 https://bugzilla.redhat.com/show_bug.cgi?id=2237798 https://www.cve.org/CVERecord?id=CVE-2023-4813 https://nvd.nist.gov/vuln/detail/CVE-2023-4813 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4813.json https://access.redhat.com/errata/RHSA-2023:5455", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.28-225.el8_8.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xyXxPp8aZoIrfhSdoDZiRw==": { "id": "xyXxPp8aZoIrfhSdoDZiRw==", "updater": "rhel-vex", "name": "CVE-2023-7008", "description": "A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.", "issued": "2022-12-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-7008 https://bugzilla.redhat.com/show_bug.cgi?id=2222672 https://www.cve.org/CVERecord?id=CVE-2023-7008 https://nvd.nist.gov/vuln/detail/CVE-2023-7008 https://bugzilla.redhat.com/show_bug.cgi?id=2222261 https://github.com/systemd/systemd/issues/25676 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-7008.json https://access.redhat.com/errata/RHSA-2024:3203", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:239-82.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yGCmffaimhyTCMJRNZflXg==": { "id": "yGCmffaimhyTCMJRNZflXg==", "updater": "rhel-vex", "name": "CVE-2026-5121", "description": "A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.", "issued": "2026-03-30T07:44:15Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5121 https://bugzilla.redhat.com/show_bug.cgi?id=2452945 https://www.cve.org/CVERecord?id=CVE-2026-5121 https://nvd.nist.gov/vuln/detail/CVE-2026-5121 https://github.com/advisories/GHSA-2vwv-vqpv-v8vc https://github.com/libarchive/libarchive/pull/2934 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5121.json https://access.redhat.com/errata/RHSA-2026:8534", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.3.3-7.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yQIFYkzYJzgmJ2Nsgj7X6g==": { "id": "yQIFYkzYJzgmJ2Nsgj7X6g==", "updater": "rhel-vex", "name": "CVE-2023-48795", "description": "A flaw was found in the SSH channel integrity. By manipulating sequence numbers during the handshake, an attacker can remove the initial messages on the secure channel without causing a MAC failure. For example, an attacker could disable the ping extension and thus disable the new countermeasure in OpenSSH 9.5 against keystroke timing attacks.", "issued": "2023-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-48795 https://bugzilla.redhat.com/show_bug.cgi?id=2254210 https://www.cve.org/CVERecord?id=CVE-2023-48795 https://nvd.nist.gov/vuln/detail/CVE-2023-48795 https://access.redhat.com/solutions/7071748 https://terrapin-attack.com/ https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-48795.json https://access.redhat.com/errata/RHSA-2024:0628", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-13.el8_9", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yReQJ7USlKwxPIyVvEKPEQ==": { "id": "yReQJ7USlKwxPIyVvEKPEQ==", "updater": "osv/go", "name": "GO-2022-1037", "description": "Unbounded memory consumption when reading headers in archive/tar", "issued": "2022-10-06T16:26:05Z", "links": "https://go.dev/issue/54853 https://go.dev/cl/439355 https://groups.google.com/g/golang-announce/c/xtuG5faxtaU https://osv.dev/vulnerability/BIT-golang-2022-2879 https://osv.dev/vulnerability/CVE-2022-2879", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.18.7", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yVMgAYQDeD0vSehEFrItQw==": { "id": "yVMgAYQDeD0vSehEFrItQw==", "updater": "osv/go", "name": "GO-2025-3373", "description": "Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509", "issued": "2025-01-28T00:47:30Z", "links": "https://go.dev/cl/643099 https://go.dev/issue/71156 https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ https://osv.dev/vulnerability/BIT-golang-2024-45341 https://osv.dev/vulnerability/CVE-2024-45341", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.22.11", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yfmRolXybbYkofU31txxnw==": { "id": "yfmRolXybbYkofU31txxnw==", "updater": "rhel-vex", "name": "CVE-2022-32208", "description": "A vulnerability was found in curl. This issue occurs because it mishandles message verification failures when curl does FTP transfers secured by krb5. This flaw makes it possible for a Man-in-the-middle attack to go unnoticed and allows data injection into the client.", "issued": "2022-06-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-32208 https://bugzilla.redhat.com/show_bug.cgi?id=2099306 https://www.cve.org/CVERecord?id=CVE-2022-32208 https://nvd.nist.gov/vuln/detail/CVE-2022-32208 https://curl.se/docs/CVE-2022-32208.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-32208.json https://access.redhat.com/errata/RHSA-2022:6159", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libcurl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.4", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yiTWIBfruE5rPxLBPqTezA==": { "id": "yiTWIBfruE5rPxLBPqTezA==", "updater": "rhel-vex", "name": "CVE-2018-1000880", "description": "A vulnerability was found in libarchive, where improper input validation in the _warc_read function in libarchive/archive_read_support_format_warc.c can lead to a denial of service, a remote attacker could exploit this flaw by persuading a victim to open a specially crafted file, causing the application to crash.", "issued": "2018-11-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-1000880 https://bugzilla.redhat.com/show_bug.cgi?id=1663892 https://www.cve.org/CVERecord?id=CVE-2018-1000880 https://nvd.nist.gov/vuln/detail/CVE-2018-1000880 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-1000880.json", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yoFsaXAZ07Udczxdp1zymw==": { "id": "yoFsaXAZ07Udczxdp1zymw==", "updater": "osv/go", "name": "GO-2025-3956", "description": "Unexpected paths returned from LookPath in os/exec", "issued": "2025-09-18T18:21:44Z", "links": "https://go.dev/cl/691775 https://go.dev/issue/74466 https://groups.google.com/g/golang-announce/c/x5MKroML2yM https://osv.dev/vulnerability/BIT-golang-2025-47906 https://osv.dev/vulnerability/CVE-2025-47906", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.23.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yrec5aYK5L1Cn+46ZF7wbw==": { "id": "yrec5aYK5L1Cn+46ZF7wbw==", "updater": "rhel-vex", "name": "CVE-2026-6253", "description": "A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6253 https://bugzilla.redhat.com/show_bug.cgi?id=2461202 https://www.cve.org/CVERecord?id=CVE-2026-6253 https://nvd.nist.gov/vuln/detail/CVE-2026-6253 https://curl.se/docs/CVE-2026-6253.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6253.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yt110SBxX5z5zTGI4p46Hw==": { "id": "yt110SBxX5z5zTGI4p46Hw==", "updater": "rhel-vex", "name": "CVE-2025-6176", "description": "Scrapy are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.", "issued": "2025-10-31T00:00:21Z", "links": "https://access.redhat.com/security/cve/CVE-2025-6176 https://bugzilla.redhat.com/show_bug.cgi?id=2408762 https://www.cve.org/CVERecord?id=CVE-2025-6176 https://nvd.nist.gov/vuln/detail/CVE-2025-6176 https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6176.json https://access.redhat.com/errata/RHSA-2026:2389", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "brotli", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.0.6-4.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yuFlxOGqQlDuMCywIIELNw==": { "id": "yuFlxOGqQlDuMCywIIELNw==", "updater": "rhel-vex", "name": "CVE-2025-30258", "description": "A flaw was found in GnuPG. In affected versions, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, leading to a verification denial of service.", "issued": "2025-03-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-30258 https://bugzilla.redhat.com/show_bug.cgi?id=2353427 https://www.cve.org/CVERecord?id=CVE-2025-30258 https://nvd.nist.gov/vuln/detail/CVE-2025-30258 https://dev.gnupg.org/T7527 https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158 https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-30258.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yvPadVM0tnN/2SPeW4dXXg==": { "id": "yvPadVM0tnN/2SPeW4dXXg==", "updater": "rhel-vex", "name": "CVE-2023-2283", "description": "A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,` which is initialized to SSH_ERROR and later rewritten to save the return value of the function call `pki_key_check_hash_compatible.` The value of the variable is not changed between this point and the cryptographic verification. Therefore any error between them calls `goto error` returning SSH_OK.", "issued": "2023-05-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-2283 https://bugzilla.redhat.com/show_bug.cgi?id=2189736 https://www.cve.org/CVERecord?id=CVE-2023-2283 https://nvd.nist.gov/vuln/detail/CVE-2023-2283 https://www.libssh.org/security/advisories/CVE-2023-2283.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-2283.json https://access.redhat.com/errata/RHSA-2023:3839", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh-config", "version": "", "kind": "binary", "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-10.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yzNylVcbQzOhZLnqyDvmSQ==": { "id": "yzNylVcbQzOhZLnqyDvmSQ==", "updater": "rhel-vex", "name": "CVE-2026-42012", "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42012 https://bugzilla.redhat.com/show_bug.cgi?id=2467441 https://www.cve.org/CVERecord?id=CVE-2026-42012 https://nvd.nist.gov/vuln/detail/CVE-2026-42012 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-7 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42012.json https://access.redhat.com/errata/RHSA-2026:20611", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yzSKnt30J1hZQJNakZ51bw==": { "id": "yzSKnt30J1hZQJNakZ51bw==", "updater": "rhel-vex", "name": "CVE-2020-35525", "description": "A NULL pointer dereference flaw was found in select.c of SQLite. An out-of-memory error occurs while an early out on the INTERSECT query is processing. This flaw allows an attacker to execute a potential NULL pointer dereference.", "issued": "2020-02-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-35525 https://bugzilla.redhat.com/show_bug.cgi?id=2122324 https://www.cve.org/CVERecord?id=CVE-2020-35525 https://nvd.nist.gov/vuln/detail/CVE-2020-35525 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-35525.json https://access.redhat.com/errata/RHSA-2022:7108", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.26.0-16.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zHj8soqBjkVCuNsVsJIP8w==": { "id": "zHj8soqBjkVCuNsVsJIP8w==", "updater": "rhel-vex", "name": "CVE-2025-5318", "description": "A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.", "issued": "2025-06-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5318 https://bugzilla.redhat.com/show_bug.cgi?id=2369131 https://www.cve.org/CVERecord?id=CVE-2025-5318 https://nvd.nist.gov/vuln/detail/CVE-2025-5318 https://www.libssh.org/security/advisories/CVE-2025-5318.txt https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5318.json https://access.redhat.com/errata/RHSA-2025:18286", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-15.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zMV0VqePDk+l1ba2z8ocRA==": { "id": "zMV0VqePDk+l1ba2z8ocRA==", "updater": "rhel-vex", "name": "CVE-2019-12900", "description": "A data integrity error was found in the bzip2 (User-space package) functionality when decompressing. This issue occurs when a user decompresses a particular kind of .bz2 files. A local user could get unexpected results (or corrupted data) as result of decompressing these files.", "issued": "2024-11-15T10:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-12900 https://bugzilla.redhat.com/show_bug.cgi?id=2332075 https://www.cve.org/CVERecord?id=CVE-2019-12900 https://nvd.nist.gov/vuln/detail/CVE-2019-12900 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-12900.json https://access.redhat.com/errata/RHSA-2025:0733", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "bzip2-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.0.6-28.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zWleXlh1b6JsvwGVnX0JVA==": { "id": "zWleXlh1b6JsvwGVnX0JVA==", "updater": "rhel-vex", "name": "CVE-2026-8286", "description": "A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.", "issued": "2026-07-03T06:14:17Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8286 https://bugzilla.redhat.com/show_bug.cgi?id=2496763 https://www.cve.org/CVERecord?id=CVE-2026-8286 https://nvd.nist.gov/vuln/detail/CVE-2026-8286 https://curl.se/docs/CVE-2026-8286.html https://curl.se/docs/CVE-2026-8286.json https://hackerone.com/reports/3718195 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8286.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zXr7igle7nOx31hbJnIUMQ==": { "id": "zXr7igle7nOx31hbJnIUMQ==", "updater": "osv/go", "name": "GO-2024-2963", "description": "Denial of service due to improper 100-continue handling in net/http", "issued": "2024-07-02T20:11:00Z", "links": "https://go.dev/cl/591255 https://go.dev/issue/67555 https://groups.google.com/g/golang-dev/c/t0rK-qHBqzY/m/6MMoAZkMAgAJ https://osv.dev/vulnerability/BIT-golang-2024-24791 https://osv.dev/vulnerability/CVE-2024-24791", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.21.12", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zXrrwuYD9wK+seRCGBDutA==": { "id": "zXrrwuYD9wK+seRCGBDutA==", "updater": "rhel-vex", "name": "CVE-2026-58013", "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.", "issued": "2026-04-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58013 https://bugzilla.redhat.com/show_bug.cgi?id=2492248 https://www.cve.org/CVERecord?id=CVE-2026-58013 https://nvd.nist.gov/vuln/detail/CVE-2026-58013 https://gitlab.gnome.org/GNOME/glib/-/issues/3925 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58013.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zb5yy59CLP4WltyO2l3tFQ==": { "id": "zb5yy59CLP4WltyO2l3tFQ==", "updater": "rhel-vex", "name": "CVE-2022-2097", "description": "AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimized implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of \"in place\" encryption, sixteen bytes of the plaintext would be revealed.", "issued": "2022-07-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-2097 https://bugzilla.redhat.com/show_bug.cgi?id=2104905 https://www.cve.org/CVERecord?id=CVE-2022-2097 https://nvd.nist.gov/vuln/detail/CVE-2022-2097 https://www.openssl.org/news/secadv/20220705.txt https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2097.json https://access.redhat.com/errata/RHSA-2022:5818", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:1.1.1k-7.el8_6", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zbffUiUdFeVmzp9ywA12fg==": { "id": "zbffUiUdFeVmzp9ywA12fg==", "updater": "rhel-vex", "name": "CVE-2023-23916", "description": "A flaw was found in the Curl package. A malicious server can insert an unlimited number of compression steps. This decompression chain could result in out-of-memory errors.", "issued": "2023-02-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-23916 https://bugzilla.redhat.com/show_bug.cgi?id=2167815 https://www.cve.org/CVERecord?id=CVE-2023-23916 https://nvd.nist.gov/vuln/detail/CVE-2023-23916 https://curl.se/docs/CVE-2023-23916.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-23916.json https://access.redhat.com/errata/RHSA-2023:1140", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-25.el8_7.3", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zhcMOYWJcHjalysw3seV6A==": { "id": "zhcMOYWJcHjalysw3seV6A==", "updater": "osv/go", "name": "GO-2025-3503", "description": "HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net", "issued": "2025-03-12T18:17:07Z", "links": "https://go.dev/cl/654697 https://go.dev/issue/71984 https://groups.google.com/g/golang-announce/c/4t3lzH3I0eI/m/b42ImqrBAQAJ https://osv.dev/vulnerability/CVE-2025-22870 https://osv.dev/vulnerability/GHSA-qxp5-gwg8-xv66", "severity": "", "normalized_severity": "Unknown", "package": { "id": "", "name": "stdlib", "version": "", "kind": "binary", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "go", "uri": "https://pkg.go.dev/", "cpe": "" }, "fixed_in_version": "1.23.7", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zk/ctmNzLQq2GXe3oAc76w==": { "id": "zk/ctmNzLQq2GXe3oAc76w==", "updater": "rhel-vex", "name": "CVE-2022-32208", "description": "A vulnerability was found in curl. This issue occurs because it mishandles message verification failures when curl does FTP transfers secured by krb5. This flaw makes it possible for a Man-in-the-middle attack to go unnoticed and allows data injection into the client.", "issued": "2022-06-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-32208 https://bugzilla.redhat.com/show_bug.cgi?id=2099306 https://www.cve.org/CVERecord?id=CVE-2022-32208 https://nvd.nist.gov/vuln/detail/CVE-2022-32208 https://curl.se/docs/CVE-2022-32208.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-32208.json https://access.redhat.com/errata/RHSA-2022:6159", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:7.61.1-22.el8_6.4", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zqKQG906L7J523hKE7PKKQ==": { "id": "zqKQG906L7J523hKE7PKKQ==", "updater": "rhel-vex", "name": "CVE-2022-47629", "description": "A vulnerability was found in the Libksba library, due to an integer overflow within the CRL's signature parser. This issue can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.", "issued": "2022-10-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-47629 https://bugzilla.redhat.com/show_bug.cgi?id=2161571 https://www.cve.org/CVERecord?id=CVE-2022-47629 https://nvd.nist.gov/vuln/detail/CVE-2022-47629 https://gnupg.org/blog/20221017-pepe-left-the-ksba.html https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-47629.json https://access.redhat.com/errata/RHSA-2023:0625", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", "normalized_severity": "High", "package": { "id": "", "name": "libksba", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.3.5-9.el8_7", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zqSg2zVc3ATJedTq/O4UjQ==": { "id": "zqSg2zVc3ATJedTq/O4UjQ==", "updater": "rhel-vex", "name": "CVE-2025-32990", "description": "A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.", "issued": "2025-07-09T07:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-32990 https://bugzilla.redhat.com/show_bug.cgi?id=2359620 https://www.cve.org/CVERecord?id=CVE-2025-32990 https://nvd.nist.gov/vuln/detail/CVE-2025-32990 https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-32990.json https://access.redhat.com/errata/RHSA-2025:17415", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "gnutls", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.6.16-8.el8_10.4", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zu8rcc5+OA/x6/gr05p8LA==": { "id": "zu8rcc5+OA/x6/gr05p8LA==", "updater": "rhel-vex", "name": "CVE-2023-6004", "description": "A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.", "issued": "2023-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-6004 https://bugzilla.redhat.com/show_bug.cgi?id=2251110 https://www.cve.org/CVERecord?id=CVE-2023-6004 https://nvd.nist.gov/vuln/detail/CVE-2023-6004 https://www.libssh.org/security/advisories/CVE-2023-6004.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6004.json https://access.redhat.com/errata/RHSA-2024:3233", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.9.6-14.el8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zyvQuin4jXjJlAFXbw1hxA==": { "id": "zyvQuin4jXjJlAFXbw1hxA==", "updater": "rhel-vex", "name": "CVE-2023-2602", "description": "A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.", "issued": "2023-05-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-2602 https://bugzilla.redhat.com/show_bug.cgi?id=2209114 https://www.cve.org/CVERecord?id=CVE-2023-2602 https://nvd.nist.gov/vuln/detail/CVE-2023-2602 https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-2602.json https://access.redhat.com/errata/RHSA-2023:4524", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libcap", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.48-5.el8_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false } }, "package_vulnerabilities": { "+oTt3EDPSdSzupH3D6G0BA==": [ "JBUzZfAmFuub9+ICcI9U+A==" ], "2MdeoPFfsUv55LlpgwkOkQ==": [ "IGPwsZmhKfFY6/NwDIOUqQ==", "QLbtrH2NAW6yNTOAlwjUsg==", "yReQJ7USlKwxPIyVvEKPEQ==", "YV4pdpWlOQp4ENY4WBgu+A==", "PKZnOUqZ09NHTQCk4Bz5AQ==", "v+AawDOr4RSUljIzpyfKJg==", "lek/1FI0HdClJgWDNVsHsw==", "b4sDCRZC0dyaz+kllMgRKQ==", "fpkJVe/KmtRv+bBXsYsIcg==", "K2zSg30ZJqCOrHCu65WPsQ==", "C/7x/dKLKsO/O2OclcdjjA==", "my/DHKGJeRxjSNNUPhqPsQ==", "8dbu5kTJCKmDz6HN0xziDw==", "MQVSqfx3uP9HdGFmxGNcpQ==", "tVlxIOZ6F6+EJvRQqpYx4Q==", "lyuzCm7wHQVS8pCLzKOsig==", "rShXs/LMffX1AYFunGEpaw==", "0QnoqOg3TG4vdvby55jMig==", "10mkuQa11DvXpmFksl36qw==", "C8MCCElz0FGYpiXZKAjC8Q==", "nhjv2yqEDuqmBmg1t/yG5g==", "m8lo1EAeizRLnboLT9DGmw==", "7lpl5ajwZr5ADf7iLSBbkA==", "W0HHl6nwR8cHTX8V+Igpag==", "R7Y+1EAHNMj7+xQ3iSua8A==", "LGLL5bzn6z1heSEK9DVkdg==", "OyM2FAnj5ih/yf34RyzScw==", "fyxlf06S6rMafIj672gFrg==", "584yXY5vNaGck4ra71kLOQ==", "Cbzd/bqnZLJIbxJ/1EtUpA==", "UmdXLUcUrfF679npg1+prQ==", "imeJafHbpMchyG3ddsecRg==", "W29H3Qu4TKCFE3tgIeo7pQ==", "K2gOcFXEpHuJkqp/DWKlBQ==", "sDJRRD4zdMjd9jt+SpEg1g==", "FHCOXtsZkfB1HxIZ+8xgpA==", "uFU7coNmhuYnfXDMEDZ5Wg==", "ok6DL7Sb+nmxetWVktjVwg==", "zXr7igle7nOx31hbJnIUMQ==", "ObCt83i8midan504u4przQ==", "OjMZhwxdWxE8pAN8xmrYjg==", "pPCCDOxXrmtalloMkX+jAw==", "yVMgAYQDeD0vSehEFrItQw==", "mR4NMMASPMeRLF/0aGWMcQ==", "sp6iHe6p/KI1q1gzO+J2Sg==", "zhcMOYWJcHjalysw3seV6A==", "+CCbBbxF4hCSEcLE2gCuCA==", "EP6GBY33NlRo5j/mmDBLxw==", "C8yN/CDEhgO0iUoSyqjl2Q==", "5J7GXlJ1u8j1vVS3M0/JgA==", "yoFsaXAZ07Udczxdp1zymw==", "6QNkz1Y+JhK+YsJ1oospGg==", "VnX21Pl9qSPoKfQfhuQUfQ==", "VZCOEnyMf3WnLTUY78ecYw==", "8xq5LOlvJAlBMFm8t08VOg==", "Ihsg9gWq7HOzHuNR/r3Psw==", "iFSzJrooziqfdj1JNPZnuw==", "XxIx1rZYfvSQo5y9eoFYqA==", "btVUVAYdH5P1NknLO1YvNA==", "KQnPK7rlVAdImKcQqtSObQ==", "bYhoAXNcXAJxD4C8u0Ulpw==", "WgM6qkbffWr4Ffsfxk0RDg==", "LVqCXgCDKHDbHsi8OdeBdA==", "m0IJGRf61cMaVU+GJnWBLg==", "/n3JLGVkGgJxFBUJuV7OqA==", "wyr3miTYwjwE6qXtpMKFcA==", "aAOnNh+E2AVONwzbe0X/HA==", "ayb0xDdrI1KzUFqnB2YdlQ==", "3i3rFQ2YbuMILxtg++/X5Q==", "IrOkLYqY2+NBEePGW9P7+A==", "nK6y/UHclqHxgr5WNtNo3Q==", "ZE8z5pZigQ6zR3DrST6XmA==", "6dd3s2x6XRSOCR1hRF275Q==", "d80wPIXiop25QcH362PUgw==", "Cc4ne2QMiCdzg9ej7Ay22A==", "EBRh8/O2Nfmk9fpGdTJfHg==", "AkM7UIP5BtWgOljRb7sV2w==", "koSTqHLTqKovq9PuCx4+LQ==", "nuZSEkRSJLkLrfITtMWhJA==", "jh7m9hFQE/K2fRaz3f3VoQ==", "1xXjuza0G6LPntbEUbkuMg==", "DAA1dKzv1qLCntHLpPLIog==", "rqCeYOmXHyf6R8tJDRQf3A==", "8OaUZ5FEonzWI2BSl0pn5Q==", "O20oLjUCvyKcM7mKHtw1kA==", "TYK4EhmbkLsiNuamdoZ23w==", "1wPGWBpDgFCknqwW3nIAlQ==", "xNexg9DpjcrTRov7qTIFQw==", "lyJMJpTk90SdK260W3kmpA==", "bzF8eDWfH3908SM3uW7W4Q==", "Qf3ehynA9eSLxEmKdgPWzA==", "veYa/2wgH4+VvZYYHBCfPA==", "B1yLegFFcSieySsw74cDww==", "xLEp4QWNtWRdArvsNX84PA==", "uf6hvc/hsJ/rGvizo8Merg==", "IzKl0lqTDhgKE5HPnTfjkA==", "Eyr9WSXlMOV35hvg7CeJKg==" ], "2k8BSFOOZ2ndA++n5wl4TA==": [ "jRUkZ6iXWKQuY8AdCpy0kw==", "twdwvAIDqvKiZLoTbg48Eg==", "gX9OFbpxSsqG4i5HYpODaA==", "9ZyVWoLQ5lFBoIjtu4uEOQ==", "i/DIhomKIBWLQ9viL//FXQ==", "kkf66xuZDAfA1HsGQnywJQ==", "3O56WVSolkvoABYGfjiFHg==", "1x64uH6cdOb5OUrxpLCD0Q==", "ehV42Kf4mNxkwEnYSPYF5A==", "3RvU4z8AafN9DpKXu1VimQ==", "gJbhqv40+/JI6bs5ENVcow==", "fTM3JBmBHsfnwLNG4gJHRQ==", "RjFmZiccRAHOcTfXhttaHw==", "wNoACM7I52HsdbnfoTfqkQ==", "U9OAekt5rMrp2NfnN1hexA==", "3YfvdccW37dXx04g7wb1eg==", "Y/82v7jgmp9WbPyh6zXAqA==", "L5csyNx8FnjUaMAb5WgZaQ==", "Dztwmkxu9NB/xbjOo2p2ZA==", "DcFGNfCGa6QmD0IQUzLpCQ==", "XmzaV+28ObadSObJQlWH4A==", "vLyqX/wwXw895kwHvWCMWw==", "obihmRb48WNZ5GURvZjzJQ==", "dcE/xJAn45jFiks4WqmKbQ==", "6AErW03qOxvwfBKrSzg4iA==", "8rDgIikh0LbAtcEOjHed4Q==", "mVZw6HfBeWMeBMbQ3QI3eQ==", "6Cqvzp5JbuVfHsuYnIJNFw==", "cqYWiTibDLM7aibErMKang==" ], "5Mcqv1rmwAoEs983fcq1cg==": [ "0ywB8yoh2sWnVY1GY399UQ==", "dtogVDvmA8tsAGvyEPjPQA==", "9TZ4yQhaDigJqc3QE7rzRQ==", "R1p9seVH9iMH1JLw33Ofrw==", "uov0ccZmWpY3SZTYmOkCCw==", "8rDgIikh0LbAtcEOjHed4Q==", "mVZw6HfBeWMeBMbQ3QI3eQ==", "6Cqvzp5JbuVfHsuYnIJNFw==", "cqYWiTibDLM7aibErMKang==", "fYMNFu0xQxp0Z7y2lb9Aog==", "G7736sGJCA2FtLz6Qs+G1Q==", "Y/DtnQFC7l5be2CCZ8YFhw==", "oW1RQqehkPmMzMEQAvBytA==", "nflhinhjU+osS1TwBk+DFA==", "JhtH2WNXIzfDA0h7qZ7RLw==", "JqERGcsh34MVDceN6DnHvw==", "HrSeOrH2KyUnC4rq2IXWgg==", "xpe48bYc11r4l1Za0UMTJA==", "HocAP230I+D9IrmRCBNVSw==", "EFaMNy5vJQV+C1E4TtRpFw==", "62mwE4DQA6gTvSLjP2HaOg==", "kXAUkPZpve1iwCUaBskqEg==", "R8DPcPvbg81z+eUw+ykYig==", "ZBcxIahHT2sOHcT4kdlprw==", "mxiKo6Gct+15cqo3Q07Ufw==", "QwE+GnarHqQPSOEo3aCrZw==", "nRvp514SVP42tlHBu46XSQ==", "QRjOpbzsYIicMf8kpKoMnA==", "NPOC1wgf2oOveHlbXsMcNQ==" ], "6KnijwRsfeerWmf5Zl8NWw==": [ "k3o+5yuHivArIfBtIXx02Q==" ], "6Tp9WGakxVaQJ9rGhrsxpw==": [ "M6HQbjeJD01kGqvzEOS2FQ==", "xQWaBVfKJo/zKQEAHLEeBg==", "XPV+5ujjQUNW+tos3Q+v/w==", "9v7GjmoBpXznA/4f7FLNTw==", "rKaUBHYppDrz0hfvcwev7Q==", "7bIaOY2SLxEwDeZXOjwejQ==", "wUhCCQ2TKmxA3z3g0s2FPg==", "W3WDVv515yQ/d0v0j5vcgw==", "NgcYbK+fPZpcG776Ewaysg==", "WkABThbDkGVWsBJZ8miT1w==", "vJm7eeVZEbnxh/9fxMVxog==", "dLBwvrbHvvMzC4tdzDzNMw==" ], "6dlkQEp2PtZPvC6f+1oBaA==": [ "gQZBNz/hUjPyqafsGVQi7g==", "zMV0VqePDk+l1ba2z8ocRA==", "5N/X0o1/JN9fqvD4aiuURA==" ], "6mY62Fou7cJqqLJXm9hzXg==": [ "sThg2GGoKqa1RTJ5skEJTA==", "W/d4trZ7jb2yxjrq4cNOWA==", "yuFlxOGqQlDuMCywIIELNw==", "DdbtHYUAFK3EvhnE38LOBw==", "0nQ3GJDLY22M176Z5ESg6A==", "x3G/eMd1Z0D10r12N+9d3Q==", "dvRjQ6BpPMHoRj/7w9dv/g==" ], "9CuK4fRE5gzOSWH5fqWZJw==": [ "xPWheycLeO7kiluEueY2Ow==", "qNuYRcgtGClAU0g3zKI5Dg==", "jT+SdCGpoEoaiFxD0YzhlA==", "CYdgitwltENTL9rtsuaouQ==", "GLs3IdvMKiw6/G8PtNw8BQ==", "yzSKnt30J1hZQJNakZ51bw==", "2nTJR0d4Yks4joGlPZKftw==", "5+EwPLeLLejao7ij4WmWAQ==", "tGsvzSy2YAolN7IIXG6tpA==", "5B1tQ2BK8z/YjRkYcvwqag==", "CPZo3oXfySRcVVjDJkrS3g==", "8ZxbhBIT+9Mj99/XbMpLSQ==", "tnBbKyfWYMq7GMqd8UCfIw==", "mS0YOFVdBeDRbPVhCEovGQ==" ], "9c4B7Edcs6gS7zy4kBT4Jw==": [ "AFfQXLrpt1jw7bczIIvo6Q==", "XygysGe2kdlyCRQHM1fu3w==", "AE8Cp1u8I9t52OYW7oGU4w==", "F0n/1XXyzTob8lElmXmB6g==", "DDWmqlxBSfXi2KJJ5mwTNg==", "O8fIVXqcGshIonMWsEH9gA==", "wxS+u/uf8o4sT9iSccXQwA==", "klCkJxhhNVG564GOUQMh+Q==", "G2Djh6mj4eOKfpIiPPuLew==", "8Sec+JvKiQWGqYCOBdZhjg==", "YiJlkUTKf0/7+ORZMmQ2cw==", "yiTWIBfruE5rPxLBPqTezA==", "HNpGGr9eP5twQKC3yCh1mA==", "OPNDKUsVLJt2v1gO1zvkBA==", "/QaL/BUIdoF2MAB/C1YiGQ==", "yGCmffaimhyTCMJRNZflXg==", "s3LI+/HXTUE2MugpF0a37g==", "aetFzlYufXdv42s6KFBXcA==" ], "BPD4nm0V1xem9/HmmAnFiA==": [ "fM/S1lXLzT3yP+sZqhNB0g==" ], "BrxW5JNpEdvbkoGRXbVirw==": [ "BUzSiF4P8l2fba8+4vytIw==", "8TFgFlUtgZLpn2Ire1885g==", "HsgdR+ZUz/buofS6xN/cdA==", "73fA3MvglACzfufm+EV8fw==", "rkTtYvrd12uyxklXyGzF1A==", "B3GLjxsk0fvju/+IzG5Prg==", "gqNlp+zMbwHq1FhCyd5krQ==", "KrdA+ZSJ60jp3zLcReaBRQ==", "yvPadVM0tnN/2SPeW4dXXg==", "Z58BGKrYmp9sLvyqZKyMHQ==", "0fRIluxuaC1n6wm+qP9Pjw==", "KCgCqCavM9U0xL+GHJqzSg==", "UUIKm7f4jyfDWGKvptUQ8Q==", "npQpPXYG8xMJ1LRSVSnKGA==", "OgFGrvrnAoXXvapnatTrxQ==", "XbpXfbeApuDuIKvY0/qWiA==", "assnsOgZ19ItYfuh/iKLMA==", "Rfm1tD+QxSP/TVjKFDNabg==", "ruDQdx7OmIsgMCpioWbqOQ==", "H9Ud41wofJc/QlL6Rm7WkA==", "jO9fUvpFi0R9/mJ1YH7KXA==", "YOjk++xRTh9VXO273YBySg==", "W0l4QAgarxrOkTlGvtp0uA==", "Ig/iNncFD4P4EYoOu9TAeQ==", "R90VfdEewbj2ZB0bKqbhNA==", "Wp4+QBQm4nhI8rQxVklEXw==", "a9FCHpokzVfpw+gdnrzSXg==" ], "Bt7v/jLkw1CWEjQhzP+6Ew==": [ "3O4IzHXnRQMZXCe1gYATvw==", "8KH5GLr9/x1y00jN/HK8MA==" ], "CbI8d0OI9wvrtddD/Wg0GA==": [ "BfjzSlo8p3Mkdy2LzyRaeg==", "WGvgNwrW2u5APZcidQ6v1Q==", "0IkIJ5q/xNX41U2yF71Pyw==" ], "Ce3Eu6RmZkiUW2to8Kec/w==": [ "qES6WE3Hn+2j01vEmBBKiQ==", "54QMeb97RdTZwYWYELMfPw==", "/X3Awdl9dZDLotIfpsQK/g==", "/MGsJ9KCE7TaFp0QWQ2amQ==", "RISSeC/EvrM60Yku1wKENQ==" ], "FdB9K1+1CEpzAW4zwkaAGw==": [ "YYbr54PEl4J1NET9C1dPhg==", "f6JqroM9DAPFPzLvkr6TsA==", "RITj6RMTk7dAExWxjkhkvg==", "6yoZPg/otXO9Ox3LLPygPQ==", "WWV/wgl5XOJ1g4XsbmHtdw==", "l8OX/JvX/6Phr3whXXIPdg==", "APwVrIce77Ku6UBCO29tAg==", "HGfAft6M/YdppebImEvcaA==", "klDSadzoRr4q59QuvFGaTA==", "0wAoL7EHybTff1dEx4QX9w==", "bLEcs4XYapNmeTM4WLeVAw==", "kKJCXd0zC8/mIMuSsDoNSw==", "yfmRolXybbYkofU31txxnw==", "gbxzM63S/+/q05197cVzwA==", "EDi0HswnDmwfAMMYtcTUqQ==", "YY1AnmNdojeTQaO/z5gGTA==", "nrNkqQpKDeKvEoEVMtGvmQ==", "usSOeO0eis4fMxpUrYF1Og==", "PRkbEOx7V6ePRT/WUyklHg==", "wbBiCPikq6Iz02EPsysTgA==", "Znm2hdK/FULQhTTGTVX59Q==", "fayrPya6DVXP9weWvA6obQ==", "crmilTSJ/pTSPBKY9EJmZg==", "qXNASosSuCsudML1MqXPjw==", "dYucp/SettSQd/Hpukj6pA==", "jKke6Txz52GXq3xidnEMgg==", "8KJb4x3mXgChaQULEsid2A==", "J0YQQx6sv/Elt2kRDVPlXg==", "A0ZMrO+gsPP+1kjH7JYgNw==", "0v/g0Z/XEXV13r48i52JgA==", "v1exQXePimNPt3tveLBP9g==", "yrec5aYK5L1Cn+46ZF7wbw==", "2U6d1qsPVwS8vUnflv9AcQ==", "AsUlQvbhYUzI8ZRGAIAAkw==", "zWleXlh1b6JsvwGVnX0JVA==", "Pe4IHqZpuBtuSkrgd2HMEg==", "noXaVqkCbpzn51NS8fKFEA==", "vTJZ/R8pdcyDbwAwRi8cBw==", "fT6cIVRM+743nfHJKo4yuQ==", "TuBnhFrkwMqIcYtYYgNGNQ==", "4JszZEguo/SAFbgp6PdKMQ==" ], "GlWFSNV8QxYx5o3TOWf+IA==": [ "TapvA/WPAxpiLfGqTfgs4A==", "hfBpyVezkUAf98QWnlvzIA==" ], "HkH7JOZ7zVk8ggpmKHnMxg==": [ "a1JZMpXS/ssjLYCl17uNJA==", "k8qh5HUHIEX/Inga/xEVgA==", "8U0+E/NmfCj/l/7kqufLug==", "49iR5D1WXClVofqwu/tZ8Q==", "ZRzqQ+u1wA21Iiq1JiWScw==" ], "Hr1TetfTnCbToWK+Q1/NLw==": [ "8nqmUoZ94lq9djmfK/BUAw==", "1Mr3ID1dsZJrqfRCJnrW+g==", "SAbLfsfvEYCEKFQYbD0xVw==", "7MTZYXN1wiJGDdcyRQJ1Fg==", "dYe0cnQs909yjJScdhxi8g==" ], "IdaeQutkPjfv4bTMEkXWog==": [ "t4oe6DBPNf5Ikk93RfTdig==", "5e3gC+KDeb36jTLxBYtijg==", "fXpWtuXNPi3tb2edhk37bw==", "LUmQoE3ILxXEHVxGRqYkVA==", "RYgdOTk5snrzxeLvC7Ui4A==" ], "IzLcxZDtcvtJR5Gwdq9HDg==": [ "7Fk3wVCUvtHC5JGu/YwCEw==" ], "JC8eNzSj6tieJqNqASET1Q==": [ "8WDcymWmuQ3Sn9ymHvtn4Q==" ], "N1RbIRo2SyHosQefv+skDw==": [ "qld8Wk8WGHJZFjcPP6Ptwg==", "R0kLLh/19P/mLd+t6ufaFg==", "UbmdE2pHXRFccv8l1e02Jw==", "mQtrNhzMQ9mAh/coURV/3g==" ], "O63QX7+X9KEjj9ex/GG2aA==": [ "aT/aXsmladAgxlVRxWQriw==", "WGvgNwrW2u5APZcidQ6v1Q==", "0IkIJ5q/xNX41U2yF71Pyw==" ], "Sg7WHD/cpWdFZ7MyPqITSQ==": [ "339w21eGPDsPlNhgbxaeRw==" ], "UKxtVVWEN0LXB/lFG1+5oA==": [ "M59UwDbs3+/LtSu1P1x+Rg==", "Eri53zjDpZ39TFPuRdYDKw==" ], "W66WOQ3v6r7mSn6+o7gaew==": [ "DkHpdzAuAlElCotBlgVgPA==", "6UnjveNMgk4ukDQJdTGvOQ==" ], "WrV+rIJLRk8b24xMew9Hkg==": [ "pNyd3CZwI+UE1lrar0+Tbg==", "zqKQG906L7J523hKE7PKKQ==" ], "XKq3fjedO7d4LSKzSLDcMw==": [ "8/XTjhUL73PmS+RFgd07FA==", "vAbtgIwYiyXbMMuErZhftQ==", "0ooSlh5nhhmGfw4m42ye2A==", "/Eu6u3EM/g6M29wF7eD4HA==", "cBE7uXJww3nGI7rdDj7t+Q==", "lrvnALLPkIyVQziuSGQ9qQ==", "gWWpK4sdhrZSUeW3Sm8ORA==", "OFDhfcSCyh89+bVcqy0Bug==", "pOPPyR+CIc4lpQu0LrmDeA==", "IrZ293CgkZfECHUvFvmpSw==", "+v7atIO/jUEFghZH7rPomw==", "DluUanANT5nvELzWjLa/TA==", "Y0QvAMtz9tlzAMfAFLbgjw==", "AKK15am6qQUGnIgHe5PZkQ==", "f3P/kawtCGYCSTroATyzAw==", "E97yacFb4u2m5K6ETIUDAQ==", "x6UCsSnHrxwMwN3+lSw6Jg==", "Ao/QxV1G+txY/o+fZamBDw==", "CNBhlzOLGRw6hilca+FCgA==", "H3G4pMSGLHVSf7Q/IdqlDQ==", "wB7876bSzFTczOPU8wybVQ==", "KgGohRx9O58TbLH2PqdLRw==", "VKqdogZsa9um4xK5rHpQyw==", "Z4UHDiA4rMNuHhox79Bz/A==", "a+awkS0u3U9BN7LTYpKUTg==", "8rDgIikh0LbAtcEOjHed4Q==", "mVZw6HfBeWMeBMbQ3QI3eQ==", "6Cqvzp5JbuVfHsuYnIJNFw==", "cqYWiTibDLM7aibErMKang==" ], "XKv+fGQhqJZl6x7NNqqaaQ==": [ "kp1TXQCpIxEQ9QttfHMWZg==", "WGvgNwrW2u5APZcidQ6v1Q==", "0IkIJ5q/xNX41U2yF71Pyw==" ], "ZRpVwDgK9rS2HJv/RQ5Gkg==": [ "geTtkmTtPDxSAjfZEBGWfQ==", "ieASPdYzGxWke8nZZhE02Q==", "mouoWVvs12H8FynnB5qIsQ==", "sRVcQFAdq4Ll42smqacaCw==" ], "aTfPDP7oJqFwbwjiDbCnWA==": [ "IEMHgBMw35D4hXSAa095xA==" ], "bcw2EOFjnx1wB4M400Jpew==": [ "uPjRNrHM6KmwqqGnGCODOw==", "1vSI4M5c48FhFckHzvLxNA==", "l9dHBEfcpD6dMVlWOwL4HA==", "MnunaZEdl7GYfOnz9f27HQ==", "WGOq+rhe3/NaL51WCyZSeA==", "QwBnC+2unbl7BaURui6Tng==", "fvGjL9hw9hDQockMTb7lrA==", "HSXdNax5s4311f36iab1RA==", "rSMeftoxZCXzQYWbyBPriw==", "WHdlDKqisJJ9fRsM9LxySA==", "VmsOBc3mY7KTk37gMHLcBA==", "afLJ2TrcMPRJL8v9fyt5hg==", "NaCKxQTduHOCF6oo1VNczw==", "yzNylVcbQzOhZLnqyDvmSQ==", "YjceJLqUKf33ztRXUlgI/Q==", "WzKr+vOS+cHO5ydxI18BFQ==", "ayNNRQmygz9tBo/oxR437A==", "1MernTu9spjwGBRYkNkZIg==", "zqSg2zVc3ATJedTq/O4UjQ==", "Qf35dl+554myaMtzHWghjQ==", "ef6DhO/UZ786aZ02XWCNqQ==", "gqZgaapoEbnm+Oj7iPZ37w==", "6GwsF+MSFOJ9Sierd0uYzw==", "GX3nMI8DKulYH9XgAGkCjw==", "3Rl0hdm/K5SiiE3lXagVYg==", "ogQLwI4CKSGkUta+rUUomw==", "iFFhT3GCX+mTkglBusKyXw==", "Jqukx5R9h3ieXFJ4Kcl9Ig==", "f8CIZ65CD/f6e9Mdmn8vXg==" ], "bfF0cEWD49u6W/lExfuSww==": [ "P9XTUYbTD1cGaDl1B19OdQ==", "XkYYkW68UK2NwhLI/UmYUg==", "EzAzLccAjftKnyVlmDBV6g==", "XzpR/ASE/VqV+Ft/wiA6Qw==", "bmNCCgFZ5KNaxCzyrOTM3g==", "FwlsVCWuXM6wdnEAE0M5tw==", "Lu3XtaI6dYpKttbUCbs47A==", "FjCuOB8g+V6CndsJn96RJA==", "OIxqwllP74OlfGeyl1Yliw==", "VNVOmhP5E/G5E7BnsCVH3g==", "v78axfxSunBGHhES6GBw8Q==", "Ld3pT/jZvU2DonJRAxTnLw==", "avvi/YxG3J40ZK3NTLgmcQ==", "zb5yy59CLP4WltyO2l3tFQ==", "kZwQRex+JNO11iMZ0Kg+IQ==", "mVDdLszud8eQGKbdS4PWJA==", "L/KNFtLGHvteeF6ArV/0DA==", "6pD/2IKN8cR6N6PBQHwPrQ==", "/hG2eFl/EZ15/sR5oOZbCA==", "ZkEez7f24VNVhTaTCDhuEg==", "BV++s35Ur4bQRS6HK0QCIA==", "8D3i4K1ylUr5dGk9imV9zA==", "F2aHNsZ7wIxMKRFoRhLULQ==", "97PwDrD8knMveLXwKCvQjA==", "PcNbuWOo0ahqjfbOQhXvvQ==", "OLKvdPVgT9/lPcflJTxE3Q==", "iFhWPnp6w/VV9hJa/b0oig==", "VLzwKVDYC7fQrtcpCzjXjA==", "QUtTYJuHdkAOgtveagWUfA==", "rEd6JdG2xx5NZ9bcsFRNpw==", "oWl6C8goK/FnQDlax8YX9Q==", "rVgBV65FWtFg3jitEqotFA==", "86unVXyTxdffdcXWZTYw5g==", "OpUahpCA4oBceG962KxTMA==", "cERFf1oFvXQnx4BPCz9RhA==", "HDr4rB3dwHneK78KvohfHQ==", "LWLSX4FCLbzYWK97i5Or+A==", "UPzTyNn8ZLXlb+bwRFPPTA==", "tlWVK61iOpKPkvmeShS9AQ==", "6FQUI3OxX4C5skWXKgq80Q==", "WcChSpNAL6V9Xfxc9AqW7g==", "gagftKXuSuh9pi4dRu9yPQ==", "Fp999hDC/lucBsNHwOlp/A==" ], "dFKSSJF5WrKg9VsNZqM98g==": [ "HTk+AAyRWNCrZTtBLx34Aw==" ], "eiOy5bizxjO/psTcJ5Gh+g==": [ "zyvQuin4jXjJlAFXbw1hxA==", "kiHW82C3wKDYOBbnq/LPIw==", "q3ulWCbJWdmHCRfeXXzLMA==" ], "ev1iPKY2UXha+ggKYJjsaQ==": [ "HdAyLUATPStr/HXiy9fgQw==", "RXjd5U95osIGXnqCa34Jkg==", "CwmELSAfO/DM/HghGDWwow==", "xjRJnKlNaH/FGi0NN5VKBQ==", "7Puka2o1jq4jSr2Hekrfhg==", "EiJx6rOT8KoLX+Wu7/N6HQ==", "G7IyfoPhe9f8QzIGbOfn7Q==", "srdggAxrYxj8SIe8dBdTNA==", "619DQiII/+IW12e6tmtrxw==", "1kwBKuPYWuGsNWB/ZWkPvg==", "IeRhFWzdFJzG/TLyibYj4g==", "a0/2S5H7zlzjqVN38pRbOg==", "v7w6RCU36McEvGLyy4Z/qA==", "EzTkSUGeeQgpxoz/kHYgqA==", "+5YAvs7pNh2OXMNza1K1SQ==", "RsX/3pJwmZI4sym3ZDA/fw==", "qn7yHwg0TG0L9eYiAmbjIg==", "WqRrObt09T7C3IJPaLipRw==", "qWRIUBMC7Yu6aXYW5EzOcQ==", "Uwr0G7T1uD9pkPe9v3QhhA==", "LrSw4TBb1fk8iUV1LcC4Cg==", "vamdoTfL2zH+m03imhf9RQ==", "+KBioDGBgFmFBqrp2FkLIQ==", "Wy+NCeepWTSiKEZIMSlFrw==", "IaK9TiZl7D4PrFM5K8yoVQ==", "/u+MoX7ESLBePT8pNUw5FQ==", "aVMgTmw8gvaYP/OjqlHeVA==", "iXEopm+7p5ZQvLickgqvJQ==", "PYrECm01712wfbeM6lQgVA==" ], "hqd/9D+OkW729P80H901pQ==": [ "uEggs7thHCRp4eZu5EDH0A==", "S5Bw/81ixhFX3PO8tegz3g==" ], "k4gCNgIfg7MM/e42ThRx2w==": [ "AZQ9MHTiNLYiRU7sYZlVGw==", "n83jaRl/T6kiaoMyWtX8xw==" ], "lqQ3rJzPTM4e3pH+ravEcw==": [ "yt110SBxX5z5zTGI4p46Hw==" ], "o4tvrO4Cuc2PXep4Fk53sA==": [ "dGtImtgXxemdBTM1vCCLUg==", "+et2nlLBpUOdsIiOQHCCVQ==" ], "oJIAHlP0pGe97iAzAFF0xA==": [ "usSOeO0eis4fMxpUrYF1Og==", "PRkbEOx7V6ePRT/WUyklHg==", "wbBiCPikq6Iz02EPsysTgA==", "Znm2hdK/FULQhTTGTVX59Q==", "fayrPya6DVXP9weWvA6obQ==", "crmilTSJ/pTSPBKY9EJmZg==", "qXNASosSuCsudML1MqXPjw==", "dYucp/SettSQd/Hpukj6pA==", "jKke6Txz52GXq3xidnEMgg==", "8KJb4x3mXgChaQULEsid2A==", "J0YQQx6sv/Elt2kRDVPlXg==", "A0ZMrO+gsPP+1kjH7JYgNw==", "0v/g0Z/XEXV13r48i52JgA==", "v1exQXePimNPt3tveLBP9g==", "yrec5aYK5L1Cn+46ZF7wbw==", "2U6d1qsPVwS8vUnflv9AcQ==", "AsUlQvbhYUzI8ZRGAIAAkw==", "zWleXlh1b6JsvwGVnX0JVA==", "Pe4IHqZpuBtuSkrgd2HMEg==", "noXaVqkCbpzn51NS8fKFEA==", "vTJZ/R8pdcyDbwAwRi8cBw==", "fT6cIVRM+743nfHJKo4yuQ==", "TuBnhFrkwMqIcYtYYgNGNQ==", "4JszZEguo/SAFbgp6PdKMQ==", "hJlWqZ7n1IINkFnSLUe61w==", "WkHqdnp8D70QvbkNJlkMDQ==", "4rmNFfTLXyhGn97x/e++IA==", "n5updgcs+J/K/GkxnmDRXQ==", "svSEG/XaetbIWOhLQcy0Rw==", "A/8WFcBgNb2KqM+8djtoNg==", "Op09biNdGX0n0Vlix1J9nA==", "fOQmU56iPUBV8Qguc6zUjg==", "YNVn4/OBbQHajyVtshrL3Q==", "zbffUiUdFeVmzp9ywA12fg==", "wjNYcQ4jin5xLZ9x3M9snA==", "wNoWbGRqNSwxpxvQoLKucA==", "zk/ctmNzLQq2GXe3oAc76w==", "fPSdx84mD5ZpVIqkzEY7lw==", "2RxMNudsmmn7hs6tgte0cg==", "G3sKOMxS4ta72W4huhBvJw==", "IZ0eLKcSsRufomKfqpkTfg==" ], "p75sU/+cD5K1Jv37jjSsxQ==": [ "vrmMgxCMgT/Bjrct252HXA==", "ZTGiJlkqcqrCLJSY/Sq8lA==", "HuOxI+pWjgGV0XsBvltzlg==", "jw1ZiDut5Ot+DyVFjCrixg==", "ofnnqzvHUpmPXQD17CK0Og==", "rEg00U8+//igCt+0+QBUhA==", "673FKazcUiydbfN5c6amaw==", "SHxE0qXbBmDEp/LL1ieJeA==", "VsocCwaFpF6PzdX5PxR+sQ==", "xCUiEQAH1lfhrKtUxQDIYA==" ], "pKEOaN2eCFIneHzHE7HYug==": [ "kl+nHl+uiNLzyLIPmJZ+2A==", "ZTGiJlkqcqrCLJSY/Sq8lA==", "HuOxI+pWjgGV0XsBvltzlg==", "jw1ZiDut5Ot+DyVFjCrixg==", "ofnnqzvHUpmPXQD17CK0Og==", "rEg00U8+//igCt+0+QBUhA==", "673FKazcUiydbfN5c6amaw==", "SHxE0qXbBmDEp/LL1ieJeA==", "VsocCwaFpF6PzdX5PxR+sQ==", "xCUiEQAH1lfhrKtUxQDIYA==" ], "rYu8Ys1qBj5SKpIdfiIX4Q==": [ "18zPxSgJwI7mcSJsDFvIMA==", "+H82pW871t8eenixI/+tlw==", "eKx2b/57ZENrxVKuRWfmwQ==", "WZpyztsbN64kzxjO5mCNCA==", "FYcmLqfShPp9H+6QnddlhQ==", "FwjfnEjZvR6Y8qr6vjzDlA==" ], "riulbh7DNxLvW7j4IHJ1VA==": [ "Z9bgaNEOWbDMyC8kgQZMlw==", "pjhL5VIkXQnq+rpcwS7JRg==", "/viT+PF8pyoWGfVITKNvYA==", "o8knMpkoquoumaFb+1FM4A==" ], "rrdnE/YLwpAII45HQiOssw==": [ "noylE2HydWlbvhrfwI8wdQ==", "E+Il2jDXO1Rg5FnzzStA+A==", "SzmYO03Ci8Y2lXH/guHOmQ==", "0fRIluxuaC1n6wm+qP9Pjw==", "KCgCqCavM9U0xL+GHJqzSg==", "UUIKm7f4jyfDWGKvptUQ8Q==", "npQpPXYG8xMJ1LRSVSnKGA==", "OgFGrvrnAoXXvapnatTrxQ==", "XbpXfbeApuDuIKvY0/qWiA==", "assnsOgZ19ItYfuh/iKLMA==", "Rfm1tD+QxSP/TVjKFDNabg==", "ruDQdx7OmIsgMCpioWbqOQ==", "H9Ud41wofJc/QlL6Rm7WkA==", "jO9fUvpFi0R9/mJ1YH7KXA==", "YOjk++xRTh9VXO273YBySg==", "W0l4QAgarxrOkTlGvtp0uA==", "Ig/iNncFD4P4EYoOu9TAeQ==", "R90VfdEewbj2ZB0bKqbhNA==", "Wp4+QBQm4nhI8rQxVklEXw==", "a9FCHpokzVfpw+gdnrzSXg==", "v15shMI69zvuf6oTbTQYrA==", "t8NWvVlCIq8TSmV68diH3w==", "ilhK+Ap+h5mZVKmQX7nDwg==", "yQIFYkzYJzgmJ2Nsgj7X6g==", "zu8rcc5+OA/x6/gr05p8LA==", "XOJZGmeZwsebobAglmEIzA==", "zHj8soqBjkVCuNsVsJIP8w==" ], "sm5sCuXecubhzEqZduLhHA==": [ "rf7KrQE1JIHCxJHtGdy3MQ==", "xyXxPp8aZoIrfhSdoDZiRw==", "2NoNPjVWSksxN+sTENwoIw==", "CFJplXTrY46a5BwwNnwfeQ==", "15glBRF4pyCc/Aq0eHsKqA==", "2DLcncUUd6/1/JtsPnknxw==", "a067YUjLHWzR99JNl/RtGQ==", "t3XJyztcU9aOXTMLI8NRmA==", "1lUHOMB3ANHGWpqCBv9Ynw==", "BooDzA4nzaDI1l3E5zAHgg==" ], "tD550emtLUl2wRNyHrPi+w==": [ "icj6a8bc4dYK/DJNvkU0+A==", "/WMB1nTGBVOBOwBvvW76zA==" ], "uC7d+TJ+SSl/a1e/alHSPg==": [ "eFkHRGAjSFu9sbgr+RArOA==", "WnU62DA2fwlfQLbeba0AYA==", "U8up9/ZYW+CTO5UcJB1hZQ==" ], "vQtjn4H9BmPSTQWBlhOhfQ==": [ "YbAnIQEqWeedb46YJk3cBg==", "zXrrwuYD9wK+seRCGBDutA==", "iEGZHZXt8HWPSM5eJesddQ==", "npBrFSWnZYxq9cizdfDfCQ==", "KaROgE0QmtiOixMG9Wi1RA==", "EKs36DFwHVCzU/cF0Be9pQ==", "DoTF+GSVr6bH3qr9kb98Iw==", "0fCtWwB6iclgRvIA+IqiJQ==", "rP7oa42+SZpvxen+n93BaQ==", "ElIjMFAz33tt/XVMysRkdA==", "xLIujTim86EomaRofe4tDg==", "GWg5WOvOqfRt4sWhRhSM+A==", "CmGl35oJyKxCfItoqDiYoQ==", "ngbKDtxhn33NKWC2lhOQNQ==", "Yruwfu4Vkg/KNSmhqw2VEg==", "EiL50P2QSOoRA18XAAH6Pg==", "4jAWcNPbUa6mXzywmxFG1g==", "VQJ+FoX0f/k7ipxHBnV3LQ==", "4jwyohcb+1bhgpZNrF5JUA==", "PDAKSDN44Xjzz2yknyU/sQ==", "4BMu8XKXu+ZtEjv/XhWxXA==", "Ahnxi92nCGMJDrFfn/I6Wg==", "MTn6Pv097F39x9jLZcCyTg==", "Qmz0nOmPr2Gi30IOiKJW0A==", "ol0claZIIaI4jDf0WjYhhw==", "eSKL36MlZ1HyqAeoxF6NSA==", "+aouF4dLx+YkeGMSFc9q+g==" ], "wE436RbDo1t5UIcLXo90zw==": [ "8WDcymWmuQ3Sn9ymHvtn4Q==" ], "z4fnEFpWc1E2kVtgPcyZxA==": [ "sGPMVAq85tNcvWM0LZLajg==", "ieASPdYzGxWke8nZZhE02Q==", "mouoWVvs12H8FynnB5qIsQ==", "sRVcQFAdq4Ll42smqacaCw==" ], "z5qQdcrRCAH7EdqVwJ79ww==": [ "KwU14JJquPd6TePl7iIt1A==" ], "zbALRizc8CWcgSofeiuhLg==": [ "sOvZn+pqO1JdbX1EL6XdGA==", "WGvgNwrW2u5APZcidQ6v1Q==", "0IkIJ5q/xNX41U2yF71Pyw==" ] }, "enrichments": { "message/vnd.clair.map.vulnerability; enricher=clair.cvss schema=https://csrc.nist.gov/schema/nvd/api/2.0/cve_api_json_2.0.schema": [ { "+5YAvs7pNh2OXMNza1K1SQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+H82pW871t8eenixI/+tlw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+KBioDGBgFmFBqrp2FkLIQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+et2nlLBpUOdsIiOQHCCVQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L", "baseScore": 4.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "/WMB1nTGBVOBOwBvvW76zA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "/X3Awdl9dZDLotIfpsQK/g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0IkIJ5q/xNX41U2yF71Pyw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0QnoqOg3TG4vdvby55jMig==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "0nQ3GJDLY22M176Z5ESg6A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "0v/g0Z/XEXV13r48i52JgA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0wAoL7EHybTff1dEx4QX9w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "10mkuQa11DvXpmFksl36qw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "15glBRF4pyCc/Aq0eHsKqA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "18zPxSgJwI7mcSJsDFvIMA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1Mr3ID1dsZJrqfRCJnrW+g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "1vSI4M5c48FhFckHzvLxNA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2DLcncUUd6/1/JtsPnknxw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "baseScore": 4.3, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "2NoNPjVWSksxN+sTENwoIw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "2RxMNudsmmn7hs6tgte0cg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 3.7, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "2nTJR0d4Yks4joGlPZKftw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "339w21eGPDsPlNhgbxaeRw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "49iR5D1WXClVofqwu/tZ8Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "4BMu8XKXu+ZtEjv/XhWxXA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "4JszZEguo/SAFbgp6PdKMQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "4jAWcNPbUa6mXzywmxFG1g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "4jwyohcb+1bhgpZNrF5JUA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "4rmNFfTLXyhGn97x/e++IA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "5+EwPLeLLejao7ij4WmWAQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "54QMeb97RdTZwYWYELMfPw==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "584yXY5vNaGck4ra71kLOQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "5B1tQ2BK8z/YjRkYcvwqag==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "619DQiII/+IW12e6tmtrxw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "62mwE4DQA6gTvSLjP2HaOg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "673FKazcUiydbfN5c6amaw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "6FQUI3OxX4C5skWXKgq80Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "6GwsF+MSFOJ9Sierd0uYzw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "6dd3s2x6XRSOCR1hRF275Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "73fA3MvglACzfufm+EV8fw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "7MTZYXN1wiJGDdcyRQJ1Fg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "7bIaOY2SLxEwDeZXOjwejQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "7lpl5ajwZr5ADf7iLSBbkA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "86unVXyTxdffdcXWZTYw5g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "8KH5GLr9/x1y00jN/HK8MA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8OaUZ5FEonzWI2BSl0pn5Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8Sec+JvKiQWGqYCOBdZhjg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H", "baseScore": 6.6, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8TFgFlUtgZLpn2Ire1885g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "8U0+E/NmfCj/l/7kqufLug==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "8ZxbhBIT+9Mj99/XbMpLSQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8dbu5kTJCKmDz6HN0xziDw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "8nqmUoZ94lq9djmfK/BUAw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "A/8WFcBgNb2KqM+8djtoNg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "AFfQXLrpt1jw7bczIIvo6Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "AKK15am6qQUGnIgHe5PZkQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "APwVrIce77Ku6UBCO29tAg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "AZQ9MHTiNLYiRU7sYZlVGw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "AkM7UIP5BtWgOljRb7sV2w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "B3GLjxsk0fvju/+IzG5Prg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "BUzSiF4P8l2fba8+4vytIw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "BV++s35Ur4bQRS6HK0QCIA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "BooDzA4nzaDI1l3E5zAHgg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "C/7x/dKLKsO/O2OclcdjjA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "C8MCCElz0FGYpiXZKAjC8Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "CFJplXTrY46a5BwwNnwfeQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "CPZo3oXfySRcVVjDJkrS3g==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "CYdgitwltENTL9rtsuaouQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L", "baseScore": 7.7, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "HIGH", "availabilityImpact": "LOW" } ], "Cbzd/bqnZLJIbxJ/1EtUpA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "Cc4ne2QMiCdzg9ej7Ay22A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "CwmELSAfO/DM/HghGDWwow==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "E+Il2jDXO1Rg5FnzzStA+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "EBRh8/O2Nfmk9fpGdTJfHg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EDi0HswnDmwfAMMYtcTUqQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 3.7, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "EKs36DFwHVCzU/cF0Be9pQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EiJx6rOT8KoLX+Wu7/N6HQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EiL50P2QSOoRA18XAAH6Pg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EzAzLccAjftKnyVlmDBV6g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "EzTkSUGeeQgpxoz/kHYgqA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FYcmLqfShPp9H+6QnddlhQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FwjfnEjZvR6Y8qr6vjzDlA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FwlsVCWuXM6wdnEAE0M5tw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "G3sKOMxS4ta72W4huhBvJw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 3.7, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "G7IyfoPhe9f8QzIGbOfn7Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GLs3IdvMKiw6/G8PtNw8BQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GWg5WOvOqfRt4sWhRhSM+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", "baseScore": 8.6, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "H9Ud41wofJc/QlL6Rm7WkA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "baseScore": 3.1, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "HsgdR+ZUz/buofS6xN/cdA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "baseScore": 4.8, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "HuOxI+pWjgGV0XsBvltzlg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "IEMHgBMw35D4hXSAa095xA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "IGPwsZmhKfFY6/NwDIOUqQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "IZ0eLKcSsRufomKfqpkTfg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.7, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "IaK9TiZl7D4PrFM5K8yoVQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "IeRhFWzdFJzG/TLyibYj4g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "JBUzZfAmFuub9+ICcI9U+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "K2zSg30ZJqCOrHCu65WPsQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "KCgCqCavM9U0xL+GHJqzSg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L", "baseScore": 6.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "KaROgE0QmtiOixMG9Wi1RA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "KgGohRx9O58TbLH2PqdLRw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "KrdA+ZSJ60jp3zLcReaBRQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "baseScore": 4.8, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "L/KNFtLGHvteeF6ArV/0DA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.4, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LGLL5bzn6z1heSEK9DVkdg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LWLSX4FCLbzYWK97i5Or+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Ld3pT/jZvU2DonJRAxTnLw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LrSw4TBb1fk8iUV1LcC4Cg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "M59UwDbs3+/LtSu1P1x+Rg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MQVSqfx3uP9HdGFmxGNcpQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MnunaZEdl7GYfOnz9f27HQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "NgcYbK+fPZpcG776Ewaysg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "O8fIVXqcGshIonMWsEH9gA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H", "baseScore": 5.6, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OIxqwllP74OlfGeyl1Yliw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "OPNDKUsVLJt2v1gO1zvkBA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Op09biNdGX0n0Vlix1J9nA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "OyM2FAnj5ih/yf34RyzScw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "PDAKSDN44Xjzz2yknyU/sQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "PKZnOUqZ09NHTQCk4Bz5AQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PYrECm01712wfbeM6lQgVA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "QLbtrH2NAW6yNTOAlwjUsg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "QUtTYJuHdkAOgtveagWUfA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "Qf35dl+554myaMtzHWghjQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "QwE+GnarHqQPSOEo3aCrZw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "R0kLLh/19P/mLd+t6ufaFg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "R7Y+1EAHNMj7+xQ3iSua8A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "R90VfdEewbj2ZB0bKqbhNA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "RITj6RMTk7dAExWxjkhkvg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "RYgdOTk5snrzxeLvC7Ui4A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "Rfm1tD+QxSP/TVjKFDNabg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "RsX/3pJwmZI4sym3ZDA/fw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "S5Bw/81ixhFX3PO8tegz3g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "SAbLfsfvEYCEKFQYbD0xVw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "SHxE0qXbBmDEp/LL1ieJeA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "SzmYO03Ci8Y2lXH/guHOmQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "baseScore": 4.8, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "TYK4EhmbkLsiNuamdoZ23w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "TapvA/WPAxpiLfGqTfgs4A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "UPzTyNn8ZLXlb+bwRFPPTA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "UbmdE2pHXRFccv8l1e02Jw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VNVOmhP5E/G5E7BnsCVH3g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "VQJ+FoX0f/k7ipxHBnV3LQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "VmsOBc3mY7KTk37gMHLcBA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "baseScore": 7.4, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "VsocCwaFpF6PzdX5PxR+sQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "W/d4trZ7jb2yxjrq4cNOWA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "W0HHl6nwR8cHTX8V+Igpag==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "W3WDVv515yQ/d0v0j5vcgw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "WWV/wgl5XOJ1g4XsbmHtdw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "WZpyztsbN64kzxjO5mCNCA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "WkHqdnp8D70QvbkNJlkMDQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "WqRrObt09T7C3IJPaLipRw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Wy+NCeepWTSiKEZIMSlFrw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "baseScore": 2.5, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "WzKr+vOS+cHO5ydxI18BFQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "baseScore": 7.4, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "XOJZGmeZwsebobAglmEIzA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "XPV+5ujjQUNW+tos3Q+v/w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XbpXfbeApuDuIKvY0/qWiA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XkYYkW68UK2NwhLI/UmYUg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XygysGe2kdlyCRQHM1fu3w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.0, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XzpR/ASE/VqV+Ft/wiA6Qw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "Y/82v7jgmp9WbPyh6zXAqA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YNVn4/OBbQHajyVtshrL3Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "baseScore": 8.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "YOjk++xRTh9VXO273YBySg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YV4pdpWlOQp4ENY4WBgu+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "YY1AnmNdojeTQaO/z5gGTA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 3.7, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "YYbr54PEl4J1NET9C1dPhg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "YbAnIQEqWeedb46YJk3cBg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YiJlkUTKf0/7+ORZMmQ2cw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Yruwfu4Vkg/KNSmhqw2VEg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "ZE8z5pZigQ6zR3DrST6XmA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "ZRzqQ+u1wA21Iiq1JiWScw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "ZTGiJlkqcqrCLJSY/Sq8lA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "a1JZMpXS/ssjLYCl17uNJA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "a9FCHpokzVfpw+gdnrzSXg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "aVMgTmw8gvaYP/OjqlHeVA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "baseScore": 7.7, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "aetFzlYufXdv42s6KFBXcA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "avvi/YxG3J40ZK3NTLgmcQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "ayNNRQmygz9tBo/oxR437A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "b4sDCRZC0dyaz+kllMgRKQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "bLEcs4XYapNmeTM4WLeVAw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "d80wPIXiop25QcH362PUgw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dGtImtgXxemdBTM1vCCLUg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L", "baseScore": 4.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "dYe0cnQs909yjJScdhxi8g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "dYucp/SettSQd/Hpukj6pA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "dvRjQ6BpPMHoRj/7w9dv/g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "eKx2b/57ZENrxVKuRWfmwQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "eSKL36MlZ1HyqAeoxF6NSA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "ehV42Kf4mNxkwEnYSPYF5A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "f6JqroM9DAPFPzLvkr6TsA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fM/S1lXLzT3yP+sZqhNB0g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "fPSdx84mD5ZpVIqkzEY7lw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N", "baseScore": 5.7, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "fayrPya6DVXP9weWvA6obQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fpkJVe/KmtRv+bBXsYsIcg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "fvGjL9hw9hDQockMTb7lrA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fyxlf06S6rMafIj672gFrg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "gQZBNz/hUjPyqafsGVQi7g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "gbxzM63S/+/q05197cVzwA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N", "baseScore": 5.7, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "geTtkmTtPDxSAjfZEBGWfQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "gqNlp+zMbwHq1FhCyd5krQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "gqZgaapoEbnm+Oj7iPZ37w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "hJlWqZ7n1IINkFnSLUe61w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "hfBpyVezkUAf98QWnlvzIA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "iFFhT3GCX+mTkglBusKyXw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "iXEopm+7p5ZQvLickgqvJQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "icj6a8bc4dYK/DJNvkU0+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ieASPdYzGxWke8nZZhE02Q==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ilhK+Ap+h5mZVKmQX7nDwg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "jO9fUvpFi0R9/mJ1YH7KXA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "jT+SdCGpoEoaiFxD0YzhlA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "jh7m9hFQE/K2fRaz3f3VoQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jw1ZiDut5Ot+DyVFjCrixg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "k8qh5HUHIEX/Inga/xEVgA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "kKJCXd0zC8/mIMuSsDoNSw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "kZwQRex+JNO11iMZ0Kg+IQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "kiHW82C3wKDYOBbnq/LPIw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "kl+nHl+uiNLzyLIPmJZ+2A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "klDSadzoRr4q59QuvFGaTA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "baseScore": 8.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "l8OX/JvX/6Phr3whXXIPdg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "l9dHBEfcpD6dMVlWOwL4HA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "lek/1FI0HdClJgWDNVsHsw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "lyuzCm7wHQVS8pCLzKOsig==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "m0IJGRf61cMaVU+GJnWBLg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "baseScore": 10.0, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "m8lo1EAeizRLnboLT9DGmw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "mQtrNhzMQ9mAh/coURV/3g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mVDdLszud8eQGKbdS4PWJA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "mouoWVvs12H8FynnB5qIsQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "my/DHKGJeRxjSNNUPhqPsQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "n83jaRl/T6kiaoMyWtX8xw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "nhjv2yqEDuqmBmg1t/yG5g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "noXaVqkCbpzn51NS8fKFEA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "noylE2HydWlbvhrfwI8wdQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "npQpPXYG8xMJ1LRSVSnKGA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "nrNkqQpKDeKvEoEVMtGvmQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.7, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "oW1RQqehkPmMzMEQAvBytA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "ofnnqzvHUpmPXQD17CK0Og==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ogQLwI4CKSGkUta+rUUomw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "ok6DL7Sb+nmxetWVktjVwg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "pNyd3CZwI+UE1lrar0+Tbg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "pOPPyR+CIc4lpQu0LrmDeA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "pjhL5VIkXQnq+rpcwS7JRg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "q3ulWCbJWdmHCRfeXXzLMA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "qES6WE3Hn+2j01vEmBBKiQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qNuYRcgtGClAU0g3zKI5Dg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qWRIUBMC7Yu6aXYW5EzOcQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qXNASosSuCsudML1MqXPjw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "qld8Wk8WGHJZFjcPP6Ptwg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "qn7yHwg0TG0L9eYiAmbjIg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "rEd6JdG2xx5NZ9bcsFRNpw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rEg00U8+//igCt+0+QBUhA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rKaUBHYppDrz0hfvcwev7Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H", "baseScore": 9.0, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "rP7oa42+SZpvxen+n93BaQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rShXs/LMffX1AYFunGEpaw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rVgBV65FWtFg3jitEqotFA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rf7KrQE1JIHCxJHtGdy3MQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "rkTtYvrd12uyxklXyGzF1A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "s3LI+/HXTUE2MugpF0a37g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "sGPMVAq85tNcvWM0LZLajg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "sRVcQFAdq4Ll42smqacaCw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "sThg2GGoKqa1RTJ5skEJTA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "srdggAxrYxj8SIe8dBdTNA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "svSEG/XaetbIWOhLQcy0Rw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "t4oe6DBPNf5Ikk93RfTdig==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "t8NWvVlCIq8TSmV68diH3w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "tGsvzSy2YAolN7IIXG6tpA==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "tVlxIOZ6F6+EJvRQqpYx4Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "tlWVK61iOpKPkvmeShS9AQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uEggs7thHCRp4eZu5EDH0A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uFU7coNmhuYnfXDMEDZ5Wg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "uPjRNrHM6KmwqqGnGCODOw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "baseScore": 7.4, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "v+AawDOr4RSUljIzpyfKJg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "v15shMI69zvuf6oTbTQYrA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "v7w6RCU36McEvGLyy4Z/qA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "vJm7eeVZEbnxh/9fxMVxog==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "vLyqX/wwXw895kwHvWCMWw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "vrmMgxCMgT/Bjrct252HXA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "wNoACM7I52HsdbnfoTfqkQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "wNoWbGRqNSwxpxvQoLKucA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "wUhCCQ2TKmxA3z3g0s2FPg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "wjNYcQ4jin5xLZ9x3M9snA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "x3G/eMd1Z0D10r12N+9d3Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "x6UCsSnHrxwMwN3+lSw6Jg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "xCUiEQAH1lfhrKtUxQDIYA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "xLIujTim86EomaRofe4tDg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "xPWheycLeO7kiluEueY2Ow==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "xpe48bYc11r4l1Za0UMTJA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "xyXxPp8aZoIrfhSdoDZiRw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "yQIFYkzYJzgmJ2Nsgj7X6g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "yReQJ7USlKwxPIyVvEKPEQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "yfmRolXybbYkofU31txxnw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "yiTWIBfruE5rPxLBPqTezA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "yuFlxOGqQlDuMCywIIELNw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "yvPadVM0tnN/2SPeW4dXXg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "yzSKnt30J1hZQJNakZ51bw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zMV0VqePDk+l1ba2z8ocRA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "zXrrwuYD9wK+seRCGBDutA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zb5yy59CLP4WltyO2l3tFQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "zbffUiUdFeVmzp9ywA12fg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zk/ctmNzLQq2GXe3oAc76w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "zqKQG906L7J523hKE7PKKQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "zqSg2zVc3ATJedTq/O4UjQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "zu8rcc5+OA/x6/gr05p8LA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "baseScore": 4.8, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "zyvQuin4jXjJlAFXbw1hxA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ] } ] }, "PackageNotVulnerable": {} }