<?xml version="1.0" encoding="UTF-8"?>
  <testsuites tests="128" disabled="42" errors="0" failures="0" time="2055.496608436">
      <testsuite name="Build Pipeline E2E" package="/workspace/source/e2e-tests/tests/build" tests="128" disabled="0" skipped="42" errors="0" failures="0" time="2055.496608436" timestamp="2026-08-14T13:12:08">
          <properties>
              <property name="SuiteSucceeded" value="true"></property>
              <property name="SuiteHasProgrammaticFocus" value="false"></property>
              <property name="SpecialSuiteFailureReason" value=""></property>
              <property name="SuiteLabels" value="[]"></property>
              <property name="SuiteSemVerConstraints" value="[]"></property>
              <property name="SuiteComponentSemVerConstraints" value="[]"></property>
              <property name="RandomSeed" value="1786712907"></property>
              <property name="RandomizeAllSpecs" value="false"></property>
              <property name="LabelFilter" value="build-pipeline-e2e"></property>
              <property name="SemVerFilter" value=""></property>
              <property name="FocusStrings" value=""></property>
              <property name="SkipStrings" value=""></property>
              <property name="FocusFiles" value=""></property>
              <property name="SkipFiles" value=""></property>
              <property name="FailOnPending" value="false"></property>
              <property name="FailOnEmpty" value="true"></property>
              <property name="FailFast" value="false"></property>
              <property name="FlakeAttempts" value="0"></property>
              <property name="DryRun" value="false"></property>
              <property name="ParallelTotal" value="3"></property>
              <property name="OutputInterceptorMode" value="none"></property>
          </properties>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;from-scratch&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="31.85626922">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;from-scratch&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:12:08.29&#xA;Image repository for component component-from-scratch in namespace build-e2e-from-scratch do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: from-scratch&#xA;RUNNING SCENARIO: from-scratch&#xA;&lt; Exit [BeforeAll] scenario &#34;from-scratch&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:12:19.947 (11.657s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:12:19.947&#xA;PipelineRun has not been created yet for the component build-e2e-from-scratch/component-from-scratch&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:12:40.146 (20.199s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;from-scratch&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="480.194212689">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:12:40.147&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm found for Component build-e2e-from-scratch/component-from-scratch&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: ResolvingTaskRef&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Running&#xA;PipelineRun component-from-scratch-on-pull-request-4hznm reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:20:40.341 (8m0.194s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;from-scratch&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.193559786">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:20:40.342&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:20:41.536 (1.193s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;from-scratch&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.428141145">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:20:41.537&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:20:41.965 (428ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;from-scratch&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000461643">
              <skipped message="skipped - floating tag validation is not needed for: from-scratch"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:20:41.966&#xA;[SKIPPED] floating tag validation is not needed for: from-scratch&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:20:41.966&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:20:41.966 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;from-scratch&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.317092706">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:20:41.966&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:20:42.283 (317ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;from-scratch&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000563456">
              <skipped message="skipped - Hermetic build is not enabled, skipping the test"></skipped>
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:20:42.284&#xA;[SKIPPED] Hermetic build is not enabled, skipping the test&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:182 @ 08/14/26 13:20:42.284&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:20:42.284 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;from-scratch&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="1.021259561">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:20:42.285&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:20:42.285&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:20:42.285 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;from-scratch&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:20:42.286&#xA;&lt; Exit [AfterAll] scenario &#34;from-scratch&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:20:43.306 (1.021s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-cargo&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="33.102696071">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;prefetch-cargo&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:20:43.307&#xA;Image repository for component component-prefetch-cargo in namespace build-e2e-prefetch-cargo do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: prefetch-cargo&#xA;RUNNING SCENARIO: prefetch-cargo&#xA;&lt; Exit [BeforeAll] scenario &#34;prefetch-cargo&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:20:56.209 (12.902s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:20:56.209&#xA;PipelineRun has not been created yet for the component build-e2e-prefetch-cargo/component-prefetch-cargo&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:21:16.41 (20.201s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-cargo&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="360.193547392">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:21:16.411&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz found for Component build-e2e-prefetch-cargo/component-prefetch-cargo&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Running&#xA;PipelineRun component-prefetch-cargo-on-pull-request-llxxz reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:27:16.604 (6m0.193s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-cargo&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.190022234">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:27:16.605&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:27:17.795 (1.19s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-cargo&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.539353188">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:27:17.795&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:27:18.335 (539ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-cargo&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000330969">
              <skipped message="skipped - floating tag validation is not needed for: prefetch-cargo"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:27:18.335&#xA;[SKIPPED] floating tag validation is not needed for: prefetch-cargo&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:27:18.335&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:27:18.335 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-cargo&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.284414197">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:27:18.336&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:27:18.62 (284ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-cargo&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.386701529">
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:27:18.621&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:27:19.008 (387ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-cargo&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="2.439311798">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:27:19.008&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:27:19.008&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:27:19.008 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;prefetch-cargo&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:27:19.009&#xA;&lt; Exit [AfterAll] scenario &#34;prefetch-cargo&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:27:21.447 (2.439s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-gomod&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="33.337324895">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;prefetch-gomod&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:27:21.448&#xA;Image repository for component component-prefetch-gomod in namespace build-e2e-prefetch-gomod do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: prefetch-gomod&#xA;RUNNING SCENARIO: prefetch-gomod&#xA;&lt; Exit [BeforeAll] scenario &#34;prefetch-gomod&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:27:34.55 (13.102s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:27:34.55&#xA;PipelineRun has not been created yet for the component build-e2e-prefetch-gomod/component-prefetch-gomod&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:27:54.786 (20.235s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-gomod&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="240.192988508">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:27:54.786&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf found for Component build-e2e-prefetch-gomod/component-prefetch-gomod&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Running&#xA;PipelineRun component-prefetch-gomod-on-pull-request-k4wcf reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:31:54.979 (4m0.193s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-gomod&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.200862014">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:31:54.98&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:31:56.181 (1.201s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-gomod&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.574716883">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:31:56.181&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:31:56.756 (575ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-gomod&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000280488">
              <skipped message="skipped - floating tag validation is not needed for: prefetch-gomod"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:31:56.757&#xA;[SKIPPED] floating tag validation is not needed for: prefetch-gomod&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:31:56.757&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:31:56.757 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-gomod&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.298934404">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:31:56.757&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:31:57.056 (299ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-gomod&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.238345758">
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:31:57.057&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:31:57.295 (238ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-gomod&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="1.5330703890000001">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:31:57.296&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:31:57.296&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:31:57.296 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;prefetch-gomod&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:31:57.296&#xA;&lt; Exit [AfterAll] scenario &#34;prefetch-gomod&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:31:58.829 (1.533s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-rpm&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="33.846115857">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;prefetch-rpm&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:31:58.83&#xA;Image repository for component component-prefetch-rpm in namespace build-e2e-prefetch-rpm do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: prefetch-rpm&#xA;RUNNING SCENARIO: prefetch-rpm&#xA;&lt; Exit [BeforeAll] scenario &#34;prefetch-rpm&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:32:12.478 (13.648s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:32:12.478&#xA;PipelineRun has not been created yet for the component build-e2e-prefetch-rpm/component-prefetch-rpm&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:32:32.676 (20.197s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-rpm&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="240.322995545">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:32:32.676&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr found for Component build-e2e-prefetch-rpm/component-prefetch-rpm&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Running&#xA;PipelineRun component-prefetch-rpm-on-pull-request-9gtpr reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:36:32.999 (4m0.323s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-rpm&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.363192284">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:36:33&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:36:34.363 (1.363s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-rpm&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.611674442">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:36:34.364&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:36:34.975 (612ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-rpm&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000274338">
              <skipped message="skipped - floating tag validation is not needed for: prefetch-rpm"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:36:34.976&#xA;[SKIPPED] floating tag validation is not needed for: prefetch-rpm&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:36:34.976&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:36:34.976 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-rpm&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.444628606">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:36:34.977&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:36:35.421 (445ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-rpm&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.216702987">
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:36:35.422&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:36:35.639 (217ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-rpm&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="2.948328143">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:36:35.639&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:36:35.64&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:36:35.64 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;prefetch-rpm&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:36:35.64&#xA;&lt; Exit [AfterAll] scenario &#34;prefetch-rpm&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:36:38.588 (2.948s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-gitlab-basic-auth&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="31.93334411">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;sample-gitlab-basic-auth&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:36:38.589&#xA;Image repository for component component-sample-gitlab-basic-auth in namespace build-e2e-sample-gitlab-basic-auth do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: sample-gitlab-basic-auth&#xA;RUNNING SCENARIO: sample-gitlab-basic-auth&#xA;&lt; Exit [BeforeAll] scenario &#34;sample-gitlab-basic-auth&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:36:50.279 (11.69s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:36:50.279&#xA;PipelineRun has not been created yet for the component build-e2e-sample-gitlab-basic-auth/component-sample-gitlab-basic-auth&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:37:10.522 (20.243s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-gitlab-basic-auth&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="331.664622104">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:37:10.523&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-hbtx2 found for Component build-e2e-sample-gitlab-basic-auth/component-sample-gitlab-basic-auth&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-hbtx2 reason: Cancelled&#xA;attempt 1/3: PipelineRun &#34;component-sample-gitlab-basic-auth-on-pull-request-hbtx2&#34; failed: Cancelled: PipelineRun &#34;component-sample-gitlab-basic-auth-on-pull-request-hbtx2&#34; was cancelledNew PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth found after retrigger for component build-e2e-sample-gitlab-basic-auth/component-sample-gitlab-basic-auth&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth found for Component build-e2e-sample-gitlab-basic-auth/component-sample-gitlab-basic-auth&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Running&#xA;PipelineRun component-sample-gitlab-basic-auth-on-pull-request-5pwth reason: Succeeded&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:42:42.187 (5m31.665s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-gitlab-basic-auth&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.00033603">
              <skipped message="skipped - Skipping push Dockerfile to registry validation, it is not applicable here"></skipped>
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:42:42.188&#xA;[SKIPPED] Skipping push Dockerfile to registry validation, it is not applicable here&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:125 @ 08/14/26 13:42:42.188&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:42:42.188 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-gitlab-basic-auth&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.123984394">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:42:42.189&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:42:42.313 (124ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-gitlab-basic-auth&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.00033717">
              <skipped message="skipped - floating tag validation is not needed for: sample-gitlab-basic-auth"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:42:42.313&#xA;[SKIPPED] floating tag validation is not needed for: sample-gitlab-basic-auth&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:42:42.313&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:42:42.313 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-gitlab-basic-auth&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.304359813">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:42:42.314&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:42:42.618 (304ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-gitlab-basic-auth&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000278918">
              <skipped message="skipped - Hermetic build is not enabled, skipping the test"></skipped>
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:42:42.619&#xA;[SKIPPED] Hermetic build is not enabled, skipping the test&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:182 @ 08/14/26 13:42:42.619&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:42:42.619 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-gitlab-basic-auth&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="2.979797329">
              <skipped message="skipped - Not applicable, skiping source image validation for the scenario sample-gitlab-basic-auth"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:42:42.619&#xA;[SKIPPED] Not applicable, skiping source image validation for the scenario sample-gitlab-basic-auth&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:216 @ 08/14/26 13:42:42.62&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:42:42.62 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;sample-gitlab-basic-auth&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:42:42.62&#xA;&lt; Exit [AfterAll] scenario &#34;sample-gitlab-basic-auth&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:42:45.599 (2.979s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="33.430822209">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:42:45.6&#xA;Image repository for component component-sample-python-basic-oci-docker-build-oci-ta in namespace build-e2e-sample-python-basic-oci-docker-build-oci-ta do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: sample-python-basic-oci-docker-build-oci-ta&#xA;RUNNING SCENARIO: sample-python-basic-oci-docker-build-oci-ta&#xA;&lt; Exit [BeforeAll] scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:42:58.791 (13.191s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:42:58.791&#xA;PipelineRun has not been created yet for the component build-e2e-sample-python-basic-oci-docker-build-oci-ta/component-sample-python-basic-oci-docker-build-oci-ta&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:43:19.031 (20.24s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="180.18610391">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:43:19.032&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 found for Component build-e2e-sample-python-basic-oci-docker-build-oci-ta/component-sample-python-basic-oci-docker-build-oci-ta&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-oci-ta-on-pz8ds8 reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:46:19.218 (3m0.186s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.089700849">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:46:19.218&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:46:20.308 (1.09s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.407666735">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:46:20.309&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:46:20.716 (408ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.00030942">
              <skipped message="skipped - floating tag validation is not needed for: sample-python-basic-oci-docker-build-oci-ta"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:46:20.717&#xA;[SKIPPED] floating tag validation is not needed for: sample-python-basic-oci-docker-build-oci-ta&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:46:20.717&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:46:20.717 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.287586116">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:46:20.717&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:46:21.005 (287ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000286639">
              <skipped message="skipped - Hermetic build is not enabled, skipping the test"></skipped>
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:46:21.005&#xA;[SKIPPED] Hermetic build is not enabled, skipping the test&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:182 @ 08/14/26 13:46:21.006&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:46:21.006 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="2.7674634559999998">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:46:21.006&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:46:21.006&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:46:21.006 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:46:21.006&#xA;&lt; Exit [AfterAll] scenario &#34;sample-python-basic-oci-docker-build-oci-ta&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:46:23.774 (2.767s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;oci-archive&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="45.9977238">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;oci-archive&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:12:08.29&#xA;Image repository for component component-oci-archive in namespace build-e2e-oci-archive do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Image repository for component component-oci-archive in namespace build-e2e-oci-archive do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: oci-archive&#xA;RUNNING SCENARIO: oci-archive&#xA;&lt; Exit [BeforeAll] scenario &#34;oci-archive&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:12:34.056 (25.765s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:12:34.056&#xA;PipelineRun has not been created yet for the component build-e2e-oci-archive/component-oci-archive&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:12:54.288 (20.232s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;oci-archive&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="480.185398321">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:12:54.289&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd found for Component build-e2e-oci-archive/component-oci-archive&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: ResolvingTaskRef&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Running&#xA;PipelineRun component-oci-archive-on-pull-request-hkhsd reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:20:54.474 (8m0.185s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;oci-archive&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.088091761">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:20:54.475&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:20:55.563 (1.088s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;oci-archive&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.412189151">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:20:55.564&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:20:55.976 (412ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;oci-archive&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000490475">
              <skipped message="skipped - floating tag validation is not needed for: oci-archive"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:20:55.976&#xA;[SKIPPED] floating tag validation is not needed for: oci-archive&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:20:55.977&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:20:55.977 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;oci-archive&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.281744816">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:20:55.977&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:20:56.259 (282ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;oci-archive&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000291418">
              <skipped message="skipped - Hermetic build is not enabled, skipping the test"></skipped>
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:20:56.26&#xA;[SKIPPED] Hermetic build is not enabled, skipping the test&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:182 @ 08/14/26 13:20:56.26&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:20:56.26 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;oci-archive&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="2.202153634">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:20:56.26&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:20:56.26&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:20:56.26 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;oci-archive&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:20:56.26&#xA;&lt; Exit [AfterAll] scenario &#34;oci-archive&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:20:58.462 (2.202s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-generic&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="33.137203149">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;prefetch-generic&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:20:58.463&#xA;Image repository for component component-prefetch-generic in namespace build-e2e-prefetch-generic do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: prefetch-generic&#xA;RUNNING SCENARIO: prefetch-generic&#xA;&lt; Exit [BeforeAll] scenario &#34;prefetch-generic&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:21:11.407 (12.944s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:21:11.408&#xA;PipelineRun has not been created yet for the component build-e2e-prefetch-generic/component-prefetch-generic&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:21:31.601 (20.193s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-generic&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="420.187583613">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:21:31.601&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 found for Component build-e2e-prefetch-generic/component-prefetch-generic&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Running&#xA;PipelineRun component-prefetch-generic-on-pull-request-rpwd5 reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:28:31.789 (7m0.187s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-generic&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.2858198220000001">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:28:31.79&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:28:33.075 (1.286s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-generic&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.683954925">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:28:33.076&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:28:33.76 (684ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-generic&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.00033916">
              <skipped message="skipped - floating tag validation is not needed for: prefetch-generic"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:28:33.761&#xA;[SKIPPED] floating tag validation is not needed for: prefetch-generic&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:28:33.761&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:28:33.761 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-generic&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.296541856">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:28:33.761&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:28:34.058 (296ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-generic&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.335260566">
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:28:34.058&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:28:34.394 (335ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-generic&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="1.594373268">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:28:34.394&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:28:34.394&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:28:34.394 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;prefetch-generic&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:28:34.394&#xA;&lt; Exit [AfterAll] scenario &#34;prefetch-generic&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:28:35.988 (1.594s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-pip&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="34.741180504">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;prefetch-pip&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:28:35.989&#xA;Image repository for component component-prefetch-pip in namespace build-e2e-prefetch-pip do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: prefetch-pip&#xA;RUNNING SCENARIO: prefetch-pip&#xA;&lt; Exit [BeforeAll] scenario &#34;prefetch-pip&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:28:50.541 (14.551s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:28:50.541&#xA;PipelineRun has not been created yet for the component build-e2e-prefetch-pip/component-prefetch-pip&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:29:10.731 (20.189s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-pip&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="380.205589709">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:29:10.731&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 found for Component build-e2e-prefetch-pip/component-prefetch-pip&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Running&#xA;PipelineRun component-prefetch-pip-on-pull-request-xnhl4 reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:35:30.937 (6m20.205s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-pip&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.182866501">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:35:30.938&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:35:32.12 (1.183s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-pip&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.622502821">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:35:32.121&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:35:32.743 (622ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-pip&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.679044098">
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:35:32.744&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:35:33.423 (679ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-pip&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.400772094">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:35:33.424&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:35:33.825 (401ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-pip&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.385709362">
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:35:33.825&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:35:34.211 (386ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-pip&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="1.8798863749999999">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:35:34.212&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:35:34.212&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:35:34.212 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;prefetch-pip&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:35:34.212&#xA;&lt; Exit [AfterAll] scenario &#34;prefetch-pip&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:35:36.091 (1.879s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-modern&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="33.686061714">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;prefetch-yarn-modern&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:35:36.092&#xA;Image repository for component component-prefetch-yarn-modern in namespace build-e2e-prefetch-yarn-modern do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: prefetch-yarn-modern&#xA;RUNNING SCENARIO: prefetch-yarn-modern&#xA;&lt; Exit [BeforeAll] scenario &#34;prefetch-yarn-modern&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:35:49.571 (13.479s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:35:49.572&#xA;PipelineRun has not been created yet for the component build-e2e-prefetch-yarn-modern/component-prefetch-yarn-modern&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:36:09.778 (20.207s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-modern&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="200.204710421">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:36:09.779&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt found for Component build-e2e-prefetch-yarn-modern/component-prefetch-yarn-modern&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Running&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Running&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Running&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Running&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Running&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Running&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Running&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Running&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Running&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Running&#xA;PipelineRun component-prefetch-yarn-modern-on-pull-request-8nprt reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:39:29.984 (3m20.205s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-modern&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.051827171">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:39:29.984&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:39:31.036 (1.052s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-modern&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.568687918">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:39:31.041&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:39:31.609 (569ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-modern&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000585217">
              <skipped message="skipped - floating tag validation is not needed for: prefetch-yarn-modern"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:39:31.61&#xA;[SKIPPED] floating tag validation is not needed for: prefetch-yarn-modern&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:39:31.61&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:39:31.61 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-modern&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.342179424">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:39:31.611&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:39:31.953 (342ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-modern&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.201304747">
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:39:31.954&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:39:32.155 (201ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-modern&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="1.751587918">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:39:32.156&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:39:32.156&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:39:32.156 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;prefetch-yarn-modern&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:39:32.156&#xA;&lt; Exit [AfterAll] scenario &#34;prefetch-yarn-modern&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:39:33.907 (1.751s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-docker&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="31.730941045">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;sample-python-basic-docker&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:39:33.908&#xA;Image repository for component component-sample-python-basic-docker in namespace build-e2e-sample-python-basic-docker do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: sample-python-basic-docker&#xA;RUNNING SCENARIO: sample-python-basic-docker&#xA;&lt; Exit [BeforeAll] scenario &#34;sample-python-basic-docker&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:39:45.433 (11.525s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:39:45.433&#xA;PipelineRun has not been created yet for the component build-e2e-sample-python-basic-docker/component-sample-python-basic-docker&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:40:05.639 (20.206s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-docker&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="200.205723305">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:40:05.64&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h found for Component build-e2e-sample-python-basic-docker/component-sample-python-basic-docker&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: ResolvingTaskRef&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: Running&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: Running&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: Running&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: Running&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: Running&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: Running&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: Running&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: Running&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: Running&#xA;PipelineRun component-sample-python-basic-docker-on-pull-request-vp77h reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:43:25.845 (3m20.206s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-docker&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.204906643">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:43:25.846&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:43:27.051 (1.205s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-docker&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.545014705">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:43:27.052&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:43:27.596 (545ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-docker&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000300629">
              <skipped message="skipped - floating tag validation is not needed for: sample-python-basic-docker"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:43:27.597&#xA;[SKIPPED] floating tag validation is not needed for: sample-python-basic-docker&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:43:27.597&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:43:27.597 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-docker&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.325011494">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:43:27.598&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:43:27.923 (325ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-docker&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000305789">
              <skipped message="skipped - Hermetic build is not enabled, skipping the test"></skipped>
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:43:27.923&#xA;[SKIPPED] Hermetic build is not enabled, skipping the test&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:182 @ 08/14/26 13:43:27.923&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:43:27.923 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-docker&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="2.34300417">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:43:27.924&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:43:27.924&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:43:27.924 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;sample-python-basic-docker&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:43:27.924&#xA;&lt; Exit [AfterAll] scenario &#34;sample-python-basic-docker&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:43:30.267 (2.343s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-symlink&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="31.748379754">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;sample-python-basic-symlink&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:43:30.268&#xA;Image repository for component component-sample-python-basic-symlink in namespace build-e2e-sample-python-basic-symlink do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: sample-python-basic-symlink&#xA;RUNNING SCENARIO: sample-python-basic-symlink&#xA;&lt; Exit [BeforeAll] scenario &#34;sample-python-basic-symlink&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:43:41.81 (11.542s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:43:41.81&#xA;PipelineRun has not been created yet for the component build-e2e-sample-python-basic-symlink/component-sample-python-basic-symlink&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:44:02.016 (20.206s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-symlink&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="40.411198286">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:44:02.017&#xA;current pipelinerun reason: Running&#xA;current pipelinerun reason: Running&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:44:42.428 (40.411s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-symlink&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000299599">
              <skipped message="skipped - Skipping push Dockerfile to registry validation, it is not applicable here"></skipped>
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:44:42.429&#xA;[SKIPPED] Skipping push Dockerfile to registry validation, it is not applicable here&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:125 @ 08/14/26 13:44:42.429&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:44:42.429 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-symlink&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000256997">
              <skipped message="skipped - Skipping tekton task results validation, not applicable"></skipped>
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:44:42.43&#xA;[SKIPPED] Skipping tekton task results validation, not applicable&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:132 @ 08/14/26 13:44:42.43&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:44:42.43 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-symlink&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000178455">
              <skipped message="skipped - floating tag validation is not needed for: sample-python-basic-symlink"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:44:42.43&#xA;[SKIPPED] floating tag validation is not needed for: sample-python-basic-symlink&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:44:42.43&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:44:42.43 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-symlink&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000167305">
              <skipped message="skipped - mediaType validation is not required for scenario: sample-python-basic-symlink"></skipped>
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:44:42.431&#xA;[SKIPPED] mediaType validation is not required for scenario: sample-python-basic-symlink&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:155 @ 08/14/26 13:44:42.431&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:44:42.431 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-symlink&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000186446">
              <skipped message="skipped - Hermetic build is not enabled, skipping the test"></skipped>
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:44:42.431&#xA;[SKIPPED] Hermetic build is not enabled, skipping the test&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:182 @ 08/14/26 13:44:42.431&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:44:42.431 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-symlink&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="2.4173929960000002">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:44:42.432&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:44:42.432&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:44:42.432 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;sample-python-basic-symlink&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:44:42.432&#xA;&lt; Exit [AfterAll] scenario &#34;sample-python-basic-symlink&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:44:44.849 (2.417s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-bundler&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="53.569837239">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;prefetch-bundler&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:12:08.297&#xA;Image repository for component component-prefetch-bundler in namespace build-e2e-prefetch-bundler do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: prefetch-bundler&#xA;RUNNING SCENARIO: prefetch-bundler&#xA;&lt; Exit [BeforeAll] scenario &#34;prefetch-bundler&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:12:21.561 (13.264s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:12:21.561&#xA;PipelineRun has not been created yet for the component build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;PipelineRun has not been created yet for the component build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:13:01.867 (40.305s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-bundler&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="876.08386438">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:13:01.867&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p found for Component build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: PipelineRunStopping&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: PipelineRunStopping&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: PipelineRunStopping&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: PipelineRunStopping&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: PipelineRunStopping&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: PipelineRunStopping&#xA;PipelineRun component-prefetch-bundler-on-pull-request-ncd7p reason: Failed&#xA;attempt 1/3: PipelineRun &#34;component-prefetch-bundler-on-pull-request-ncd7p&#34; failed: &#xA; pod: component-prefetch-bundler-3cbad5cedc1d47511a48f3c5ad3737bd-pod | init container: prepare&#xA;2026/08/14 13:18:18 Entrypoint initialization&#xA;&#xA; pod: component-prefetch-bundler-3cbad5cedc1d47511a48f3c5ad3737bd-pod | init container: place-scripts&#xA;2026/08/14 13:18:26 Decoded script /tekton/scripts/script-0-zb22m&#xA;2026/08/14 13:18:26 Decoded script /tekton/scripts/script-1-qncnh&#xA;2026/08/14 13:18:26 Decoded script /tekton/scripts/script-2-g6f89&#xA;2026/08/14 13:18:26 Decoded script /tekton/scripts/script-3-jw898&#xA;2026/08/14 13:18:26 Decoded script /tekton/scripts/script-4-cwk7r&#xA;2026/08/14 13:18:26 Decoded script /tekton/scripts/script-5-rvt8d&#xA;&#xA;pod: component-prefetch-bundler-3cbad5cedc1d47511a48f3c5ad3737bd-pod | container step-introspect: &#xA;Artifact type will be determined by introspection.&#xA;Checking the media type of the OCI artifact...&#xA;[retry] executing: skopeo inspect --raw --retry-times 3 docker://quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c&#xA;The media type of the OCI artifact is application/vnd.docker.distribution.manifest.v2+json.&#xA;Looking for image labels that indicate this might be an operator bundle...&#xA;[retry] executing: skopeo inspect --retry-times 3 docker://quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c&#xA;Found 0 matching labels.&#xA;Expecting 3 or more to identify this image as an operator bundle.&#xA;Introspection concludes that this artifact is of type &#34;application&#34;.&#xA;&#xA;pod: component-prefetch-bundler-3cbad5cedc1d47511a48f3c5ad3737bd-pod | container step-generate-container-auth: &#xA;Selecting auth for quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c&#xA;Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;Auth json written to &#34;/auth/auth.json&#34;.&#xA;&#xA;pod: component-prefetch-bundler-3cbad5cedc1d47511a48f3c5ad3737bd-pod | container step-set-skip-for-bundles: &#xA;2026/08/14 13:19:52 INFO Step was skipped due to when expressions were evaluated to false.&#xA;&#xA;pod: component-prefetch-bundler-3cbad5cedc1d47511a48f3c5ad3737bd-pod | container step-app-check: &#xA;time=&#34;2026-08-14T13:19:52Z&#34; level=info msg=&#34;certification library version&#34; version=&#34;1.19.2 &lt;commit: ffbc84882f216fca874feeaa44ce3df95ee5f07a&gt;&#34;&#xA;time=&#34;2026-08-14T13:19:53Z&#34; level=info msg=&#34;running checks for quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c for platform amd64&#34;&#xA;time=&#34;2026-08-14T13:19:53Z&#34; level=info msg=&#34;target image&#34; image=&#34;quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c&#34;&#xA;Error: failed to extract tarball: failed to drain io reader: unexpected EOF&#xA;2026/08/14 13:20:00 failed to extract tarball: failed to drain io reader: unexpected EOF&#xA;&#xA;pod: component-prefetch-bundler-3cbad5cedc1d47511a48f3c5ad3737bd-pod | container step-app-set-outcome: &#xA;2026/08/14 13:20:01 Skipping step because a previous step failed&#xA;&#xA;pod: component-prefetch-bundler-3cbad5cedc1d47511a48f3c5ad3737bd-pod | container step-final-outcome: &#xA;2026/08/14 13:20:01 Skipping step because a previous step failed&#xA;&#xA; pod: component-prefetch-bundler-cde8149fb34562fffbab5b6dbd1243e3-pod | init container: prepare&#xA;2026/08/14 13:19:21 Entrypoint initialization&#xA;&#xA; pod: component-prefetch-bundler-cde8149fb34562fffbab5b6dbd1243e3-pod | init container: place-scripts&#xA;2026/08/14 13:19:29 Decoded script /tekton/scripts/script-0-4tpf7&#xA;2026/08/14 13:19:29 Decoded script /tekton/scripts/script-1-hsccx&#xA;&#xA;pod: component-prefetch-bundler-cde8149fb34562fffbab5b6dbd1243e3-pod | container step-extract-and-scan-image: &#xA;Starting clamd ...&#xA;clamd is ready!&#xA;Detecting artifact type for quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler@sha256:1806486990f86738e26ea4751f25cd961b841d64af0fffe4c91affa4f2d116f9.&#xA;Detected container image. Processing image manifests.&#xA;Running &#34;oc image extract&#34; on image of arch amd64&#xA;Scanning image for arch amd64. This operation may take a while.&#xA;&#xA;----------- SCAN SUMMARY -----------&#xA;Infected files: 0&#xA;Time: 25.596 sec (0 m 25 s)&#xA;Start Date: 2026:08:14 13:20:04&#xA;End Date:   2026:08:14 13:20:30&#xA;Executed-on: Scan was executed on clamsdcan version - ClamAV 1.4.6/28092/Fri Aug 14 06:27:02 2026 Database version: 28092&#xA;[&#xA;&#x9;{&#xA;&#x9;&#x9;&#34;filename&#34;: &#34;/work/logs/clamscan-result-log-amd64.json&#34;,&#xA;&#x9;&#x9;&#34;namespace&#34;: &#34;required_checks&#34;,&#xA;&#x9;&#x9;&#34;successes&#34;: 2&#xA;&#x9;}&#xA;]&#xA;{&#34;timestamp&#34;:&#34;1786713630&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;timestamp&#34;:&#34;1786713630&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;timestamp&#34;:&#34;1786713630&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;image&#34;: {&#34;pullspec&#34;: &#34;quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c&#34;, &#34;digests&#34;: [&#34;sha256:1806486990f86738e26ea4751f25cd961b841d64af0fffe4c91affa4f2d116f9&#34;]}}&#xA;&#xA;pod: component-prefetch-bundler-cde8149fb34562fffbab5b6dbd1243e3-pod | container step-upload: &#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;Attaching to quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c&#xA;[retry] executing: oras attach --no-tty --registry-config /home/taskuser/auth.json --artifact-type application/vnd.clamav quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c@sha256:1806486990f86738e26ea4751f25cd961b841d64af0fffe4c91affa4f2d116f9 clamscan-result-amd64.log:text/vnd.clamav clamscan-ec-test-amd64.json:application/vnd.konflux.test_output+json&#xA;Preparing clamscan-result-amd64.log&#xA;Preparing clamscan-ec-test-amd64.json&#xA;Exists    44136fa355b3 application/vnd.oci.empty.v1+json&#xA;Uploading b5dd9eb661cf clamscan-ec-test-amd64.json&#xA;Uploading ac99e6fb81d5 clamscan-result-amd64.log&#xA;Uploaded  b5dd9eb661cf clamscan-ec-test-amd64.json&#xA;Uploaded  ac99e6fb81d5 clamscan-result-amd64.log&#xA;Uploading ae6b3afcd5a2 application/vnd.oci.image.manifest.v1+json&#xA;Uploaded  ae6b3afcd5a2 application/vnd.oci.image.manifest.v1+json&#xA;Attached to [registry] quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c@sha256:1806486990f86738e26ea4751f25cd961b841d64af0fffe4c91affa4f2d116f9&#xA;Digest: sha256:ae6b3afcd5a2e48cf41acd823b0e1be77100860336a23a30a683e4fe9fef7935&#xA;&#xA; pod: component-prefetch-bundler-on-pull-request-ncd7p-apply-tags-pod | init container: prepare&#xA;2026/08/14 13:18:20 Entrypoint initialization&#xA;&#xA;pod: component-prefetch-bundler-on-pull-request-ncd7p-apply-tags-pod | container step-apply-additional-tags: &#xA;time=&#34;2026-08-14T13:18:43Z&#34; level=info msg=&#34;[param] image-url: quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c&#34;&#xA;time=&#34;2026-08-14T13:18:43Z&#34; level=info msg=&#34;[param] digest: sha256:1806486990f86738e26ea4751f25cd961b841d64af0fffe4c91affa4f2d116f9&#34;&#xA;time=&#34;2026-08-14T13:18:43Z&#34; level=info msg=&#34;[param] tags-from-image-label: konflux.additional-tags&#34;&#xA;time=&#34;2026-08-14T13:18:45Z&#34; level=warning msg=&#34;No tags given in &#39;konflux.additional-tags&#39; image label&#34;&#xA;{&#34;tags&#34;:null}&#xA; pod: component-prefetch-bundler-on-pull-request-ncd7p-clair-scan-pod | init container: prepare&#xA;2026/08/14 13:18:16 Entrypoint initialization&#xA;&#xA; pod: component-prefetch-bundler-on-pull-request-ncd7p-clair-scan-pod | init container: place-scripts&#xA;2026/08/14 13:18:20 Decoded script /tekton/scripts/script-0-trr58&#xA;2026/08/14 13:18:20 Decoded script /tekton/scripts/script-1-w4vfq&#xA;2026/08/14 13:18:20 Decoded script /tekton/scripts/script-2-8hw2z&#xA;2026/08/14 13:18:20 Decoded script /tekton/scripts/script-3-kkz4g&#xA;&#xA;pod: component-prefetch-bundler-on-pull-request-ncd7p-clair-scan-pod | container step-get-image-manifests: &#xA;Inspecting raw image manifest quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler@sha256:1806486990f86738e26ea4751f25cd961b841d64af0fffe4c91affa4f2d116f9.&#xA;Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;&#xA;pod: component-prefetch-bundler-on-pull-request-ncd7p-clair-scan-pod | container step-get-vulnerabilities: &#xA;Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;Running clair-action on amd64 image manifest...&#xA;2026/08/14 13:20:11 INFO matchers created matcher.java-maven=https://pkg.go.dev/github.com/quay/claircore/java matcher.photon=https://pkg.go.dev/github.com/quay/claircore/photon matcher.rhel-container-matcher=https://pkg.go.dev/github.com/quay/claircore/rhel/rhcc matcher.suse=https://pkg.go.dev/github.com/quay/claircore/suse matcher.rhel=https://pkg.go.dev/github.com/quay/claircore/rhel matcher.alpine-matcher=https://pkg.go.dev/github.com/quay/claircore/alpine matcher.ruby-gem=https://pkg.go.dev/github.com/quay/claircore/ruby matcher.ubuntu-matcher=https://pkg.go.dev/github.com/quay/claircore/ubuntu matcher.aws-matcher=https://pkg.go.dev/github.com/quay/claircore/aws matcher.debian-matcher=https://pkg.go.dev/github.com/quay/claircore/debian matcher.oracle=https://pkg.go.dev/github.com/quay/claircore/oracle matcher.python=https://pkg.go.dev/github.com/quay/claircore/python matcher.gobin=https://pkg.go.dev/github.com/quay/claircore/gobin&#xA;2026/08/14 13:20:11 INFO vex factory configured base_url=https://security.access.redhat.com/data/csaf/v2/vex/ compressed_file_timeout=2m0s&#xA;2026/08/14 13:20:11 INFO libvuln initialized&#xA;2026/08/14 13:20:11 INFO registered configured scanners&#xA;2026/08/14 13:20:11 INFO constructing&#xA;2026/08/14 13:20:11 INFO index request start&#xA;2026/08/14 13:20:11 INFO starting scan&#xA;2026/08/14 13:20:11 INFO manifest to be scanned&#xA;2026/08/14 13:20:11 INFO layers fetch start&#xA;2026/08/14 13:20:19 INFO layers fetch success&#xA;2026/08/14 13:20:19 INFO layers fetch done&#xA;2026/08/14 13:20:19 INFO layers scan start&#xA;2026/08/14 13:20:21 WARN rpm source packages always record 0 epoch; this may cause incorrect matching see-also=&#34;https://github.com/rpm-software-management/rpm/issues/2796 https://github.com/rpm-software-management/rpm/discussions/3703 https://github.com/rpm-software-management/rpm/pull/3755&#34;&#xA;2026/08/14 13:20:26 INFO layers scan done&#xA;2026/08/14 13:20:26 INFO starting index manifest&#xA;2026/08/14 13:20:26 INFO finishing scan&#xA;2026/08/14 13:20:26 INFO manifest successfully scanned&#xA;2026/08/14 13:20:26 INFO index request done&#xA;{&#xA;  &#34;manifest_hash&#34;: &#34;sha256:1806486990f86738e26ea4751f25cd961b841d64af0fffe4c91affa4f2d116f9&#34;,&#xA;  &#34;packages&#34;: {&#xA;    &#34;+8b2rLdXTkZ4Ylx7vWU2tQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+8b2rLdXTkZ4Ylx7vWU2tQ==&#34;,&#xA;      &#34;name&#34;: &#34;systemd-libs&#34;,&#xA;      &#34;version&#34;: &#34;252-55.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd&#34;,&#xA;        &#34;version&#34;: &#34;252-55.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;+A7/nzEXX3Q/xJZ50VMnlQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+A7/nzEXX3Q/xJZ50VMnlQ==&#34;,&#xA;      &#34;name&#34;: &#34;libidn2&#34;,&#xA;      &#34;version&#34;: &#34;2.3.0-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libidn2&#34;,&#xA;        &#34;version&#34;: &#34;2.3.0-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;+B22ALb6YCnXu+3s6afaLg==&#34;: {&#xA;      &#34;id&#34;: &#34;+B22ALb6YCnXu+3s6afaLg==&#34;,&#xA;      &#34;name&#34;: &#34;python3-decorator&#34;,&#xA;      &#34;version&#34;: &#34;4.4.2-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-decorator&#34;,&#xA;        &#34;version&#34;: &#34;4.4.2-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;+ELGclZlzVhkDoWJwZc9OA==&#34;: {&#xA;      &#34;id&#34;: &#34;+ELGclZlzVhkDoWJwZc9OA==&#34;,&#xA;      &#34;name&#34;: &#34;libtirpc&#34;,&#xA;      &#34;version&#34;: &#34;1.3.3-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtirpc&#34;,&#xA;        &#34;version&#34;: &#34;1.3.3-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;+HmNQdmjJTL5gC4nHHd6rw==&#34;: {&#xA;      &#34;id&#34;: &#34;+HmNQdmjJTL5gC4nHHd6rw==&#34;,&#xA;      &#34;name&#34;: &#34;kernel-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;1.0-14.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;kernel-srpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;1.0-14.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;+X1MdmtPTbyDb/wq7joJhA==&#34;: {&#xA;      &#34;id&#34;: &#34;+X1MdmtPTbyDb/wq7joJhA==&#34;,&#xA;      &#34;name&#34;: &#34;libtool-ltdl&#34;,&#xA;      &#34;version&#34;: &#34;2.4.6-46.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtool&#34;,&#xA;        &#34;version&#34;: &#34;2.4.6-46.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;+bwl6UbMaWOBWdHNekJsEw==&#34;: {&#xA;      &#34;id&#34;: &#34;+bwl6UbMaWOBWdHNekJsEw==&#34;,&#xA;      &#34;name&#34;: &#34;coreutils-single&#34;,&#xA;      &#34;version&#34;: &#34;8.32-39.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;coreutils&#34;,&#xA;        &#34;version&#34;: &#34;8.32-39.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;+kdviPHeaPmwEsPQK85KjQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+kdviPHeaPmwEsPQK85KjQ==&#34;,&#xA;      &#34;name&#34;: &#34;openssl&#34;,&#xA;      &#34;version&#34;: &#34;1:3.5.1-4.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;3.5.1-4.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;+v/DtyduRnxay/g57zCBpw==&#34;: {&#xA;      &#34;id&#34;: &#34;+v/DtyduRnxay/g57zCBpw==&#34;,&#xA;      &#34;name&#34;: &#34;python3-librepo&#34;,&#xA;      &#34;version&#34;: &#34;1.14.5-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;librepo&#34;,&#xA;        &#34;version&#34;: &#34;1.14.5-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;+y+as2YNBEvOddTPxl73DA==&#34;: {&#xA;      &#34;id&#34;: &#34;+y+as2YNBEvOddTPxl73DA==&#34;,&#xA;      &#34;name&#34;: &#34;source-highlight&#34;,&#xA;      &#34;version&#34;: &#34;3.1.9-12.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;source-highlight&#34;,&#xA;        &#34;version&#34;: &#34;3.1.9-12.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;/Bb6eVO+je9kbuIGTvt6Ww==&#34;: {&#xA;      &#34;id&#34;: &#34;/Bb6eVO+je9kbuIGTvt6Ww==&#34;,&#xA;      &#34;name&#34;: &#34;ncurses&#34;,&#xA;      &#34;version&#34;: &#34;6.2-12.20210508.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ncurses&#34;,&#xA;        &#34;version&#34;: &#34;6.2-12.20210508.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;/L1kFEoHZTukrNTCQLypFQ==&#34;: {&#xA;      &#34;id&#34;: &#34;/L1kFEoHZTukrNTCQLypFQ==&#34;,&#xA;      &#34;name&#34;: &#34;xz-libs&#34;,&#xA;      &#34;version&#34;: &#34;5.2.5-8.el9_0&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;xz&#34;,&#xA;        &#34;version&#34;: &#34;5.2.5-8.el9_0&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;/O7rOBo1qRMFm3q3Kf3mEw==&#34;: {&#xA;      &#34;id&#34;: &#34;/O7rOBo1qRMFm3q3Kf3mEw==&#34;,&#xA;      &#34;name&#34;: &#34;libselinux&#34;,&#xA;      &#34;version&#34;: &#34;3.6-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libselinux&#34;,&#xA;        &#34;version&#34;: &#34;3.6-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;/THiuz93dsCZJETS3A4Xtw==&#34;: {&#xA;      &#34;id&#34;: &#34;/THiuz93dsCZJETS3A4Xtw==&#34;,&#xA;      &#34;name&#34;: &#34;libcom_err&#34;,&#xA;      &#34;version&#34;: &#34;1.46.5-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;e2fsprogs&#34;,&#xA;        &#34;version&#34;: &#34;1.46.5-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;/XUXPfxfCal3j0ldx+af3A==&#34;: {&#xA;      &#34;id&#34;: &#34;/XUXPfxfCal3j0ldx+af3A==&#34;,&#xA;      &#34;name&#34;: &#34;bzip2&#34;,&#xA;      &#34;version&#34;: &#34;1.0.8-10.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;bzip2&#34;,&#xA;        &#34;version&#34;: &#34;1.0.8-10.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;/h/TBQhfoSMCmey5oN87jA==&#34;: {&#xA;      &#34;id&#34;: &#34;/h/TBQhfoSMCmey5oN87jA==&#34;,&#xA;      &#34;name&#34;: &#34;libsolv&#34;,&#xA;      &#34;version&#34;: &#34;0.7.24-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libsolv&#34;,&#xA;        &#34;version&#34;: &#34;0.7.24-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;/l8wc0qlQdZdqgMIy+AX4w==&#34;: {&#xA;      &#34;id&#34;: &#34;/l8wc0qlQdZdqgMIy+AX4w==&#34;,&#xA;      &#34;name&#34;: &#34;gcc-c++&#34;,&#xA;      &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gcc&#34;,&#xA;        &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;/oIjTiZph8FPjlWNL5s82w==&#34;: {&#xA;      &#34;id&#34;: &#34;/oIjTiZph8FPjlWNL5s82w==&#34;,&#xA;      &#34;name&#34;: &#34;environment-modules&#34;,&#xA;      &#34;version&#34;: &#34;5.3.0-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;environment-modules&#34;,&#xA;        &#34;version&#34;: &#34;5.3.0-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;/oLe91LMLglvpqo76adFGw==&#34;: {&#xA;      &#34;id&#34;: &#34;/oLe91LMLglvpqo76adFGw==&#34;,&#xA;      &#34;name&#34;: &#34;dwz&#34;,&#xA;      &#34;version&#34;: &#34;0.16-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dwz&#34;,&#xA;        &#34;version&#34;: &#34;0.16-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;/ub7EE8Da46T0x7lRdlVJg==&#34;: {&#xA;      &#34;id&#34;: &#34;/ub7EE8Da46T0x7lRdlVJg==&#34;,&#xA;      &#34;name&#34;: &#34;libsmartcols&#34;,&#xA;      &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;0133y/ZC+9hrvuSzgka7cw==&#34;: {&#xA;      &#34;id&#34;: &#34;0133y/ZC+9hrvuSzgka7cw==&#34;,&#xA;      &#34;name&#34;: &#34;man-db&#34;,&#xA;      &#34;version&#34;: &#34;2.9.3-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;man-db&#34;,&#xA;        &#34;version&#34;: &#34;2.9.3-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;04b0yaCHYk5DVzS89hVjvw==&#34;: {&#xA;      &#34;id&#34;: &#34;04b0yaCHYk5DVzS89hVjvw==&#34;,&#xA;      &#34;name&#34;: &#34;libeconf&#34;,&#xA;      &#34;version&#34;: &#34;0.4.1-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libeconf&#34;,&#xA;        &#34;version&#34;: &#34;0.4.1-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;09fH92fqoWDOaYEpwQ9p2g==&#34;: {&#xA;      &#34;id&#34;: &#34;09fH92fqoWDOaYEpwQ9p2g==&#34;,&#xA;      &#34;name&#34;: &#34;ed&#34;,&#xA;      &#34;version&#34;: &#34;1.14.2-12.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ed&#34;,&#xA;        &#34;version&#34;: &#34;1.14.2-12.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;09r8DbZFJmI1tQW/a+ZlWQ==&#34;: {&#xA;      &#34;id&#34;: &#34;09r8DbZFJmI1tQW/a+ZlWQ==&#34;,&#xA;      &#34;name&#34;: &#34;shadow-utils&#34;,&#xA;      &#34;version&#34;: &#34;2:4.9-15.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;shadow-utils&#34;,&#xA;        &#34;version&#34;: &#34;4.9-15.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;0NHnPl3pNsT2FH8oGcfyEw==&#34;: {&#xA;      &#34;id&#34;: &#34;0NHnPl3pNsT2FH8oGcfyEw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-libs&#34;,&#xA;      &#34;version&#34;: &#34;4:5.32.1-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;0fqyUk3Q4wjepXsEzVTbuQ==&#34;: {&#xA;      &#34;id&#34;: &#34;0fqyUk3Q4wjepXsEzVTbuQ==&#34;,&#xA;      &#34;name&#34;: &#34;libuser&#34;,&#xA;      &#34;version&#34;: &#34;0.63-17.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libuser&#34;,&#xA;        &#34;version&#34;: &#34;0.63-17.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;0gNpYdx7/dHkr8z85zHOSg==&#34;: {&#xA;      &#34;id&#34;: &#34;0gNpYdx7/dHkr8z85zHOSg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-File-stat&#34;,&#xA;      &#34;version&#34;: &#34;1.09-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;0kf4C6OH9tp4+UaKjumyEg==&#34;: {&#xA;      &#34;id&#34;: &#34;0kf4C6OH9tp4+UaKjumyEg==&#34;,&#xA;      &#34;name&#34;: &#34;llvm-filesystem&#34;,&#xA;      &#34;version&#34;: &#34;20.1.8-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;llvm&#34;,&#xA;        &#34;version&#34;: &#34;20.1.8-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;1+Lg0PO3SMtKcC7avbi64w==&#34;: {&#xA;      &#34;id&#34;: &#34;1+Lg0PO3SMtKcC7avbi64w==&#34;,&#xA;      &#34;name&#34;: &#34;xorg-x11-proto-devel&#34;,&#xA;      &#34;version&#34;: &#34;2024.1-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;xorg-x11-proto-devel&#34;,&#xA;        &#34;version&#34;: &#34;2024.1-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;13LJ8VSSR7Q+r1oKIOzegw==&#34;: {&#xA;      &#34;id&#34;: &#34;13LJ8VSSR7Q+r1oKIOzegw==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/s2i-core&#34;,&#xA;      &#34;version&#34;: &#34;1764601991&#34;,&#xA;      &#34;kind&#34;: &#34;ancestry&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;BLrNfmomqpFT8qecLZ99jQ==&#34;,&#xA;        &#34;name&#34;: &#34;ubi9/s2i-core&#34;,&#xA;        &#34;version&#34;: &#34;1764601991&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;source&#34;: {&#xA;          &#34;id&#34;: &#34;&#34;,&#xA;          &#34;name&#34;: &#34;&#34;,&#xA;          &#34;version&#34;: &#34;&#34;,&#xA;          &#34;normalized_version&#34;: &#34;&#34;,&#xA;          &#34;cpe&#34;: &#34;&#34;,&#xA;          &#34;detector&#34;: null&#xA;        },&#xA;        &#34;normalized_version&#34;: &#34;unmatchable:1764601991.0.0.0.0.0.0.0.0.0&#34;,&#xA;        &#34;arch&#34;: &#34;x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764601991.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;1XXuvf69/0I2dNHaU2UndQ==&#34;: {&#xA;      &#34;id&#34;: &#34;1XXuvf69/0I2dNHaU2UndQ==&#34;,&#xA;      &#34;name&#34;: &#34;patch&#34;,&#xA;      &#34;version&#34;: &#34;2.7.6-16.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;patch&#34;,&#xA;        &#34;version&#34;: &#34;2.7.6-16.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;1Xbb0MgMTadhlE/gdXAC9g==&#34;: {&#xA;      &#34;id&#34;: &#34;1Xbb0MgMTadhlE/gdXAC9g==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/ruby-33&#34;,&#xA;      &#34;version&#34;: &#34;1764649613&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;rOo0eaSDbJ9TZ3lifnsvSQ==&#34;,&#xA;        &#34;name&#34;: &#34;ubi9/ruby-33&#34;,&#xA;        &#34;version&#34;: &#34;1764649613&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;source&#34;: {&#xA;          &#34;id&#34;: &#34;&#34;,&#xA;          &#34;name&#34;: &#34;&#34;,&#xA;          &#34;version&#34;: &#34;&#34;,&#xA;          &#34;normalized_version&#34;: &#34;&#34;,&#xA;          &#34;cpe&#34;: &#34;&#34;,&#xA;          &#34;detector&#34;: null&#xA;        },&#xA;        &#34;normalized_version&#34;: &#34;unmatchable:1764649613.0.0.0.0.0.0.0.0.0&#34;,&#xA;        &#34;arch&#34;: &#34;x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764649613.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;1atoBfoH0mJ0bCpetQ7/0g==&#34;: {&#xA;      &#34;id&#34;: &#34;1atoBfoH0mJ0bCpetQ7/0g==&#34;,&#xA;      &#34;name&#34;: &#34;file-libs&#34;,&#xA;      &#34;version&#34;: &#34;5.39-16.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;file&#34;,&#xA;        &#34;version&#34;: &#34;5.39-16.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;1c78imYwGnF54k326pUleA==&#34;: {&#xA;      &#34;id&#34;: &#34;1c78imYwGnF54k326pUleA==&#34;,&#xA;      &#34;name&#34;: &#34;kernel-headers&#34;,&#xA;      &#34;version&#34;: &#34;5.14.0-611.11.1.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;kernel&#34;,&#xA;        &#34;version&#34;: &#34;5.14.0-611.11.1.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;1h2bWnAaSbAMrDYM8V/8sw==&#34;: {&#xA;      &#34;id&#34;: &#34;1h2bWnAaSbAMrDYM8V/8sw==&#34;,&#xA;      &#34;name&#34;: &#34;pcre-utf16&#34;,&#xA;      &#34;version&#34;: &#34;8.44-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre&#34;,&#xA;        &#34;version&#34;: &#34;8.44-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;1m9sKqHTfU4F/K4fidg9cg==&#34;: {&#xA;      &#34;id&#34;: &#34;1m9sKqHTfU4F/K4fidg9cg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Exporter&#34;,&#xA;      &#34;version&#34;: &#34;5.74-461.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Exporter&#34;,&#xA;        &#34;version&#34;: &#34;5.74-461.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;1p1wTPVFlokLdC9/X3ksGg==&#34;: {&#xA;      &#34;id&#34;: &#34;1p1wTPVFlokLdC9/X3ksGg==&#34;,&#xA;      &#34;name&#34;: &#34;expat&#34;,&#xA;      &#34;version&#34;: &#34;2.5.0-5.el9_7.1&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;2.5.0-5.el9_7.1&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;1pWwHIWE2UYOVNkFfcPZhQ==&#34;: {&#xA;      &#34;id&#34;: &#34;1pWwHIWE2UYOVNkFfcPZhQ==&#34;,&#xA;      &#34;name&#34;: &#34;sqlite&#34;,&#xA;      &#34;version&#34;: &#34;3.34.1-9.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;sqlite&#34;,&#xA;        &#34;version&#34;: &#34;3.34.1-9.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;1pqtMQqVpCMzDCv8KXVyuA==&#34;: {&#xA;      &#34;id&#34;: &#34;1pqtMQqVpCMzDCv8KXVyuA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Class-Struct&#34;,&#xA;      &#34;version&#34;: &#34;0.66-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;20ttMIcZDyeRDwHLGLpY5g==&#34;: {&#xA;      &#34;id&#34;: &#34;20ttMIcZDyeRDwHLGLpY5g==&#34;,&#xA;      &#34;name&#34;: &#34;python3-libs&#34;,&#xA;      &#34;version&#34;: &#34;3.9.23-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;3.9.23-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;2QUKRSh7NN4cTp6+OOEm8w==&#34;: {&#xA;      &#34;id&#34;: &#34;2QUKRSh7NN4cTp6+OOEm8w==&#34;,&#xA;      &#34;name&#34;: &#34;rsync&#34;,&#xA;      &#34;version&#34;: &#34;3.2.5-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;3.2.5-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;2gCbp4kt+cF44NF/LqukDg==&#34;: {&#xA;      &#34;id&#34;: &#34;2gCbp4kt+cF44NF/LqukDg==&#34;,&#xA;      &#34;name&#34;: &#34;pcre2-syntax&#34;,&#xA;      &#34;version&#34;: &#34;10.40-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre2&#34;,&#xA;        &#34;version&#34;: &#34;10.40-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;2hVeGisxeIl5ZCVdBXxWKg==&#34;: {&#xA;      &#34;id&#34;: &#34;2hVeGisxeIl5ZCVdBXxWKg==&#34;,&#xA;      &#34;name&#34;: &#34;virt-what&#34;,&#xA;      &#34;version&#34;: &#34;1.27-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;virt-what&#34;,&#xA;        &#34;version&#34;: &#34;1.27-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;2tnKv76FL7fQoypGU9dvWQ==&#34;: {&#xA;      &#34;id&#34;: &#34;2tnKv76FL7fQoypGU9dvWQ==&#34;,&#xA;      &#34;name&#34;: &#34;binutils-gold&#34;,&#xA;      &#34;version&#34;: &#34;2.35.2-67.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;2.35.2-67.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;2w8qE/d9mqIY/9+1qBBrPg==&#34;: {&#xA;      &#34;id&#34;: &#34;2w8qE/d9mqIY/9+1qBBrPg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-IO-Socket-IP&#34;,&#xA;      &#34;version&#34;: &#34;0.41-5.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-IO-Socket-IP&#34;,&#xA;        &#34;version&#34;: &#34;0.41-5.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;35MvZs/A5NUjD+xZ1Vlnyw==&#34;: {&#xA;      &#34;id&#34;: &#34;35MvZs/A5NUjD+xZ1Vlnyw==&#34;,&#xA;      &#34;name&#34;: &#34;libpkgconf&#34;,&#xA;      &#34;version&#34;: &#34;1.7.3-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pkgconf&#34;,&#xA;        &#34;version&#34;: &#34;1.7.3-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;38FdUixzs3eDg/NPZRiJIA==&#34;: {&#xA;      &#34;id&#34;: &#34;38FdUixzs3eDg/NPZRiJIA==&#34;,&#xA;      &#34;name&#34;: &#34;glibc-langpack-en&#34;,&#xA;      &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;3YAw8el/3rSN8/26QNTqsA==&#34;: {&#xA;      &#34;id&#34;: &#34;3YAw8el/3rSN8/26QNTqsA==&#34;,&#xA;      &#34;name&#34;: &#34;pixman&#34;,&#xA;      &#34;version&#34;: &#34;0.40.0-6.el9_3&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pixman&#34;,&#xA;        &#34;version&#34;: &#34;0.40.0-6.el9_3&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;3adzKM06LvCWYFXCgwdnjA==&#34;: {&#xA;      &#34;id&#34;: &#34;3adzKM06LvCWYFXCgwdnjA==&#34;,&#xA;      &#34;name&#34;: &#34;efi-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;6-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;efi-rpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;6-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;3kiQXJjCV5HlO0qf9OFzoQ==&#34;: {&#xA;      &#34;id&#34;: &#34;3kiQXJjCV5HlO0qf9OFzoQ==&#34;,&#xA;      &#34;name&#34;: &#34;perl-File-Find&#34;,&#xA;      &#34;version&#34;: &#34;1.37-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;3nZGfOwzhExfw1oIgyJNUg==&#34;: {&#xA;      &#34;id&#34;: &#34;3nZGfOwzhExfw1oIgyJNUg==&#34;,&#xA;      &#34;name&#34;: &#34;util-linux-core&#34;,&#xA;      &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;4DALE9qlRQsocTmGTN3jhg==&#34;: {&#xA;      &#34;id&#34;: &#34;4DALE9qlRQsocTmGTN3jhg==&#34;,&#xA;      &#34;name&#34;: &#34;glibc-locale-source&#34;,&#xA;      &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;4Kw/w2gH7CYCOCv19cdYYA==&#34;: {&#xA;      &#34;id&#34;: &#34;4Kw/w2gH7CYCOCv19cdYYA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-File-Path&#34;,&#xA;      &#34;version&#34;: &#34;2.18-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-File-Path&#34;,&#xA;        &#34;version&#34;: &#34;2.18-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;4U8NwfIL6oZ9HtlVrK/5EQ==&#34;: {&#xA;      &#34;id&#34;: &#34;4U8NwfIL6oZ9HtlVrK/5EQ==&#34;,&#xA;      &#34;name&#34;: &#34;gettext&#34;,&#xA;      &#34;version&#34;: &#34;0.21-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gettext&#34;,&#xA;        &#34;version&#34;: &#34;0.21-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;4xm12R/wZXmG2Cs/ve2Zjw==&#34;: {&#xA;      &#34;id&#34;: &#34;4xm12R/wZXmG2Cs/ve2Zjw==&#34;,&#xA;      &#34;name&#34;: &#34;cpp&#34;,&#xA;      &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gcc&#34;,&#xA;        &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;5+tHFkkNi+1rUDSrmgYdkw==&#34;: {&#xA;      &#34;id&#34;: &#34;5+tHFkkNi+1rUDSrmgYdkw==&#34;,&#xA;      &#34;name&#34;: &#34;p11-kit-trust&#34;,&#xA;      &#34;version&#34;: &#34;0.25.3-3.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;p11-kit&#34;,&#xA;        &#34;version&#34;: &#34;0.25.3-3.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;582nBqlxZXz0sTRmkFvU4Q==&#34;: {&#xA;      &#34;id&#34;: &#34;582nBqlxZXz0sTRmkFvU4Q==&#34;,&#xA;      &#34;name&#34;: &#34;libxcb&#34;,&#xA;      &#34;version&#34;: &#34;1.13.1-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxcb&#34;,&#xA;        &#34;version&#34;: &#34;1.13.1-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;5GtYmv+rWUY9Nq0zLzVwuQ==&#34;: {&#xA;      &#34;id&#34;: &#34;5GtYmv+rWUY9Nq0zLzVwuQ==&#34;,&#xA;      &#34;name&#34;: &#34;automake&#34;,&#xA;      &#34;version&#34;: &#34;1.16.2-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;automake&#34;,&#xA;        &#34;version&#34;: &#34;1.16.2-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;5JAFUJWmy04+T6x2oJw2jg==&#34;: {&#xA;      &#34;id&#34;: &#34;5JAFUJWmy04+T6x2oJw2jg==&#34;,&#xA;      &#34;name&#34;: &#34;libxml2&#34;,&#xA;      &#34;version&#34;: &#34;2.9.13-14.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;2.9.13-14.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;5hkeK2sS5i1OF8czY7eD+A==&#34;: {&#xA;      &#34;id&#34;: &#34;5hkeK2sS5i1OF8czY7eD+A==&#34;,&#xA;      &#34;name&#34;: &#34;perl-HTTP-Tiny&#34;,&#xA;      &#34;version&#34;: &#34;0.076-462.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-HTTP-Tiny&#34;,&#xA;        &#34;version&#34;: &#34;0.076-462.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;5w6Z1FeiHTUU7Pzs/S0tow==&#34;: {&#xA;      &#34;id&#34;: &#34;5w6Z1FeiHTUU7Pzs/S0tow==&#34;,&#xA;      &#34;name&#34;: &#34;rspec-mocks&#34;,&#xA;      &#34;version&#34;: &#34;3.13.7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;5x6eb7pZ/EuGII0pLw9fTg==&#34;: {&#xA;      &#34;id&#34;: &#34;5x6eb7pZ/EuGII0pLw9fTg==&#34;,&#xA;      &#34;name&#34;: &#34;libffi-devel&#34;,&#xA;      &#34;version&#34;: &#34;3.4.2-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libffi&#34;,&#xA;        &#34;version&#34;: &#34;3.4.2-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;60b1mOIk+ncF/benyKWfug==&#34;: {&#xA;      &#34;id&#34;: &#34;60b1mOIk+ncF/benyKWfug==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Data-Dumper&#34;,&#xA;      &#34;version&#34;: &#34;2.174-462.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Data-Dumper&#34;,&#xA;        &#34;version&#34;: &#34;2.174-462.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;60pEkQUMtqjJkDtrBnZkZw==&#34;: {&#xA;      &#34;id&#34;: &#34;60pEkQUMtqjJkDtrBnZkZw==&#34;,&#xA;      &#34;name&#34;: &#34;rpm-build-libs&#34;,&#xA;      &#34;version&#34;: &#34;4.16.1.3-39.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rpm&#34;,&#xA;        &#34;version&#34;: &#34;4.16.1.3-39.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;65vQ2fJTp0DlFVHdZmyGLw==&#34;: {&#xA;      &#34;id&#34;: &#34;65vQ2fJTp0DlFVHdZmyGLw==&#34;,&#xA;      &#34;name&#34;: &#34;rpm-sign-libs&#34;,&#xA;      &#34;version&#34;: &#34;4.16.1.3-39.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rpm&#34;,&#xA;        &#34;version&#34;: &#34;4.16.1.3-39.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;6AYt+NWt55432RGa/HxiQg==&#34;: {&#xA;      &#34;id&#34;: &#34;6AYt+NWt55432RGa/HxiQg==&#34;,&#xA;      &#34;name&#34;: &#34;libXt&#34;,&#xA;      &#34;version&#34;: &#34;1.2.0-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libXt&#34;,&#xA;        &#34;version&#34;: &#34;1.2.0-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;6G1ytjIPgX0NNsVwuPQKkQ==&#34;: {&#xA;      &#34;id&#34;: &#34;6G1ytjIPgX0NNsVwuPQKkQ==&#34;,&#xA;      &#34;name&#34;: &#34;python3-gpg&#34;,&#xA;      &#34;version&#34;: &#34;1.15.1-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gpgme&#34;,&#xA;        &#34;version&#34;: &#34;1.15.1-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;6HUC1/dPziZpbtWEymw0nQ==&#34;: {&#xA;      &#34;id&#34;: &#34;6HUC1/dPziZpbtWEymw0nQ==&#34;,&#xA;      &#34;name&#34;: &#34;gzip&#34;,&#xA;      &#34;version&#34;: &#34;1.12-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gzip&#34;,&#xA;        &#34;version&#34;: &#34;1.12-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;6MFxZDjn6ZxVQspQib4VSA==&#34;: {&#xA;      &#34;id&#34;: &#34;6MFxZDjn6ZxVQspQib4VSA==&#34;,&#xA;      &#34;name&#34;: &#34;libXau&#34;,&#xA;      &#34;version&#34;: &#34;1.0.9-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libXau&#34;,&#xA;        &#34;version&#34;: &#34;1.0.9-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;6yTvnPP57NJPXUaaMuHa5Q==&#34;: {&#xA;      &#34;id&#34;: &#34;6yTvnPP57NJPXUaaMuHa5Q==&#34;,&#xA;      &#34;name&#34;: &#34;libdnf&#34;,&#xA;      &#34;version&#34;: &#34;0.69.0-16.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libdnf&#34;,&#xA;        &#34;version&#34;: &#34;0.69.0-16.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;7/k2KO9ZYtIX1WvnibuCwg==&#34;: {&#xA;      &#34;id&#34;: &#34;7/k2KO9ZYtIX1WvnibuCwg==&#34;,&#xA;      &#34;name&#34;: &#34;procps-ng&#34;,&#xA;      &#34;version&#34;: &#34;3.3.17-14.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;procps-ng&#34;,&#xA;        &#34;version&#34;: &#34;3.3.17-14.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;71E7ojyMFQ1Uwy0VMr2WLg==&#34;: {&#xA;      &#34;id&#34;: &#34;71E7ojyMFQ1Uwy0VMr2WLg==&#34;,&#xA;      &#34;name&#34;: &#34;rpm&#34;,&#xA;      &#34;version&#34;: &#34;4.16.1.3-39.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rpm&#34;,&#xA;        &#34;version&#34;: &#34;4.16.1.3-39.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;7NGPdoQ8CufgoRI2a0XI0g==&#34;: {&#xA;      &#34;id&#34;: &#34;7NGPdoQ8CufgoRI2a0XI0g==&#34;,&#xA;      &#34;name&#34;: &#34;perl-File-Compare&#34;,&#xA;      &#34;version&#34;: &#34;1.100.600-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;7cpIREEQnkaI7dbmWgmrvg==&#34;: {&#xA;      &#34;id&#34;: &#34;7cpIREEQnkaI7dbmWgmrvg==&#34;,&#xA;      &#34;name&#34;: &#34;gdbm-libs&#34;,&#xA;      &#34;version&#34;: &#34;1:1.23-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gdbm&#34;,&#xA;        &#34;version&#34;: &#34;1.23-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;7mDaaxs3ev+uNEDYC97U3Q==&#34;: {&#xA;      &#34;id&#34;: &#34;7mDaaxs3ev+uNEDYC97U3Q==&#34;,&#xA;      &#34;name&#34;: &#34;zlib&#34;,&#xA;      &#34;version&#34;: &#34;1.2.11-40.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;zlib&#34;,&#xA;        &#34;version&#34;: &#34;1.2.11-40.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;7oPP0/pHHdyRIJK6pYsCbQ==&#34;: {&#xA;      &#34;id&#34;: &#34;7oPP0/pHHdyRIJK6pYsCbQ==&#34;,&#xA;      &#34;name&#34;: &#34;python3&#34;,&#xA;      &#34;version&#34;: &#34;3.9.23-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;3.9.23-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;7qAMBOvJ2FYxpK9n05pI7Q==&#34;: {&#xA;      &#34;id&#34;: &#34;7qAMBOvJ2FYxpK9n05pI7Q==&#34;,&#xA;      &#34;name&#34;: &#34;libpng&#34;,&#xA;      &#34;version&#34;: &#34;2:1.6.37-12.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;1.6.37-12.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;7ra56f21gLrcSpBD8a9+NQ==&#34;: {&#xA;      &#34;id&#34;: &#34;7ra56f21gLrcSpBD8a9+NQ==&#34;,&#xA;      &#34;name&#34;: &#34;libmount&#34;,&#xA;      &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;7yB5oIQve4tWIMlUmHbdQQ==&#34;: {&#xA;      &#34;id&#34;: &#34;7yB5oIQve4tWIMlUmHbdQQ==&#34;,&#xA;      &#34;name&#34;: &#34;graphite2&#34;,&#xA;      &#34;version&#34;: &#34;1.3.14-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;graphite2&#34;,&#xA;        &#34;version&#34;: &#34;1.3.14-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;8+AT+dHyoFXmtWYeClg3hQ==&#34;: {&#xA;      &#34;id&#34;: &#34;8+AT+dHyoFXmtWYeClg3hQ==&#34;,&#xA;      &#34;name&#34;: &#34;libmnl&#34;,&#xA;      &#34;version&#34;: &#34;1.0.4-16.el9_4&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libmnl&#34;,&#xA;        &#34;version&#34;: &#34;1.0.4-16.el9_4&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;8/+OIixLXu+fX/6UoQwl/g==&#34;: {&#xA;      &#34;id&#34;: &#34;8/+OIixLXu+fX/6UoQwl/g==&#34;,&#xA;      &#34;name&#34;: &#34;go-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;3.6.0-12.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;go-rpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;3.6.0-12.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;87VUAbsTn2cSvq70x9SIKw==&#34;: {&#xA;      &#34;id&#34;: &#34;87VUAbsTn2cSvq70x9SIKw==&#34;,&#xA;      &#34;name&#34;: &#34;rubygem-io-console&#34;,&#xA;      &#34;version&#34;: &#34;0.7.1-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;88jYB91M4ddvxo2XjMJKmQ==&#34;: {&#xA;      &#34;id&#34;: &#34;88jYB91M4ddvxo2XjMJKmQ==&#34;,&#xA;      &#34;name&#34;: &#34;libmpc&#34;,&#xA;      &#34;version&#34;: &#34;1.2.1-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libmpc&#34;,&#xA;        &#34;version&#34;: &#34;1.2.1-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;8Al1Y3mQILwPqoFjfjIK0Q==&#34;: {&#xA;      &#34;id&#34;: &#34;8Al1Y3mQILwPqoFjfjIK0Q==&#34;,&#xA;      &#34;name&#34;: &#34;python3-setuptools-wheel&#34;,&#xA;      &#34;version&#34;: &#34;53.0.0-15.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-setuptools&#34;,&#xA;        &#34;version&#34;: &#34;53.0.0-15.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;8OE8ax/E0UXByEoVMTfkbA==&#34;: {&#xA;      &#34;id&#34;: &#34;8OE8ax/E0UXByEoVMTfkbA==&#34;,&#xA;      &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;      &#34;version&#34;: &#34;1:3.5.1-4.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;3.5.1-4.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;8dKij0lKhp8eGM5ynaMPfg==&#34;: {&#xA;      &#34;id&#34;: &#34;8dKij0lKhp8eGM5ynaMPfg==&#34;,&#xA;      &#34;name&#34;: &#34;glibc-minimal-langpack&#34;,&#xA;      &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;8gpmX0NZa9MMhcqi6FUGtg==&#34;: {&#xA;      &#34;id&#34;: &#34;8gpmX0NZa9MMhcqi6FUGtg==&#34;,&#xA;      &#34;name&#34;: &#34;python3-gobject-base&#34;,&#xA;      &#34;version&#34;: &#34;3.40.1-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pygobject3&#34;,&#xA;        &#34;version&#34;: &#34;3.40.1-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;8k+Ulo3wv2SSKo3DSJNJ6A==&#34;: {&#xA;      &#34;id&#34;: &#34;8k+Ulo3wv2SSKo3DSJNJ6A==&#34;,&#xA;      &#34;name&#34;: &#34;kmod-libs&#34;,&#xA;      &#34;version&#34;: &#34;28-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;kmod&#34;,&#xA;        &#34;version&#34;: &#34;28-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;8n6bVUPPsV3vtnz+vLHqKQ==&#34;: {&#xA;      &#34;id&#34;: &#34;8n6bVUPPsV3vtnz+vLHqKQ==&#34;,&#xA;      &#34;name&#34;: &#34;pam&#34;,&#xA;      &#34;version&#34;: &#34;1.5.1-26.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pam&#34;,&#xA;        &#34;version&#34;: &#34;1.5.1-26.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;8uME+PFu6p/OAD7q+ZTVLw==&#34;: {&#xA;      &#34;id&#34;: &#34;8uME+PFu6p/OAD7q+ZTVLw==&#34;,&#xA;      &#34;name&#34;: &#34;p11-kit&#34;,&#xA;      &#34;version&#34;: &#34;0.25.3-3.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;p11-kit&#34;,&#xA;        &#34;version&#34;: &#34;0.25.3-3.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;8uNlRHm24HlCfj4vRuzAgA==&#34;: {&#xA;      &#34;id&#34;: &#34;8uNlRHm24HlCfj4vRuzAgA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-if&#34;,&#xA;      &#34;version&#34;: &#34;0.60.800-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;9HjCH3SeUwgItfYZysNlOw==&#34;: {&#xA;      &#34;id&#34;: &#34;9HjCH3SeUwgItfYZysNlOw==&#34;,&#xA;      &#34;name&#34;: &#34;mariadb-connector-c-config&#34;,&#xA;      &#34;version&#34;: &#34;3.2.6-1.el9_0&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;mariadb-connector-c&#34;,&#xA;        &#34;version&#34;: &#34;3.2.6-1.el9_0&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;9bMXqD09C2r4s8P+HNy2uw==&#34;: {&#xA;      &#34;id&#34;: &#34;9bMXqD09C2r4s8P+HNy2uw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Pod-Perldoc&#34;,&#xA;      &#34;version&#34;: &#34;3.28.01-461.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Pod-Perldoc&#34;,&#xA;        &#34;version&#34;: &#34;3.28.01-461.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;9olIUlLHZMdoUMju+8diyQ==&#34;: {&#xA;      &#34;id&#34;: &#34;9olIUlLHZMdoUMju+8diyQ==&#34;,&#xA;      &#34;name&#34;: &#34;filesystem&#34;,&#xA;      &#34;version&#34;: &#34;3.16-5.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;filesystem&#34;,&#xA;        &#34;version&#34;: &#34;3.16-5.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;A5zg77FwqyQ7YbgSi5bkFw==&#34;: {&#xA;      &#34;id&#34;: &#34;A5zg77FwqyQ7YbgSi5bkFw==&#34;,&#xA;      &#34;name&#34;: &#34;libxslt-devel&#34;,&#xA;      &#34;version&#34;: &#34;1.1.34-13.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxslt&#34;,&#xA;        &#34;version&#34;: &#34;1.1.34-13.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ACNA1cjsRpihwLsZYxMiYQ==&#34;: {&#xA;      &#34;id&#34;: &#34;ACNA1cjsRpihwLsZYxMiYQ==&#34;,&#xA;      &#34;name&#34;: &#34;libXrender&#34;,&#xA;      &#34;version&#34;: &#34;0.9.10-16.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libXrender&#34;,&#xA;        &#34;version&#34;: &#34;0.9.10-16.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;AMvlCR3g+vHIXnbjgXeX2Q==&#34;: {&#xA;      &#34;id&#34;: &#34;AMvlCR3g+vHIXnbjgXeX2Q==&#34;,&#xA;      &#34;name&#34;: &#34;redhat-rpm-config&#34;,&#xA;      &#34;version&#34;: &#34;210-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;redhat-rpm-config&#34;,&#xA;        &#34;version&#34;: &#34;210-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;AUjudWCWcMUZtLYqynIMkg==&#34;: {&#xA;      &#34;id&#34;: &#34;AUjudWCWcMUZtLYqynIMkg==&#34;,&#xA;      &#34;name&#34;: &#34;tpm2-tss&#34;,&#xA;      &#34;version&#34;: &#34;3.2.3-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tpm2-tss&#34;,&#xA;        &#34;version&#34;: &#34;3.2.3-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;AbW1lRpGUjSEKNnr/Toz6A==&#34;: {&#xA;      &#34;id&#34;: &#34;AbW1lRpGUjSEKNnr/Toz6A==&#34;,&#xA;      &#34;name&#34;: &#34;jbigkit-libs&#34;,&#xA;      &#34;version&#34;: &#34;2.1-23.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;jbigkit&#34;,&#xA;        &#34;version&#34;: &#34;2.1-23.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;At9otkYcx2c7gDG/+qxMog==&#34;: {&#xA;      &#34;id&#34;: &#34;At9otkYcx2c7gDG/+qxMog==&#34;,&#xA;      &#34;name&#34;: &#34;libxml2-devel&#34;,&#xA;      &#34;version&#34;: &#34;2.9.13-14.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;2.9.13-14.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;BIzbOPagaosMprtM0oW/UQ==&#34;: {&#xA;      &#34;id&#34;: &#34;BIzbOPagaosMprtM0oW/UQ==&#34;,&#xA;      &#34;name&#34;: &#34;git-core-doc&#34;,&#xA;      &#34;version&#34;: &#34;2.47.3-1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;git&#34;,&#xA;        &#34;version&#34;: &#34;2.47.3-1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;BLrNfmomqpFT8qecLZ99jQ==&#34;: {&#xA;      &#34;id&#34;: &#34;BLrNfmomqpFT8qecLZ99jQ==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/s2i-core&#34;,&#xA;      &#34;version&#34;: &#34;1764601991&#34;,&#xA;      &#34;kind&#34;: &#34;source&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764601991.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;BQhiFmX4hLYteW4oRCLTSA==&#34;: {&#xA;      &#34;id&#34;: &#34;BQhiFmX4hLYteW4oRCLTSA==&#34;,&#xA;      &#34;name&#34;: &#34;libassuan&#34;,&#xA;      &#34;version&#34;: &#34;2.5.5-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libassuan&#34;,&#xA;        &#34;version&#34;: &#34;2.5.5-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;BRLVvSCW1qZQlEQR2x48fQ==&#34;: {&#xA;      &#34;id&#34;: &#34;BRLVvSCW1qZQlEQR2x48fQ==&#34;,&#xA;      &#34;name&#34;: &#34;gobject-introspection&#34;,&#xA;      &#34;version&#34;: &#34;1.68.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gobject-introspection&#34;,&#xA;        &#34;version&#34;: &#34;1.68.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;BUmLEOIviku9guiDM/J5qA==&#34;: {&#xA;      &#34;id&#34;: &#34;BUmLEOIviku9guiDM/J5qA==&#34;,&#xA;      &#34;name&#34;: &#34;libcurl-minimal&#34;,&#xA;      &#34;version&#34;: &#34;7.76.1-34.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;7.76.1-34.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Be3u3fxCSx0yV9rW5tn7+A==&#34;: {&#xA;      &#34;id&#34;: &#34;Be3u3fxCSx0yV9rW5tn7+A==&#34;,&#xA;      &#34;name&#34;: &#34;harfbuzz-icu&#34;,&#xA;      &#34;version&#34;: &#34;2.7.4-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;harfbuzz&#34;,&#xA;        &#34;version&#34;: &#34;2.7.4-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;CM/XLOAV8nEwvYEgfvOluA==&#34;: {&#xA;      &#34;id&#34;: &#34;CM/XLOAV8nEwvYEgfvOluA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Net-SSLeay&#34;,&#xA;      &#34;version&#34;: &#34;1.94-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Net-SSLeay&#34;,&#xA;        &#34;version&#34;: &#34;1.94-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;CQ7LW8sdHcbka0B3IpMM1Q==&#34;: {&#xA;      &#34;id&#34;: &#34;CQ7LW8sdHcbka0B3IpMM1Q==&#34;,&#xA;      &#34;name&#34;: &#34;which&#34;,&#xA;      &#34;version&#34;: &#34;2.21-30.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;which&#34;,&#xA;        &#34;version&#34;: &#34;2.21-30.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;CS6z0/SKwjMOr6VBFQ1+lw==&#34;: {&#xA;      &#34;id&#34;: &#34;CS6z0/SKwjMOr6VBFQ1+lw==&#34;,&#xA;      &#34;name&#34;: &#34;findutils&#34;,&#xA;      &#34;version&#34;: &#34;1:4.8.0-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;findutils&#34;,&#xA;        &#34;version&#34;: &#34;4.8.0-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;CfMo51dlSGLRWNluoKfMUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;CfMo51dlSGLRWNluoKfMUQ==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Scalar-List-Utils&#34;,&#xA;      &#34;version&#34;: &#34;4:1.56-462.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Scalar-List-Utils&#34;,&#xA;        &#34;version&#34;: &#34;1.56-462.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Cn4UOizx3r/8sEEZ0cgGfw==&#34;: {&#xA;      &#34;id&#34;: &#34;Cn4UOizx3r/8sEEZ0cgGfw==&#34;,&#xA;      &#34;name&#34;: &#34;libgomp&#34;,&#xA;      &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gcc&#34;,&#xA;        &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;CpfomSYboaXPZ9yn9NgGgw==&#34;: {&#xA;      &#34;id&#34;: &#34;CpfomSYboaXPZ9yn9NgGgw==&#34;,&#xA;      &#34;name&#34;: &#34;krb5-libs&#34;,&#xA;      &#34;version&#34;: &#34;1.21.1-8.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;krb5&#34;,&#xA;        &#34;version&#34;: &#34;1.21.1-8.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Cwut2mrMMUaIvKenvO1qWw==&#34;: {&#xA;      &#34;id&#34;: &#34;Cwut2mrMMUaIvKenvO1qWw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Socket&#34;,&#xA;      &#34;version&#34;: &#34;4:2.031-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Socket&#34;,&#xA;        &#34;version&#34;: &#34;2.031-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;CyeMFBrESWOU4r5NgnAVEQ==&#34;: {&#xA;      &#34;id&#34;: &#34;CyeMFBrESWOU4r5NgnAVEQ==&#34;,&#xA;      &#34;name&#34;: &#34;cmake-filesystem&#34;,&#xA;      &#34;version&#34;: &#34;3.26.5-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;cmake&#34;,&#xA;        &#34;version&#34;: &#34;3.26.5-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;D3RCrUIdQ+uwLTm+GGcqSA==&#34;: {&#xA;      &#34;id&#34;: &#34;D3RCrUIdQ+uwLTm+GGcqSA==&#34;,&#xA;      &#34;name&#34;: &#34;autoconf&#34;,&#xA;      &#34;version&#34;: &#34;2.69-41.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;autoconf&#34;,&#xA;        &#34;version&#34;: &#34;2.69-41.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;D5m7YK6SRxMXWJzbEMw9qw==&#34;: {&#xA;      &#34;id&#34;: &#34;D5m7YK6SRxMXWJzbEMw9qw==&#34;,&#xA;      &#34;name&#34;: &#34;pyproject-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;1.16.2-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pyproject-rpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;1.16.2-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;DK0d2bPQCX0xz6Lec7u1cg==&#34;: {&#xA;      &#34;id&#34;: &#34;DK0d2bPQCX0xz6Lec7u1cg==&#34;,&#xA;      &#34;name&#34;: &#34;info&#34;,&#xA;      &#34;version&#34;: &#34;6.7-15.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;texinfo&#34;,&#xA;        &#34;version&#34;: &#34;6.7-15.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;DNyIkrd4IXePRueLDNc6ZA==&#34;: {&#xA;      &#34;id&#34;: &#34;DNyIkrd4IXePRueLDNc6ZA==&#34;,&#xA;      &#34;name&#34;: &#34;libXpm&#34;,&#xA;      &#34;version&#34;: &#34;3.5.13-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libXpm&#34;,&#xA;        &#34;version&#34;: &#34;3.5.13-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;DVT5EsNYhhc4TADNn+PvwA==&#34;: {&#xA;      &#34;id&#34;: &#34;DVT5EsNYhhc4TADNn+PvwA==&#34;,&#xA;      &#34;name&#34;: &#34;rootfiles&#34;,&#xA;      &#34;version&#34;: &#34;8.1-35.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rootfiles&#34;,&#xA;        &#34;version&#34;: &#34;8.1-35.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;DVWG3mWD7odZzCgFCUPZPw==&#34;: {&#xA;      &#34;id&#34;: &#34;DVWG3mWD7odZzCgFCUPZPw==&#34;,&#xA;      &#34;name&#34;: &#34;pkgconf-pkg-config&#34;,&#xA;      &#34;version&#34;: &#34;1.7.3-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pkgconf&#34;,&#xA;        &#34;version&#34;: &#34;1.7.3-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;DXPX19bdN5nJbVwnxKFlOA==&#34;: {&#xA;      &#34;id&#34;: &#34;DXPX19bdN5nJbVwnxKFlOA==&#34;,&#xA;      &#34;name&#34;: &#34;brotli&#34;,&#xA;      &#34;version&#34;: &#34;1.0.9-7.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;brotli&#34;,&#xA;        &#34;version&#34;: &#34;1.0.9-7.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;DrLq8qfU1bfE8o8AfdvkrQ==&#34;: {&#xA;      &#34;id&#34;: &#34;DrLq8qfU1bfE8o8AfdvkrQ==&#34;,&#xA;      &#34;name&#34;: &#34;libverto&#34;,&#xA;      &#34;version&#34;: &#34;0.3.2-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libverto&#34;,&#xA;        &#34;version&#34;: &#34;0.3.2-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;DyVc00dL0fB/TbUtdImPIA==&#34;: {&#xA;      &#34;id&#34;: &#34;DyVc00dL0fB/TbUtdImPIA==&#34;,&#xA;      &#34;name&#34;: &#34;libedit&#34;,&#xA;      &#34;version&#34;: &#34;3.1-38.20210216cvs.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libedit&#34;,&#xA;        &#34;version&#34;: &#34;3.1-38.20210216cvs.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;EEcEMKhGMvXAfnMhboIpqw==&#34;: {&#xA;      &#34;id&#34;: &#34;EEcEMKhGMvXAfnMhboIpqw==&#34;,&#xA;      &#34;name&#34;: &#34;publicsuffix-list-dafsa&#34;,&#xA;      &#34;version&#34;: &#34;20210518-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;publicsuffix-list&#34;,&#xA;        &#34;version&#34;: &#34;20210518-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;EhaFwS5l8+kj0ips0KX28g==&#34;: {&#xA;      &#34;id&#34;: &#34;EhaFwS5l8+kj0ips0KX28g==&#34;,&#xA;      &#34;name&#34;: &#34;vim-minimal&#34;,&#xA;      &#34;version&#34;: &#34;2:8.2.2637-23.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;8.2.2637-23.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;EjrCko4EN35q3gOrHdIWjw==&#34;: {&#xA;      &#34;id&#34;: &#34;EjrCko4EN35q3gOrHdIWjw==&#34;,&#xA;      &#34;name&#34;: &#34;rpm-libs&#34;,&#xA;      &#34;version&#34;: &#34;4.16.1.3-39.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rpm&#34;,&#xA;        &#34;version&#34;: &#34;4.16.1.3-39.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Ep9qjtRg5KBEw8RkogSOKQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Ep9qjtRg5KBEw8RkogSOKQ==&#34;,&#xA;      &#34;name&#34;: &#34;python3-dateutil&#34;,&#xA;      &#34;version&#34;: &#34;1:2.9.0.post0-1.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-dateutil&#34;,&#xA;        &#34;version&#34;: &#34;2.9.0.post0-1.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Esfj4A6yCPG0aR5IhgHmUg==&#34;: {&#xA;      &#34;id&#34;: &#34;Esfj4A6yCPG0aR5IhgHmUg==&#34;,&#xA;      &#34;name&#34;: &#34;libgcc&#34;,&#xA;      &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gcc&#34;,&#xA;        &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Exv8+xTp+7Y4AfuM+ph47Q==&#34;: {&#xA;      &#34;id&#34;: &#34;Exv8+xTp+7Y4AfuM+ph47Q==&#34;,&#xA;      &#34;name&#34;: &#34;perl-parent&#34;,&#xA;      &#34;version&#34;: &#34;1:0.238-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-parent&#34;,&#xA;        &#34;version&#34;: &#34;0.238-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;F5S3/GN2uyb/+Q/5rj2gBA==&#34;: {&#xA;      &#34;id&#34;: &#34;F5S3/GN2uyb/+Q/5rj2gBA==&#34;,&#xA;      &#34;name&#34;: &#34;ruby-default-gems&#34;,&#xA;      &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;F6sWmqQXkobYs1E0otG8/A==&#34;: {&#xA;      &#34;id&#34;: &#34;F6sWmqQXkobYs1E0otG8/A==&#34;,&#xA;      &#34;name&#34;: &#34;openssh&#34;,&#xA;      &#34;version&#34;: &#34;8.7p1-46.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;8.7p1-46.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;F90x58kELkC16MbTpMw3vg==&#34;: {&#xA;      &#34;id&#34;: &#34;F90x58kELkC16MbTpMw3vg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-POSIX&#34;,&#xA;      &#34;version&#34;: &#34;1.94-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;FDdpwYO23GZzR/6AZCdQZA==&#34;: {&#xA;      &#34;id&#34;: &#34;FDdpwYO23GZzR/6AZCdQZA==&#34;,&#xA;      &#34;name&#34;: &#34;harfbuzz&#34;,&#xA;      &#34;version&#34;: &#34;2.7.4-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;harfbuzz&#34;,&#xA;        &#34;version&#34;: &#34;2.7.4-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;FEF27h+V5TzrUeQsFddapA==&#34;: {&#xA;      &#34;id&#34;: &#34;FEF27h+V5TzrUeQsFddapA==&#34;,&#xA;      &#34;name&#34;: &#34;libSM&#34;,&#xA;      &#34;version&#34;: &#34;1.2.3-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libSM&#34;,&#xA;        &#34;version&#34;: &#34;1.2.3-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;FEW4+DY0GhovHIdRCyqYhg==&#34;: {&#xA;      &#34;id&#34;: &#34;FEW4+DY0GhovHIdRCyqYhg==&#34;,&#xA;      &#34;name&#34;: &#34;gnutls&#34;,&#xA;      &#34;version&#34;: &#34;3.8.3-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;3.8.3-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;FFSNe661VBElA1asGZ7k3g==&#34;: {&#xA;      &#34;id&#34;: &#34;FFSNe661VBElA1asGZ7k3g==&#34;,&#xA;      &#34;name&#34;: &#34;rust-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;17-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rust-srpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;17-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;FKD/ouYSWOOZHy4i43SaxA==&#34;: {&#xA;      &#34;id&#34;: &#34;FKD/ouYSWOOZHy4i43SaxA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-TermReadKey&#34;,&#xA;      &#34;version&#34;: &#34;2.38-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-TermReadKey&#34;,&#xA;        &#34;version&#34;: &#34;2.38-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;FW8ByCOP6ljvNWDQolahwg==&#34;: {&#xA;      &#34;id&#34;: &#34;FW8ByCOP6ljvNWDQolahwg==&#34;,&#xA;      &#34;name&#34;: &#34;sysprof-capture-devel&#34;,&#xA;      &#34;version&#34;: &#34;3.40.1-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;sysprof&#34;,&#xA;        &#34;version&#34;: &#34;3.40.1-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;FaNO6QWs1mWPp40PrBiBUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;FaNO6QWs1mWPp40PrBiBUQ==&#34;,&#xA;      &#34;name&#34;: &#34;libseccomp&#34;,&#xA;      &#34;version&#34;: &#34;2.5.2-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libseccomp&#34;,&#xA;        &#34;version&#34;: &#34;2.5.2-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;FiLBkAWUUsnpX53xBEBwNw==&#34;: {&#xA;      &#34;id&#34;: &#34;FiLBkAWUUsnpX53xBEBwNw==&#34;,&#xA;      &#34;name&#34;: &#34;dbus&#34;,&#xA;      &#34;version&#34;: &#34;1:1.12.20-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dbus&#34;,&#xA;        &#34;version&#34;: &#34;1.12.20-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;FoNZoDzlktTR7m0xbn6aAw==&#34;: {&#xA;      &#34;id&#34;: &#34;FoNZoDzlktTR7m0xbn6aAw==&#34;,&#xA;      &#34;name&#34;: &#34;python3-libdnf&#34;,&#xA;      &#34;version&#34;: &#34;0.69.0-16.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libdnf&#34;,&#xA;        &#34;version&#34;: &#34;0.69.0-16.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;FoncQi9chif7gDbfNIi6VQ==&#34;: {&#xA;      &#34;id&#34;: &#34;FoncQi9chif7gDbfNIi6VQ==&#34;,&#xA;      &#34;name&#34;: &#34;file&#34;,&#xA;      &#34;version&#34;: &#34;5.39-16.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;file&#34;,&#xA;        &#34;version&#34;: &#34;5.39-16.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;G1YDEd7+V95Qa+PMxB8sJw==&#34;: {&#xA;      &#34;id&#34;: &#34;G1YDEd7+V95Qa+PMxB8sJw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Digest&#34;,&#xA;      &#34;version&#34;: &#34;1.19-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Digest&#34;,&#xA;        &#34;version&#34;: &#34;1.19-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;G61ZL2SOHR2qgvQfi118gw==&#34;: {&#xA;      &#34;id&#34;: &#34;G61ZL2SOHR2qgvQfi118gw==&#34;,&#xA;      &#34;name&#34;: &#34;dejavu-sans-fonts&#34;,&#xA;      &#34;version&#34;: &#34;2.37-18.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dejavu-fonts&#34;,&#xA;        &#34;version&#34;: &#34;2.37-18.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;GIScmMWQrnoFNoEgq3fg2w==&#34;: {&#xA;      &#34;id&#34;: &#34;GIScmMWQrnoFNoEgq3fg2w==&#34;,&#xA;      &#34;name&#34;: &#34;python3-dbus&#34;,&#xA;      &#34;version&#34;: &#34;1.2.18-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dbus-python&#34;,&#xA;        &#34;version&#34;: &#34;1.2.18-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;GSkR2SOuqWQN8NtOvU4cgw==&#34;: {&#xA;      &#34;id&#34;: &#34;GSkR2SOuqWQN8NtOvU4cgw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Thread-Queue&#34;,&#xA;      &#34;version&#34;: &#34;3.14-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Thread-Queue&#34;,&#xA;        &#34;version&#34;: &#34;3.14-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;GdLrcchvFseDsR7KOv0vSQ==&#34;: {&#xA;      &#34;id&#34;: &#34;GdLrcchvFseDsR7KOv0vSQ==&#34;,&#xA;      &#34;name&#34;: &#34;crypto-policies&#34;,&#xA;      &#34;version&#34;: &#34;20250905-1.git377cc42.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;crypto-policies&#34;,&#xA;        &#34;version&#34;: &#34;20250905-1.git377cc42.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Gfvf4LQKHStcGqbzaAe/lA==&#34;: {&#xA;      &#34;id&#34;: &#34;Gfvf4LQKHStcGqbzaAe/lA==&#34;,&#xA;      &#34;name&#34;: &#34;brotli-devel&#34;,&#xA;      &#34;version&#34;: &#34;1.0.9-7.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;brotli&#34;,&#xA;        &#34;version&#34;: &#34;1.0.9-7.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;GrPCC9ybwOy98qwLdeCX6A==&#34;: {&#xA;      &#34;id&#34;: &#34;GrPCC9ybwOy98qwLdeCX6A==&#34;,&#xA;      &#34;name&#34;: &#34;nodejs&#34;,&#xA;      &#34;version&#34;: &#34;1:22.19.0-2.module+el9.6.0+23473+45664c2d&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;22.19.0-2.module+el9.6.0+23473+45664c2d&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;GrohJMl/MISMll2qndOSGg==&#34;: {&#xA;      &#34;id&#34;: &#34;GrohJMl/MISMll2qndOSGg==&#34;,&#xA;      &#34;name&#34;: &#34;libX11-xcb&#34;,&#xA;      &#34;version&#34;: &#34;1.7.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libX11&#34;,&#xA;        &#34;version&#34;: &#34;1.7.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;GtFO3rQtk4lExV/Q1qfFOg==&#34;: {&#xA;      &#34;id&#34;: &#34;GtFO3rQtk4lExV/Q1qfFOg==&#34;,&#xA;      &#34;name&#34;: &#34;zip&#34;,&#xA;      &#34;version&#34;: &#34;3.0-35.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;zip&#34;,&#xA;        &#34;version&#34;: &#34;3.0-35.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;GwNK8p9XcJLynTdoZWdCxg==&#34;: {&#xA;      &#34;id&#34;: &#34;GwNK8p9XcJLynTdoZWdCxg==&#34;,&#xA;      &#34;name&#34;: &#34;libdb&#34;,&#xA;      &#34;version&#34;: &#34;5.3.28-57.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libdb&#34;,&#xA;        &#34;version&#34;: &#34;5.3.28-57.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;H3zfV58LzeEUiNQbZbZb2A==&#34;: {&#xA;      &#34;id&#34;: &#34;H3zfV58LzeEUiNQbZbZb2A==&#34;,&#xA;      &#34;name&#34;: &#34;perl-File-Temp&#34;,&#xA;      &#34;version&#34;: &#34;1:0.231.100-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-File-Temp&#34;,&#xA;        &#34;version&#34;: &#34;0.231.100-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;HF0BuzgGNjLOUKqVyjw0oA==&#34;: {&#xA;      &#34;id&#34;: &#34;HF0BuzgGNjLOUKqVyjw0oA==&#34;,&#xA;      &#34;name&#34;: &#34;rubygem-irb&#34;,&#xA;      &#34;version&#34;: &#34;1.13.1-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;HKlRsQZtXaa3HoNDv500tg==&#34;: {&#xA;      &#34;id&#34;: &#34;HKlRsQZtXaa3HoNDv500tg==&#34;,&#xA;      &#34;name&#34;: &#34;openssl-fips-provider-so&#34;,&#xA;      &#34;version&#34;: &#34;3.0.7-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-fips-provider&#34;,&#xA;        &#34;version&#34;: &#34;3.0.7-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;HQLCuUiHA+476ax5LmI78Q==&#34;: {&#xA;      &#34;id&#34;: &#34;HQLCuUiHA+476ax5LmI78Q==&#34;,&#xA;      &#34;name&#34;: &#34;rubygem-bigdecimal&#34;,&#xA;      &#34;version&#34;: &#34;3.1.5-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;HQdWvmyUSqtI3UTY0T4JiQ==&#34;: {&#xA;      &#34;id&#34;: &#34;HQdWvmyUSqtI3UTY0T4JiQ==&#34;,&#xA;      &#34;name&#34;: &#34;pcre&#34;,&#xA;      &#34;version&#34;: &#34;8.44-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre&#34;,&#xA;        &#34;version&#34;: &#34;8.44-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;HaOoNwb8lV6rMAwKRGxXbA==&#34;: {&#xA;      &#34;id&#34;: &#34;HaOoNwb8lV6rMAwKRGxXbA==&#34;,&#xA;      &#34;name&#34;: &#34;python3-dnf-plugins-core&#34;,&#xA;      &#34;version&#34;: &#34;4.3.0-24.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dnf-plugins-core&#34;,&#xA;        &#34;version&#34;: &#34;4.3.0-24.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;HyWYXl8ZaOY6wtr4mKF7qA==&#34;: {&#xA;      &#34;id&#34;: &#34;HyWYXl8ZaOY6wtr4mKF7qA==&#34;,&#xA;      &#34;name&#34;: &#34;elfutils-libelf&#34;,&#xA;      &#34;version&#34;: &#34;0.193-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;elfutils&#34;,&#xA;        &#34;version&#34;: &#34;0.193-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;HyjfzS7o9NZj6mKbOA36wA==&#34;: {&#xA;      &#34;id&#34;: &#34;HyjfzS7o9NZj6mKbOA36wA==&#34;,&#xA;      &#34;name&#34;: &#34;ruby-devel&#34;,&#xA;      &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;I16VSEydeiRYB1TSf5694A==&#34;: {&#xA;      &#34;id&#34;: &#34;I16VSEydeiRYB1TSf5694A==&#34;,&#xA;      &#34;name&#34;: &#34;libreport-filesystem&#34;,&#xA;      &#34;version&#34;: &#34;2.15.2-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libreport&#34;,&#xA;        &#34;version&#34;: &#34;2.15.2-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;I4xeNeKgfXcsAYIlRhjPiQ==&#34;: {&#xA;      &#34;id&#34;: &#34;I4xeNeKgfXcsAYIlRhjPiQ==&#34;,&#xA;      &#34;name&#34;: &#34;glibc-devel&#34;,&#xA;      &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;IC3qYOgP07zDDhN8OMm04Q==&#34;: {&#xA;      &#34;id&#34;: &#34;IC3qYOgP07zDDhN8OMm04Q==&#34;,&#xA;      &#34;name&#34;: &#34;perl-lib&#34;,&#xA;      &#34;version&#34;: &#34;0.65-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;IDaB7M+//88qbPppM+LpUw==&#34;: {&#xA;      &#34;id&#34;: &#34;IDaB7M+//88qbPppM+LpUw==&#34;,&#xA;      &#34;name&#34;: &#34;cracklib&#34;,&#xA;      &#34;version&#34;: &#34;2.9.6-27.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;cracklib&#34;,&#xA;        &#34;version&#34;: &#34;2.9.6-27.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;IG/inuDbgBm/XuY2u/Aumw==&#34;: {&#xA;      &#34;id&#34;: &#34;IG/inuDbgBm/XuY2u/Aumw==&#34;,&#xA;      &#34;name&#34;: &#34;vim-filesystem&#34;,&#xA;      &#34;version&#34;: &#34;2:8.2.2637-23.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;8.2.2637-23.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;IZ65O3ZOapykHwhaOX1/YA==&#34;: {&#xA;      &#34;id&#34;: &#34;IZ65O3ZOapykHwhaOX1/YA==&#34;,&#xA;      &#34;name&#34;: &#34;libnghttp2&#34;,&#xA;      &#34;version&#34;: &#34;1.43.0-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nghttp2&#34;,&#xA;        &#34;version&#34;: &#34;1.43.0-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;IqB8E1ANUG9NXQorLZJDiQ==&#34;: {&#xA;      &#34;id&#34;: &#34;IqB8E1ANUG9NXQorLZJDiQ==&#34;,&#xA;      &#34;name&#34;: &#34;perl-DynaLoader&#34;,&#xA;      &#34;version&#34;: &#34;1.47-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;IxIhH0Z+Om/E2wWJgs7oqA==&#34;: {&#xA;      &#34;id&#34;: &#34;IxIhH0Z+Om/E2wWJgs7oqA==&#34;,&#xA;      &#34;name&#34;: &#34;libstdc++-devel&#34;,&#xA;      &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gcc&#34;,&#xA;        &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;J4wVTpjsd90BinvJHS7Zqw==&#34;: {&#xA;      &#34;id&#34;: &#34;J4wVTpjsd90BinvJHS7Zqw==&#34;,&#xA;      &#34;name&#34;: &#34;sqlite-devel&#34;,&#xA;      &#34;version&#34;: &#34;3.34.1-9.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;sqlite&#34;,&#xA;        &#34;version&#34;: &#34;3.34.1-9.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;J9Ac2zSOxpvD4YQ2MZMs6w==&#34;: {&#xA;      &#34;id&#34;: &#34;J9Ac2zSOxpvD4YQ2MZMs6w==&#34;,&#xA;      &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;      &#34;version&#34;: &#34;1:22.19.0-2.module+el9.6.0+23473+45664c2d&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;22.19.0-2.module+el9.6.0+23473+45664c2d&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;JF/KXrYQKwPQyQXcXBUzkQ==&#34;: {&#xA;      &#34;id&#34;: &#34;JF/KXrYQKwPQyQXcXBUzkQ==&#34;,&#xA;      &#34;name&#34;: &#34;librepo&#34;,&#xA;      &#34;version&#34;: &#34;1.14.5-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;librepo&#34;,&#xA;        &#34;version&#34;: &#34;1.14.5-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;JFKff4xqwvXPuYTu9WPwUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;JFKff4xqwvXPuYTu9WPwUQ==&#34;,&#xA;      &#34;name&#34;: &#34;binutils&#34;,&#xA;      &#34;version&#34;: &#34;2.35.2-67.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;2.35.2-67.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;JKP7JzVg7UGaAz4VrH03lQ==&#34;: {&#xA;      &#34;id&#34;: &#34;JKP7JzVg7UGaAz4VrH03lQ==&#34;,&#xA;      &#34;name&#34;: &#34;langpacks-core-font-en&#34;,&#xA;      &#34;version&#34;: &#34;3.0-16.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;langpacks&#34;,&#xA;        &#34;version&#34;: &#34;3.0-16.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;JaeGSHoaw5r486gmcDmRVA==&#34;: {&#xA;      &#34;id&#34;: &#34;JaeGSHoaw5r486gmcDmRVA==&#34;,&#xA;      &#34;name&#34;: &#34;gcc-plugin-annobin&#34;,&#xA;      &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gcc&#34;,&#xA;        &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;KEwhWR+KmcE0gZ+mC6lSDw==&#34;: {&#xA;      &#34;id&#34;: &#34;KEwhWR+KmcE0gZ+mC6lSDw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-SelectSaver&#34;,&#xA;      &#34;version&#34;: &#34;1.02-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;KF5C+zKu/uFB7knCqOvDAQ==&#34;: {&#xA;      &#34;id&#34;: &#34;KF5C+zKu/uFB7knCqOvDAQ==&#34;,&#xA;      &#34;name&#34;: &#34;json-glib&#34;,&#xA;      &#34;version&#34;: &#34;1.6.6-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;json-glib&#34;,&#xA;        &#34;version&#34;: &#34;1.6.6-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;KH0/KbRUi7KL6UvWa8i6Pg==&#34;: {&#xA;      &#34;id&#34;: &#34;KH0/KbRUi7KL6UvWa8i6Pg==&#34;,&#xA;      &#34;name&#34;: &#34;python3-inotify&#34;,&#xA;      &#34;version&#34;: &#34;0.9.6-25.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-inotify&#34;,&#xA;        &#34;version&#34;: &#34;0.9.6-25.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;KS0gfrpBqK77mtupKmitjw==&#34;: {&#xA;      &#34;id&#34;: &#34;KS0gfrpBqK77mtupKmitjw==&#34;,&#xA;      &#34;name&#34;: &#34;glibc&#34;,&#xA;      &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;KcPAdOork3AFYl8WLwr8lQ==&#34;: {&#xA;      &#34;id&#34;: &#34;KcPAdOork3AFYl8WLwr8lQ==&#34;,&#xA;      &#34;name&#34;: &#34;zlib-devel&#34;,&#xA;      &#34;version&#34;: &#34;1.2.11-40.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;zlib&#34;,&#xA;        &#34;version&#34;: &#34;1.2.11-40.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;KcftiMkhTw4x89HNJI8NNg==&#34;: {&#xA;      &#34;id&#34;: &#34;KcftiMkhTw4x89HNJI8NNg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Text-ParseWords&#34;,&#xA;      &#34;version&#34;: &#34;3.30-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Text-ParseWords&#34;,&#xA;        &#34;version&#34;: &#34;3.30-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;KnsryeYjIOfmvupUdl8bDg==&#34;: {&#xA;      &#34;id&#34;: &#34;KnsryeYjIOfmvupUdl8bDg==&#34;,&#xA;      &#34;name&#34;: &#34;scl-utils&#34;,&#xA;      &#34;version&#34;: &#34;1:2.0.3-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;scl-utils&#34;,&#xA;        &#34;version&#34;: &#34;2.0.3-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;KyRw1LumZrRo6AKKkHgP7w==&#34;: {&#xA;      &#34;id&#34;: &#34;KyRw1LumZrRo6AKKkHgP7w==&#34;,&#xA;      &#34;name&#34;: &#34;libXext&#34;,&#xA;      &#34;version&#34;: &#34;1.3.4-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libXext&#34;,&#xA;        &#34;version&#34;: &#34;1.3.4-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;L1CJW90/qIOW7PuGFCWT3g==&#34;: {&#xA;      &#34;id&#34;: &#34;L1CJW90/qIOW7PuGFCWT3g==&#34;,&#xA;      &#34;name&#34;: &#34;perl-mro&#34;,&#xA;      &#34;version&#34;: &#34;1.23-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;L2RUW2Fm5EOgoqwyitY3bg==&#34;: {&#xA;      &#34;id&#34;: &#34;L2RUW2Fm5EOgoqwyitY3bg==&#34;,&#xA;      &#34;name&#34;: &#34;dbus-broker&#34;,&#xA;      &#34;version&#34;: &#34;28-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dbus-broker&#34;,&#xA;        &#34;version&#34;: &#34;28-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;LDIMlzOywHz1+CG5FwjKdQ==&#34;: {&#xA;      &#34;id&#34;: &#34;LDIMlzOywHz1+CG5FwjKdQ==&#34;,&#xA;      &#34;name&#34;: &#34;subscription-manager-rhsm-certificates&#34;,&#xA;      &#34;version&#34;: &#34;20220623-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;subscription-manager-rhsm-certificates&#34;,&#xA;        &#34;version&#34;: &#34;20220623-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;LEyuwSco7tb1WIyWy42H8g==&#34;: {&#xA;      &#34;id&#34;: &#34;LEyuwSco7tb1WIyWy42H8g==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Storable&#34;,&#xA;      &#34;version&#34;: &#34;1:3.21-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Storable&#34;,&#xA;        &#34;version&#34;: &#34;3.21-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;LPNXQi0V2EN73HoDD+RYaw==&#34;: {&#xA;      &#34;id&#34;: &#34;LPNXQi0V2EN73HoDD+RYaw==&#34;,&#xA;      &#34;name&#34;: &#34;annobin&#34;,&#xA;      &#34;version&#34;: &#34;12.98-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;annobin&#34;,&#xA;        &#34;version&#34;: &#34;12.98-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;LW/iN16rWtvIqrNuZRqrvA==&#34;: {&#xA;      &#34;id&#34;: &#34;LW/iN16rWtvIqrNuZRqrvA==&#34;,&#xA;      &#34;name&#34;: &#34;npm&#34;,&#xA;      &#34;version&#34;: &#34;1:10.9.3-1.22.19.0.2.module+el9.6.0+23473+45664c2d&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;22.19.0-2.module+el9.6.0+23473+45664c2d&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Leh3RdsGa1oyRcl5Dz4SdA==&#34;: {&#xA;      &#34;id&#34;: &#34;Leh3RdsGa1oyRcl5Dz4SdA==&#34;,&#xA;      &#34;name&#34;: &#34;gd-devel&#34;,&#xA;      &#34;version&#34;: &#34;2.3.2-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gd&#34;,&#xA;        &#34;version&#34;: &#34;2.3.2-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;LjtOegR/S/Y0KwJeOuSl/w==&#34;: {&#xA;      &#34;id&#34;: &#34;LjtOegR/S/Y0KwJeOuSl/w==&#34;,&#xA;      &#34;name&#34;: &#34;perl-podlators&#34;,&#xA;      &#34;version&#34;: &#34;1:4.14-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-podlators&#34;,&#xA;        &#34;version&#34;: &#34;4.14-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Lwqn0aweLQLZmo12VvYcog==&#34;: {&#xA;      &#34;id&#34;: &#34;Lwqn0aweLQLZmo12VvYcog==&#34;,&#xA;      &#34;name&#34;: &#34;popt&#34;,&#xA;      &#34;version&#34;: &#34;1.18-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;popt&#34;,&#xA;        &#34;version&#34;: &#34;1.18-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;M2qdPAOOvb+CWXJwouP4Rw==&#34;: {&#xA;      &#34;id&#34;: &#34;M2qdPAOOvb+CWXJwouP4Rw==&#34;,&#xA;      &#34;name&#34;: &#34;mariadb-connector-c-devel&#34;,&#xA;      &#34;version&#34;: &#34;3.2.6-1.el9_0&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;mariadb-connector-c&#34;,&#xA;        &#34;version&#34;: &#34;3.2.6-1.el9_0&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;MDH8Zt4oQWDiYk9qFV5Lbg==&#34;: {&#xA;      &#34;id&#34;: &#34;MDH8Zt4oQWDiYk9qFV5Lbg==&#34;,&#xA;      &#34;name&#34;: &#34;libxcrypt&#34;,&#xA;      &#34;version&#34;: &#34;4.4.18-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxcrypt&#34;,&#xA;        &#34;version&#34;: &#34;4.4.18-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;MORX6hW9ZLZCt/52w71zTg==&#34;: {&#xA;      &#34;id&#34;: &#34;MORX6hW9ZLZCt/52w71zTg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-PathTools&#34;,&#xA;      &#34;version&#34;: &#34;3.78-461.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-PathTools&#34;,&#xA;        &#34;version&#34;: &#34;3.78-461.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;MdGkZ055CI+TZYqVm7FIPg==&#34;: {&#xA;      &#34;id&#34;: &#34;MdGkZ055CI+TZYqVm7FIPg==&#34;,&#xA;      &#34;name&#34;: &#34;libcbor&#34;,&#xA;      &#34;version&#34;: &#34;0.7.0-5.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libcbor&#34;,&#xA;        &#34;version&#34;: &#34;0.7.0-5.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Mp61fGpK3II0W8dIQgk3hA==&#34;: {&#xA;      &#34;id&#34;: &#34;Mp61fGpK3II0W8dIQgk3hA==&#34;,&#xA;      &#34;name&#34;: &#34;libpipeline&#34;,&#xA;      &#34;version&#34;: &#34;1.5.3-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpipeline&#34;,&#xA;        &#34;version&#34;: &#34;1.5.3-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Mta8K+tWCjAV6ERlLy6JNw==&#34;: {&#xA;      &#34;id&#34;: &#34;Mta8K+tWCjAV6ERlLy6JNw==&#34;,&#xA;      &#34;name&#34;: &#34;audit-libs&#34;,&#xA;      &#34;version&#34;: &#34;3.1.5-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;audit&#34;,&#xA;        &#34;version&#34;: &#34;3.1.5-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;MvInuV8lMA+9LBSzIEvv5g==&#34;: {&#xA;      &#34;id&#34;: &#34;MvInuV8lMA+9LBSzIEvv5g==&#34;,&#xA;      &#34;name&#34;: &#34;ruby-libs&#34;,&#xA;      &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;N2AxbBO2ySQgGMgkdbfo+w==&#34;: {&#xA;      &#34;id&#34;: &#34;N2AxbBO2ySQgGMgkdbfo+w==&#34;,&#xA;      &#34;name&#34;: &#34;python3-requests&#34;,&#xA;      &#34;version&#34;: &#34;2.25.1-10.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-requests&#34;,&#xA;        &#34;version&#34;: &#34;2.25.1-10.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;N9SQ1VZ/1zaqG0gdsMW91g==&#34;: {&#xA;      &#34;id&#34;: &#34;N9SQ1VZ/1zaqG0gdsMW91g==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Term-ANSIColor&#34;,&#xA;      &#34;version&#34;: &#34;5.01-461.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Term-ANSIColor&#34;,&#xA;        &#34;version&#34;: &#34;5.01-461.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;NCC3wkuc6lwSKJH9fwRaTQ==&#34;: {&#xA;      &#34;id&#34;: &#34;NCC3wkuc6lwSKJH9fwRaTQ==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/ubi&#34;,&#xA;      &#34;version&#34;: &#34;1764578730&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;isMk2o0BvgtLnlqdbo7sxQ==&#34;,&#xA;        &#34;name&#34;: &#34;ubi9/ubi&#34;,&#xA;        &#34;version&#34;: &#34;1764578730&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;source&#34;: {&#xA;          &#34;id&#34;: &#34;&#34;,&#xA;          &#34;name&#34;: &#34;&#34;,&#xA;          &#34;version&#34;: &#34;&#34;,&#xA;          &#34;normalized_version&#34;: &#34;&#34;,&#xA;          &#34;cpe&#34;: &#34;&#34;,&#xA;          &#34;detector&#34;: null&#xA;        },&#xA;        &#34;normalized_version&#34;: &#34;unmatchable:1764578730.0.0.0.0.0.0.0.0.0&#34;,&#xA;        &#34;arch&#34;: &#34;x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764578730.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;NDKmI4fvu2M/TtapvknDEg==&#34;: {&#xA;      &#34;id&#34;: &#34;NDKmI4fvu2M/TtapvknDEg==&#34;,&#xA;      &#34;name&#34;: &#34;libsepol-devel&#34;,&#xA;      &#34;version&#34;: &#34;3.6-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libsepol&#34;,&#xA;        &#34;version&#34;: &#34;3.6-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;NSiprMdkK5/5pxuNNJOh2A==&#34;: {&#xA;      &#34;id&#34;: &#34;NSiprMdkK5/5pxuNNJOh2A==&#34;,&#xA;      &#34;name&#34;: &#34;openssl-fips-provider&#34;,&#xA;      &#34;version&#34;: &#34;3.0.7-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-fips-provider&#34;,&#xA;        &#34;version&#34;: &#34;3.0.7-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Nak/NGhCYVubG4CsEbHhug==&#34;: {&#xA;      &#34;id&#34;: &#34;Nak/NGhCYVubG4CsEbHhug==&#34;,&#xA;      &#34;name&#34;: &#34;graphite2-devel&#34;,&#xA;      &#34;version&#34;: &#34;1.3.14-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;graphite2&#34;,&#xA;        &#34;version&#34;: &#34;1.3.14-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;NdCY2/S+syamLH224R4hug==&#34;: {&#xA;      &#34;id&#34;: &#34;NdCY2/S+syamLH224R4hug==&#34;,&#xA;      &#34;name&#34;: &#34;langpacks-en&#34;,&#xA;      &#34;version&#34;: &#34;3.0-16.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;langpacks&#34;,&#xA;        &#34;version&#34;: &#34;3.0-16.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;NsU0bgQSA1JrKw3zvB+XBw==&#34;: {&#xA;      &#34;id&#34;: &#34;NsU0bgQSA1JrKw3zvB+XBw==&#34;,&#xA;      &#34;name&#34;: &#34;dbus-libs&#34;,&#xA;      &#34;version&#34;: &#34;1:1.12.20-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dbus&#34;,&#xA;        &#34;version&#34;: &#34;1.12.20-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;O6NCE8KkqNnnBGJrWxfPwA==&#34;: {&#xA;      &#34;id&#34;: &#34;O6NCE8KkqNnnBGJrWxfPwA==&#34;,&#xA;      &#34;name&#34;: &#34;libstdc++&#34;,&#xA;      &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gcc&#34;,&#xA;        &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;OCIjbR16ktOEiFK36r0WNw==&#34;: {&#xA;      &#34;id&#34;: &#34;OCIjbR16ktOEiFK36r0WNw==&#34;,&#xA;      &#34;name&#34;: &#34;libtasn1&#34;,&#xA;      &#34;version&#34;: &#34;4.16.0-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtasn1&#34;,&#xA;        &#34;version&#34;: &#34;4.16.0-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;OgwdUybWl/HQYbnPTE4Psw==&#34;: {&#xA;      &#34;id&#34;: &#34;OgwdUybWl/HQYbnPTE4Psw==&#34;,&#xA;      &#34;name&#34;: &#34;npth&#34;,&#xA;      &#34;version&#34;: &#34;1.6-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npth&#34;,&#xA;        &#34;version&#34;: &#34;1.6-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Ohssf0Jzlafd9vtrrUKCXg==&#34;: {&#xA;      &#34;id&#34;: &#34;Ohssf0Jzlafd9vtrrUKCXg==&#34;,&#xA;      &#34;name&#34;: &#34;bash&#34;,&#xA;      &#34;version&#34;: &#34;5.1.8-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;bash&#34;,&#xA;        &#34;version&#34;: &#34;5.1.8-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;OkY4XBjh2jDTkYhGjNkrUA==&#34;: {&#xA;      &#34;id&#34;: &#34;OkY4XBjh2jDTkYhGjNkrUA==&#34;,&#xA;      &#34;name&#34;: &#34;mariadb-connector-c&#34;,&#xA;      &#34;version&#34;: &#34;3.2.6-1.el9_0&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;mariadb-connector-c&#34;,&#xA;        &#34;version&#34;: &#34;3.2.6-1.el9_0&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Ol1YWxU11Z64v1nA/zb/5w==&#34;: {&#xA;      &#34;id&#34;: &#34;Ol1YWxU11Z64v1nA/zb/5w==&#34;,&#xA;      &#34;name&#34;: &#34;pkgconf&#34;,&#xA;      &#34;version&#34;: &#34;1.7.3-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pkgconf&#34;,&#xA;        &#34;version&#34;: &#34;1.7.3-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;OvOSK0YS4U6j2gyFBATNXg==&#34;: {&#xA;      &#34;id&#34;: &#34;OvOSK0YS4U6j2gyFBATNXg==&#34;,&#xA;      &#34;name&#34;: &#34;xz&#34;,&#xA;      &#34;version&#34;: &#34;5.2.5-8.el9_0&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;xz&#34;,&#xA;        &#34;version&#34;: &#34;5.2.5-8.el9_0&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;P5Om9zCJ/QZ+hnrEvj6fGw==&#34;: {&#xA;      &#34;id&#34;: &#34;P5Om9zCJ/QZ+hnrEvj6fGw==&#34;,&#xA;      &#34;name&#34;: &#34;libgcrypt&#34;,&#xA;      &#34;version&#34;: &#34;1.10.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libgcrypt&#34;,&#xA;        &#34;version&#34;: &#34;1.10.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;PCxuTBi9SbzcxEcQiiLesg==&#34;: {&#xA;      &#34;id&#34;: &#34;PCxuTBi9SbzcxEcQiiLesg==&#34;,&#xA;      &#34;name&#34;: &#34;pcre-utf32&#34;,&#xA;      &#34;version&#34;: &#34;8.44-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre&#34;,&#xA;        &#34;version&#34;: &#34;8.44-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;PIk2BBAWexCFofMi5q03RA==&#34;: {&#xA;      &#34;id&#34;: &#34;PIk2BBAWexCFofMi5q03RA==&#34;,&#xA;      &#34;name&#34;: &#34;pcre2&#34;,&#xA;      &#34;version&#34;: &#34;10.40-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre2&#34;,&#xA;        &#34;version&#34;: &#34;10.40-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;PQJujrJagYV+Ey8n4uQ95g==&#34;: {&#xA;      &#34;id&#34;: &#34;PQJujrJagYV+Ey8n4uQ95g==&#34;,&#xA;      &#34;name&#34;: &#34;subscription-manager&#34;,&#xA;      &#34;version&#34;: &#34;1.29.47.1-1.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;subscription-manager&#34;,&#xA;        &#34;version&#34;: &#34;1.29.47.1-1.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Q4EH8dHdml+oN5T9LssIRw==&#34;: {&#xA;      &#34;id&#34;: &#34;Q4EH8dHdml+oN5T9LssIRw==&#34;,&#xA;      &#34;name&#34;: &#34;gettext-libs&#34;,&#xA;      &#34;version&#34;: &#34;0.21-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gettext&#34;,&#xA;        &#34;version&#34;: &#34;0.21-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Q8V6CJq+uIfjVUujX4I61Q==&#34;: {&#xA;      &#34;id&#34;: &#34;Q8V6CJq+uIfjVUujX4I61Q==&#34;,&#xA;      &#34;name&#34;: &#34;pcre2-utf32&#34;,&#xA;      &#34;version&#34;: &#34;10.40-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre2&#34;,&#xA;        &#34;version&#34;: &#34;10.40-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;QG9+UTOvnb8kW+im/fjlJQ==&#34;: {&#xA;      &#34;id&#34;: &#34;QG9+UTOvnb8kW+im/fjlJQ==&#34;,&#xA;      &#34;name&#34;: &#34;libpq-devel&#34;,&#xA;      &#34;version&#34;: &#34;13.20-1.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpq&#34;,&#xA;        &#34;version&#34;: &#34;13.20-1.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;QbZd82FdnCLBtn8fUkWn0A==&#34;: {&#xA;      &#34;id&#34;: &#34;QbZd82FdnCLBtn8fUkWn0A==&#34;,&#xA;      &#34;name&#34;: &#34;glib2&#34;,&#xA;      &#34;version&#34;: &#34;2.68.4-18.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;2.68.4-18.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;QcXiQZ6UKeueoaxjtrYKog==&#34;: {&#xA;      &#34;id&#34;: &#34;QcXiQZ6UKeueoaxjtrYKog==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Symbol&#34;,&#xA;      &#34;version&#34;: &#34;1.08-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Qk1bxbjfumdXF7/eZ6qhuw==&#34;: {&#xA;      &#34;id&#34;: &#34;Qk1bxbjfumdXF7/eZ6qhuw==&#34;,&#xA;      &#34;name&#34;: &#34;less&#34;,&#xA;      &#34;version&#34;: &#34;590-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;less&#34;,&#xA;        &#34;version&#34;: &#34;590-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;QlHijPVbW9yTtx/mAeIhAg==&#34;: {&#xA;      &#34;id&#34;: &#34;QlHijPVbW9yTtx/mAeIhAg==&#34;,&#xA;      &#34;name&#34;: &#34;python3-dnf&#34;,&#xA;      &#34;version&#34;: &#34;4.14.0-31.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dnf&#34;,&#xA;        &#34;version&#34;: &#34;4.14.0-31.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;QpWwMw97N/44PyIvwMh0cA==&#34;: {&#xA;      &#34;id&#34;: &#34;QpWwMw97N/44PyIvwMh0cA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-interpreter&#34;,&#xA;      &#34;version&#34;: &#34;4:5.32.1-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;R9sC7SuM6vJmJZYq/bMHWw==&#34;: {&#xA;      &#34;id&#34;: &#34;R9sC7SuM6vJmJZYq/bMHWw==&#34;,&#xA;      &#34;name&#34;: &#34;m4&#34;,&#xA;      &#34;version&#34;: &#34;1.4.19-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;m4&#34;,&#xA;        &#34;version&#34;: &#34;1.4.19-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;RH5gHxMLfgSMn5ktJt/VXA==&#34;: {&#xA;      &#34;id&#34;: &#34;RH5gHxMLfgSMn5ktJt/VXA==&#34;,&#xA;      &#34;name&#34;: &#34;psmisc&#34;,&#xA;      &#34;version&#34;: &#34;23.4-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;psmisc&#34;,&#xA;        &#34;version&#34;: &#34;23.4-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;RIdJTslNAIfH4yKbDsoK9Q==&#34;: {&#xA;      &#34;id&#34;: &#34;RIdJTslNAIfH4yKbDsoK9Q==&#34;,&#xA;      &#34;name&#34;: &#34;redhat-release&#34;,&#xA;      &#34;version&#34;: &#34;9.7-0.7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;redhat-release&#34;,&#xA;        &#34;version&#34;: &#34;9.7-0.7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;RXh3fimX8fGZeCt4chJEiA==&#34;: {&#xA;      &#34;id&#34;: &#34;RXh3fimX8fGZeCt4chJEiA==&#34;,&#xA;      &#34;name&#34;: &#34;librhsm&#34;,&#xA;      &#34;version&#34;: &#34;0.0.3-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;librhsm&#34;,&#xA;        &#34;version&#34;: &#34;0.0.3-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Riemnu+blxsuHCoBGaacLA==&#34;: {&#xA;      &#34;id&#34;: &#34;Riemnu+blxsuHCoBGaacLA==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/ruby-33&#34;,&#xA;      &#34;version&#34;: &#34;1786713372&#34;,&#xA;      &#34;kind&#34;: &#34;source&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;rhctag:1786713372.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;RlkbUDRj6k1VsLWBs4sx5g==&#34;: {&#xA;      &#34;id&#34;: &#34;RlkbUDRj6k1VsLWBs4sx5g==&#34;,&#xA;      &#34;name&#34;: &#34;rspec-support&#34;,&#xA;      &#34;version&#34;: &#34;3.13.6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Rmp+/J0Vf6Z1c/jUFbiVFw==&#34;: {&#xA;      &#34;id&#34;: &#34;Rmp+/J0Vf6Z1c/jUFbiVFw==&#34;,&#xA;      &#34;name&#34;: &#34;gdb&#34;,&#xA;      &#34;version&#34;: &#34;16.3-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gdb&#34;,&#xA;        &#34;version&#34;: &#34;16.3-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;RmtwCYp+M3KMl7TiyHKwMA==&#34;: {&#xA;      &#34;id&#34;: &#34;RmtwCYp+M3KMl7TiyHKwMA==&#34;,&#xA;      &#34;name&#34;: &#34;pcre2-devel&#34;,&#xA;      &#34;version&#34;: &#34;10.40-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre2&#34;,&#xA;        &#34;version&#34;: &#34;10.40-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;S8p9UGak1oycptcpYp/1eg==&#34;: {&#xA;      &#34;id&#34;: &#34;S8p9UGak1oycptcpYp/1eg==&#34;,&#xA;      &#34;name&#34;: &#34;openldap&#34;,&#xA;      &#34;version&#34;: &#34;2.6.8-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openldap&#34;,&#xA;        &#34;version&#34;: &#34;2.6.8-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;SDcVZRLpwAQNjUwZ+PuxkA==&#34;: {&#xA;      &#34;id&#34;: &#34;SDcVZRLpwAQNjUwZ+PuxkA==&#34;,&#xA;      &#34;name&#34;: &#34;freetype-devel&#34;,&#xA;      &#34;version&#34;: &#34;2.10.4-10.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;freetype&#34;,&#xA;        &#34;version&#34;: &#34;2.10.4-10.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;SZllfeGD2yJm0VL0H7onLg==&#34;: {&#xA;      &#34;id&#34;: &#34;SZllfeGD2yJm0VL0H7onLg==&#34;,&#xA;      &#34;name&#34;: &#34;libxcb-devel&#34;,&#xA;      &#34;version&#34;: &#34;1.13.1-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxcb&#34;,&#xA;        &#34;version&#34;: &#34;1.13.1-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ScSZYXWuosUrTT47e6vL3g==&#34;: {&#xA;      &#34;id&#34;: &#34;ScSZYXWuosUrTT47e6vL3g==&#34;,&#xA;      &#34;name&#34;: &#34;emacs-filesystem&#34;,&#xA;      &#34;version&#34;: &#34;1:27.2-18.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;emacs&#34;,&#xA;        &#34;version&#34;: &#34;27.2-18.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;SjQtW3gQmgt+Qj8JlnY4Mg==&#34;: {&#xA;      &#34;id&#34;: &#34;SjQtW3gQmgt+Qj8JlnY4Mg==&#34;,&#xA;      &#34;name&#34;: &#34;libblkid&#34;,&#xA;      &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;SsUshR21MZuli8B+sjKoRg==&#34;: {&#xA;      &#34;id&#34;: &#34;SsUshR21MZuli8B+sjKoRg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-File-Basename&#34;,&#xA;      &#34;version&#34;: &#34;2.85-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Su8bfW9ijc0V5CiAum2V1g==&#34;: {&#xA;      &#34;id&#34;: &#34;Su8bfW9ijc0V5CiAum2V1g==&#34;,&#xA;      &#34;name&#34;: &#34;bzip2-libs&#34;,&#xA;      &#34;version&#34;: &#34;1.0.8-10.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;bzip2&#34;,&#xA;        &#34;version&#34;: &#34;1.0.8-10.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;TPIRq84Pr3a6ywzPeCr3Pw==&#34;: {&#xA;      &#34;id&#34;: &#34;TPIRq84Pr3a6ywzPeCr3Pw==&#34;,&#xA;      &#34;name&#34;: &#34;libcap-ng&#34;,&#xA;      &#34;version&#34;: &#34;0.8.2-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libcap-ng&#34;,&#xA;        &#34;version&#34;: &#34;0.8.2-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;TSs+KS9B9pkzz7FIgxu+aw==&#34;: {&#xA;      &#34;id&#34;: &#34;TSs+KS9B9pkzz7FIgxu+aw==&#34;,&#xA;      &#34;name&#34;: &#34;wget&#34;,&#xA;      &#34;version&#34;: &#34;1.21.1-8.el9_4&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;wget&#34;,&#xA;        &#34;version&#34;: &#34;1.21.1-8.el9_4&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Tniy6w9fMQe2ISrhGqJ8ww==&#34;: {&#xA;      &#34;id&#34;: &#34;Tniy6w9fMQe2ISrhGqJ8ww==&#34;,&#xA;      &#34;name&#34;: &#34;rspec-core&#34;,&#xA;      &#34;version&#34;: &#34;3.13.6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;To0NR+oyXDu1CYJfmVGurQ==&#34;: {&#xA;      &#34;id&#34;: &#34;To0NR+oyXDu1CYJfmVGurQ==&#34;,&#xA;      &#34;name&#34;: &#34;gpgme&#34;,&#xA;      &#34;version&#34;: &#34;1.15.1-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gpgme&#34;,&#xA;        &#34;version&#34;: &#34;1.15.1-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ULrmZHuHE64atjgQOV1lWQ==&#34;: {&#xA;      &#34;id&#34;: &#34;ULrmZHuHE64atjgQOV1lWQ==&#34;,&#xA;      &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;      &#34;version&#34;: &#34;1:22.19.0-2.module+el9.6.0+23473+45664c2d&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;22.19.0-2.module+el9.6.0+23473+45664c2d&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;UPcwub579LDL6kq2lq/xZw==&#34;: {&#xA;      &#34;id&#34;: &#34;UPcwub579LDL6kq2lq/xZw==&#34;,&#xA;      &#34;name&#34;: &#34;harfbuzz-devel&#34;,&#xA;      &#34;version&#34;: &#34;2.7.4-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;harfbuzz&#34;,&#xA;        &#34;version&#34;: &#34;2.7.4-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;UTNN7VK61RHl/IW+g5aMJA==&#34;: {&#xA;      &#34;id&#34;: &#34;UTNN7VK61RHl/IW+g5aMJA==&#34;,&#xA;      &#34;name&#34;: &#34;libjpeg-turbo&#34;,&#xA;      &#34;version&#34;: &#34;2.0.90-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libjpeg-turbo&#34;,&#xA;        &#34;version&#34;: &#34;2.0.90-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;UWXJUZfGCJSFYUff3zhl3g==&#34;: {&#xA;      &#34;id&#34;: &#34;UWXJUZfGCJSFYUff3zhl3g==&#34;,&#xA;      &#34;name&#34;: &#34;dmidecode&#34;,&#xA;      &#34;version&#34;: &#34;1:3.6-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dmidecode&#34;,&#xA;        &#34;version&#34;: &#34;3.6-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;UcGy2+DIOqObBfK9GBmDEw==&#34;: {&#xA;      &#34;id&#34;: &#34;UcGy2+DIOqObBfK9GBmDEw==&#34;,&#xA;      &#34;name&#34;: &#34;python-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;3.9-54.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-rpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;3.9-54.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;UnaL8VteZLsad5rFJhaXcw==&#34;: {&#xA;      &#34;id&#34;: &#34;UnaL8VteZLsad5rFJhaXcw==&#34;,&#xA;      &#34;name&#34;: &#34;python3-rpm&#34;,&#xA;      &#34;version&#34;: &#34;4.16.1.3-39.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rpm&#34;,&#xA;        &#34;version&#34;: &#34;4.16.1.3-39.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;VPMvwiwbrTXjPkPpxmP3sw==&#34;: {&#xA;      &#34;id&#34;: &#34;VPMvwiwbrTXjPkPpxmP3sw==&#34;,&#xA;      &#34;name&#34;: &#34;acl&#34;,&#xA;      &#34;version&#34;: &#34;2.3.1-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;acl&#34;,&#xA;        &#34;version&#34;: &#34;2.3.1-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;VV2Z1ngTs6sGvt5SrayPCg==&#34;: {&#xA;      &#34;id&#34;: &#34;VV2Z1ngTs6sGvt5SrayPCg==&#34;,&#xA;      &#34;name&#34;: &#34;libgpg-error&#34;,&#xA;      &#34;version&#34;: &#34;1.42-5.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libgpg-error&#34;,&#xA;        &#34;version&#34;: &#34;1.42-5.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;VX9V+Y680L2xf2tBREdpCw==&#34;: {&#xA;      &#34;id&#34;: &#34;VX9V+Y680L2xf2tBREdpCw==&#34;,&#xA;      &#34;name&#34;: &#34;gmp&#34;,&#xA;      &#34;version&#34;: &#34;1:6.2.0-13.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gmp&#34;,&#xA;        &#34;version&#34;: &#34;6.2.0-13.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;VhjrPOGZ9XGEFgLnQWc+KQ==&#34;: {&#xA;      &#34;id&#34;: &#34;VhjrPOGZ9XGEFgLnQWc+KQ==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Text-Tabs+Wrap&#34;,&#xA;      &#34;version&#34;: &#34;2013.0523-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Text-Tabs+Wrap&#34;,&#xA;        &#34;version&#34;: &#34;2013.0523-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Vk7Abr1qzxUEVjteKWWX5g==&#34;: {&#xA;      &#34;id&#34;: &#34;Vk7Abr1qzxUEVjteKWWX5g==&#34;,&#xA;      &#34;name&#34;: &#34;tar&#34;,&#xA;      &#34;version&#34;: &#34;2:1.34-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;1.34-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;W7uBqJb8l9AhSXjNg1JZQg==&#34;: {&#xA;      &#34;id&#34;: &#34;W7uBqJb8l9AhSXjNg1JZQg==&#34;,&#xA;      &#34;name&#34;: &#34;ncurses-libs&#34;,&#xA;      &#34;version&#34;: &#34;6.2-12.20210508.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ncurses&#34;,&#xA;        &#34;version&#34;: &#34;6.2-12.20210508.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;WCQtqHWXoTXna7IAIUuLVg==&#34;: {&#xA;      &#34;id&#34;: &#34;WCQtqHWXoTXna7IAIUuLVg==&#34;,&#xA;      &#34;name&#34;: &#34;rubygem-json&#34;,&#xA;      &#34;version&#34;: &#34;2.7.2-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;WKbv3dOPjWYMO8/3E5KlHQ==&#34;: {&#xA;      &#34;id&#34;: &#34;WKbv3dOPjWYMO8/3E5KlHQ==&#34;,&#xA;      &#34;name&#34;: &#34;libbrotli&#34;,&#xA;      &#34;version&#34;: &#34;1.0.9-7.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;brotli&#34;,&#xA;        &#34;version&#34;: &#34;1.0.9-7.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;WQqPFo8Asn86tAeRqCxr1w==&#34;: {&#xA;      &#34;id&#34;: &#34;WQqPFo8Asn86tAeRqCxr1w==&#34;,&#xA;      &#34;name&#34;: &#34;perl-IPC-Open3&#34;,&#xA;      &#34;version&#34;: &#34;1.21-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;WVajSGKLGm8z6I23XYAhLQ==&#34;: {&#xA;      &#34;id&#34;: &#34;WVajSGKLGm8z6I23XYAhLQ==&#34;,&#xA;      &#34;name&#34;: &#34;cyrus-sasl-lib&#34;,&#xA;      &#34;version&#34;: &#34;2.1.27-22.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;cyrus-sasl&#34;,&#xA;        &#34;version&#34;: &#34;2.1.27-22.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;WifWl02dLM2pp5urxOSuNg==&#34;: {&#xA;      &#34;id&#34;: &#34;WifWl02dLM2pp5urxOSuNg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-URI&#34;,&#xA;      &#34;version&#34;: &#34;5.09-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-URI&#34;,&#xA;        &#34;version&#34;: &#34;5.09-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;WrJXEOHH0Gy0bbmWqGmrDg==&#34;: {&#xA;      &#34;id&#34;: &#34;WrJXEOHH0Gy0bbmWqGmrDg==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/ruby-33&#34;,&#xA;      &#34;version&#34;: &#34;1786713372&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;Riemnu+blxsuHCoBGaacLA==&#34;,&#xA;        &#34;name&#34;: &#34;ubi9/ruby-33&#34;,&#xA;        &#34;version&#34;: &#34;1786713372&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;source&#34;: {&#xA;          &#34;id&#34;: &#34;&#34;,&#xA;          &#34;name&#34;: &#34;&#34;,&#xA;          &#34;version&#34;: &#34;&#34;,&#xA;          &#34;normalized_version&#34;: &#34;&#34;,&#xA;          &#34;cpe&#34;: &#34;&#34;,&#xA;          &#34;detector&#34;: null&#xA;        },&#xA;        &#34;normalized_version&#34;: &#34;rhctag:1786713372.0.0.0.0.0.0.0.0.0&#34;,&#xA;        &#34;arch&#34;: &#34;x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;rhctag:1786713372.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;WzYxymAFFZiduGsTG/o8gA==&#34;: {&#xA;      &#34;id&#34;: &#34;WzYxymAFFZiduGsTG/o8gA==&#34;,&#xA;      &#34;name&#34;: &#34;attr&#34;,&#xA;      &#34;version&#34;: &#34;2.5.1-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;attr&#34;,&#xA;        &#34;version&#34;: &#34;2.5.1-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XG5+bW8np2NedSy/od6z8Q==&#34;: {&#xA;      &#34;id&#34;: &#34;XG5+bW8np2NedSy/od6z8Q==&#34;,&#xA;      &#34;name&#34;: &#34;libacl&#34;,&#xA;      &#34;version&#34;: &#34;2.3.1-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;acl&#34;,&#xA;        &#34;version&#34;: &#34;2.3.1-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XGaIL7YJmyr8vz8ETC4dAA==&#34;: {&#xA;      &#34;id&#34;: &#34;XGaIL7YJmyr8vz8ETC4dAA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-IO&#34;,&#xA;      &#34;version&#34;: &#34;1.43-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XIcr6HdP94Dud7DtFrfMZg==&#34;: {&#xA;      &#34;id&#34;: &#34;XIcr6HdP94Dud7DtFrfMZg==&#34;,&#xA;      &#34;name&#34;: &#34;libcap&#34;,&#xA;      &#34;version&#34;: &#34;2.48-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libcap&#34;,&#xA;        &#34;version&#34;: &#34;2.48-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XMI2bnJZdxdcHnKc3zgCUA==&#34;: {&#xA;      &#34;id&#34;: &#34;XMI2bnJZdxdcHnKc3zgCUA==&#34;,&#xA;      &#34;name&#34;: &#34;ghc-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;1.5.0-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ghc-srpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;1.5.0-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XP0LiIWbLisoI52ZCyFcLg==&#34;: {&#xA;      &#34;id&#34;: &#34;XP0LiIWbLisoI52ZCyFcLg==&#34;,&#xA;      &#34;name&#34;: &#34;libXpm-devel&#34;,&#xA;      &#34;version&#34;: &#34;3.5.13-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libXpm&#34;,&#xA;        &#34;version&#34;: &#34;3.5.13-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XTnX2VddNvCYpYt/meLgYA==&#34;: {&#xA;      &#34;id&#34;: &#34;XTnX2VddNvCYpYt/meLgYA==&#34;,&#xA;      &#34;name&#34;: &#34;libxslt&#34;,&#xA;      &#34;version&#34;: &#34;1.1.34-13.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxslt&#34;,&#xA;        &#34;version&#34;: &#34;1.1.34-13.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XgE+qDogkObCc5XPQHN25A==&#34;: {&#xA;      &#34;id&#34;: &#34;XgE+qDogkObCc5XPQHN25A==&#34;,&#xA;      &#34;name&#34;: &#34;python3-cloud-what&#34;,&#xA;      &#34;version&#34;: &#34;1.29.47.1-1.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;subscription-manager&#34;,&#xA;        &#34;version&#34;: &#34;1.29.47.1-1.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XliA1VgMzM5VjjSZdnmlQw==&#34;: {&#xA;      &#34;id&#34;: &#34;XliA1VgMzM5VjjSZdnmlQw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Getopt-Long&#34;,&#xA;      &#34;version&#34;: &#34;1:2.52-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Getopt-Long&#34;,&#xA;        &#34;version&#34;: &#34;2.52-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XpiKzmFjoUH4P3gzIyNStg==&#34;: {&#xA;      &#34;id&#34;: &#34;XpiKzmFjoUH4P3gzIyNStg==&#34;,&#xA;      &#34;name&#34;: &#34;rspec&#34;,&#xA;      &#34;version&#34;: &#34;3.13.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XvQXlm/D2h/0lO6HdF8+7g==&#34;: {&#xA;      &#34;id&#34;: &#34;XvQXlm/D2h/0lO6HdF8+7g==&#34;,&#xA;      &#34;name&#34;: &#34;rspec-expectations&#34;,&#xA;      &#34;version&#34;: &#34;3.13.5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;XwbkaIGCYyq6BjBMVZ1wzw==&#34;: {&#xA;      &#34;id&#34;: &#34;XwbkaIGCYyq6BjBMVZ1wzw==&#34;,&#xA;      &#34;name&#34;: &#34;readline&#34;,&#xA;      &#34;version&#34;: &#34;8.1-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;readline&#34;,&#xA;        &#34;version&#34;: &#34;8.1-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Y35yrxWjtTUkUbNtS9+p6g==&#34;: {&#xA;      &#34;id&#34;: &#34;Y35yrxWjtTUkUbNtS9+p6g==&#34;,&#xA;      &#34;name&#34;: &#34;python3-six&#34;,&#xA;      &#34;version&#34;: &#34;1.15.0-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-six&#34;,&#xA;        &#34;version&#34;: &#34;1.15.0-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Y5PnxdiaM8nGZKt9U6sMKw==&#34;: {&#xA;      &#34;id&#34;: &#34;Y5PnxdiaM8nGZKt9U6sMKw==&#34;,&#xA;      &#34;name&#34;: &#34;pcre-cpp&#34;,&#xA;      &#34;version&#34;: &#34;8.44-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre&#34;,&#xA;        &#34;version&#34;: &#34;8.44-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;YMB2ro5tOcEm81D0RjHxXA==&#34;: {&#xA;      &#34;id&#34;: &#34;YMB2ro5tOcEm81D0RjHxXA==&#34;,&#xA;      &#34;name&#34;: &#34;rubygem-psych&#34;,&#xA;      &#34;version&#34;: &#34;5.1.2-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;YuMHdRatKmZ56mnoWUwdqw==&#34;: {&#xA;      &#34;id&#34;: &#34;YuMHdRatKmZ56mnoWUwdqw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Git&#34;,&#xA;      &#34;version&#34;: &#34;2.47.3-1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;git&#34;,&#xA;        &#34;version&#34;: &#34;2.47.3-1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;YwobqP8raRKIH+wXi7ZS4g==&#34;: {&#xA;      &#34;id&#34;: &#34;YwobqP8raRKIH+wXi7ZS4g==&#34;,&#xA;      &#34;name&#34;: &#34;curl-minimal&#34;,&#xA;      &#34;version&#34;: &#34;7.76.1-34.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;7.76.1-34.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;Z+lO9FXEjKlmAeYPAHGorA==&#34;: {&#xA;      &#34;id&#34;: &#34;Z+lO9FXEjKlmAeYPAHGorA==&#34;,&#xA;      &#34;name&#34;: &#34;libmount-devel&#34;,&#xA;      &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ZX4vKkXsoMfQ2HH9oPb0TA==&#34;: {&#xA;      &#34;id&#34;: &#34;ZX4vKkXsoMfQ2HH9oPb0TA==&#34;,&#xA;      &#34;name&#34;: &#34;libXau-devel&#34;,&#xA;      &#34;version&#34;: &#34;1.0.9-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libXau&#34;,&#xA;        &#34;version&#34;: &#34;1.0.9-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ZhfyLrfrE9A0xmCI9BiGXA==&#34;: {&#xA;      &#34;id&#34;: &#34;ZhfyLrfrE9A0xmCI9BiGXA==&#34;,&#xA;      &#34;name&#34;: &#34;tzdata&#34;,&#xA;      &#34;version&#34;: &#34;2025b-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tzdata&#34;,&#xA;        &#34;version&#34;: &#34;2025b-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;aJNccc76ay90akro/A82ww==&#34;: {&#xA;      &#34;id&#34;: &#34;aJNccc76ay90akro/A82ww==&#34;,&#xA;      &#34;name&#34;: &#34;python3-systemd&#34;,&#xA;      &#34;version&#34;: &#34;234-19.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-systemd&#34;,&#xA;        &#34;version&#34;: &#34;234-19.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;afL/h/3XzYq6me3BTaFWlA==&#34;: {&#xA;      &#34;id&#34;: &#34;afL/h/3XzYq6me3BTaFWlA==&#34;,&#xA;      &#34;name&#34;: &#34;libdnf-plugin-subscription-manager&#34;,&#xA;      &#34;version&#34;: &#34;1.29.47.1-1.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;subscription-manager&#34;,&#xA;        &#34;version&#34;: &#34;1.29.47.1-1.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;al0lbET4LJsNSGMw0pP5wg==&#34;: {&#xA;      &#34;id&#34;: &#34;al0lbET4LJsNSGMw0pP5wg==&#34;,&#xA;      &#34;name&#34;: &#34;libjpeg-turbo-devel&#34;,&#xA;      &#34;version&#34;: &#34;2.0.90-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libjpeg-turbo&#34;,&#xA;        &#34;version&#34;: &#34;2.0.90-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;arLt5War9yeQ8auYn/Idmw==&#34;: {&#xA;      &#34;id&#34;: &#34;arLt5War9yeQ8auYn/Idmw==&#34;,&#xA;      &#34;name&#34;: &#34;nettle&#34;,&#xA;      &#34;version&#34;: &#34;3.10.1-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nettle&#34;,&#xA;        &#34;version&#34;: &#34;3.10.1-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;bEsPytE/ZdCMbfuAgQc9AA==&#34;: {&#xA;      &#34;id&#34;: &#34;bEsPytE/ZdCMbfuAgQc9AA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;1-41.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-srpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;1-41.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;bFvWffGqJWr7FWnI7K9NVw==&#34;: {&#xA;      &#34;id&#34;: &#34;bFvWffGqJWr7FWnI7K9NVw==&#34;,&#xA;      &#34;name&#34;: &#34;grep&#34;,&#xA;      &#34;version&#34;: &#34;3.6-5.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;grep&#34;,&#xA;        &#34;version&#34;: &#34;3.6-5.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;bemGVBhbDe9iV1Kjvd9hAA==&#34;: {&#xA;      &#34;id&#34;: &#34;bemGVBhbDe9iV1Kjvd9hAA==&#34;,&#xA;      &#34;name&#34;: &#34;libffi&#34;,&#xA;      &#34;version&#34;: &#34;3.4.2-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libffi&#34;,&#xA;        &#34;version&#34;: &#34;3.4.2-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;cHAJILwEV0OAQcBBnKqncg==&#34;: {&#xA;      &#34;id&#34;: &#34;cHAJILwEV0OAQcBBnKqncg==&#34;,&#xA;      &#34;name&#34;: &#34;elfutils-default-yama-scope&#34;,&#xA;      &#34;version&#34;: &#34;0.193-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;elfutils&#34;,&#xA;        &#34;version&#34;: &#34;0.193-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;cZtZpGQDMJ8/qYUdQbgb3Q==&#34;: {&#xA;      &#34;id&#34;: &#34;cZtZpGQDMJ8/qYUdQbgb3Q==&#34;,&#xA;      &#34;name&#34;: &#34;glibc-headers&#34;,&#xA;      &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ck/z6XzYDT2o8eVJI5IO+Q==&#34;: {&#xA;      &#34;id&#34;: &#34;ck/z6XzYDT2o8eVJI5IO+Q==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/s2i-base&#34;,&#xA;      &#34;version&#34;: &#34;1764621512&#34;,&#xA;      &#34;kind&#34;: &#34;source&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764621512.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;cpIirH9DE6nFQZA6wIpxLg==&#34;: {&#xA;      &#34;id&#34;: &#34;cpIirH9DE6nFQZA6wIpxLg==&#34;,&#xA;      &#34;name&#34;: &#34;gdb-gdbserver&#34;,&#xA;      &#34;version&#34;: &#34;16.3-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gdb&#34;,&#xA;        &#34;version&#34;: &#34;16.3-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ct/ndQfSB+G17YP34ufDBA==&#34;: {&#xA;      &#34;id&#34;: &#34;ct/ndQfSB+G17YP34ufDBA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Digest-MD5&#34;,&#xA;      &#34;version&#34;: &#34;2.58-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Digest-MD5&#34;,&#xA;        &#34;version&#34;: &#34;2.58-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;dBKXgz7fNBsMAqmGTkj8sQ==&#34;: {&#xA;      &#34;id&#34;: &#34;dBKXgz7fNBsMAqmGTkj8sQ==&#34;,&#xA;      &#34;name&#34;: &#34;freetype&#34;,&#xA;      &#34;version&#34;: &#34;2.10.4-10.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;freetype&#34;,&#xA;        &#34;version&#34;: &#34;2.10.4-10.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;dC9CoYt17eaqinGSVCfCxw==&#34;: {&#xA;      &#34;id&#34;: &#34;dC9CoYt17eaqinGSVCfCxw==&#34;,&#xA;      &#34;name&#34;: &#34;libattr&#34;,&#xA;      &#34;version&#34;: &#34;2.5.1-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;attr&#34;,&#xA;        &#34;version&#34;: &#34;2.5.1-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;dH7n2Ct/z7JALFNo9SCMDg==&#34;: {&#xA;      &#34;id&#34;: &#34;dH7n2Ct/z7JALFNo9SCMDg==&#34;,&#xA;      &#34;name&#34;: &#34;gdb-headless&#34;,&#xA;      &#34;version&#34;: &#34;16.3-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gdb&#34;,&#xA;        &#34;version&#34;: &#34;16.3-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;de44cUqF23LvU0fOSvNRjA==&#34;: {&#xA;      &#34;id&#34;: &#34;de44cUqF23LvU0fOSvNRjA==&#34;,&#xA;      &#34;name&#34;: &#34;libevent&#34;,&#xA;      &#34;version&#34;: &#34;2.1.12-8.el9_4&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libevent&#34;,&#xA;        &#34;version&#34;: &#34;2.1.12-8.el9_4&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;dj7DwOHHHI+8+9QuzFaSUA==&#34;: {&#xA;      &#34;id&#34;: &#34;dj7DwOHHHI+8+9QuzFaSUA==&#34;,&#xA;      &#34;name&#34;: &#34;keyutils&#34;,&#xA;      &#34;version&#34;: &#34;1.6.3-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;keyutils&#34;,&#xA;        &#34;version&#34;: &#34;1.6.3-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;dpQG/pUwAqVv1OdQqnvylQ==&#34;: {&#xA;      &#34;id&#34;: &#34;dpQG/pUwAqVv1OdQqnvylQ==&#34;,&#xA;      &#34;name&#34;: &#34;libsigsegv&#34;,&#xA;      &#34;version&#34;: &#34;2.13-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libsigsegv&#34;,&#xA;        &#34;version&#34;: &#34;2.13-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;e+CtHsEaBCLbHEFWXwHRyg==&#34;: {&#xA;      &#34;id&#34;: &#34;e+CtHsEaBCLbHEFWXwHRyg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-base&#34;,&#xA;      &#34;version&#34;: &#34;2.27-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;e40n/77uWc/t2R+0m7WchA==&#34;: {&#xA;      &#34;id&#34;: &#34;e40n/77uWc/t2R+0m7WchA==&#34;,&#xA;      &#34;name&#34;: &#34;glibc-common&#34;,&#xA;      &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;e7W78NrdwYaVEcBcXhDv5Q==&#34;: {&#xA;      &#34;id&#34;: &#34;e7W78NrdwYaVEcBcXhDv5Q==&#34;,&#xA;      &#34;name&#34;: &#34;libcomps&#34;,&#xA;      &#34;version&#34;: &#34;0.1.18-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libcomps&#34;,&#xA;        &#34;version&#34;: &#34;0.1.18-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;e9e6iwwufr2qvMYpuZgq7Q==&#34;: {&#xA;      &#34;id&#34;: &#34;e9e6iwwufr2qvMYpuZgq7Q==&#34;,&#xA;      &#34;name&#34;: &#34;elfutils-libs&#34;,&#xA;      &#34;version&#34;: &#34;0.193-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;elfutils&#34;,&#xA;        &#34;version&#34;: &#34;0.193-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;eEjpOxWkwvzzJN5kkeVUcg==&#34;: {&#xA;      &#34;id&#34;: &#34;eEjpOxWkwvzzJN5kkeVUcg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Encode&#34;,&#xA;      &#34;version&#34;: &#34;4:3.08-462.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Encode&#34;,&#xA;        &#34;version&#34;: &#34;3.08-462.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;eRa7MZyiHBvsv7GPhkGKdg==&#34;: {&#xA;      &#34;id&#34;: &#34;eRa7MZyiHBvsv7GPhkGKdg==&#34;,&#xA;      &#34;name&#34;: &#34;lua-libs&#34;,&#xA;      &#34;version&#34;: &#34;5.4.4-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;lua&#34;,&#xA;        &#34;version&#34;: &#34;5.4.4-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ejmVM2MTGmDkkntlZCpYEw==&#34;: {&#xA;      &#34;id&#34;: &#34;ejmVM2MTGmDkkntlZCpYEw==&#34;,&#xA;      &#34;name&#34;: &#34;dbus-common&#34;,&#xA;      &#34;version&#34;: &#34;1:1.12.20-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dbus&#34;,&#xA;        &#34;version&#34;: &#34;1.12.20-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ev4LjEwclLnf3ehIi3l8oA==&#34;: {&#xA;      &#34;id&#34;: &#34;ev4LjEwclLnf3ehIi3l8oA==&#34;,&#xA;      &#34;name&#34;: &#34;sqlite-libs&#34;,&#xA;      &#34;version&#34;: &#34;3.34.1-9.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;sqlite&#34;,&#xA;        &#34;version&#34;: &#34;3.34.1-9.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ewbqmzgK8Rzf739yT7IKUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;ewbqmzgK8Rzf739yT7IKUQ==&#34;,&#xA;      &#34;name&#34;: &#34;ncurses-base&#34;,&#xA;      &#34;version&#34;: &#34;6.2-12.20210508.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ncurses&#34;,&#xA;        &#34;version&#34;: &#34;6.2-12.20210508.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ez3E/Jxg/MQLUXOYIN/OlQ==&#34;: {&#xA;      &#34;id&#34;: &#34;ez3E/Jxg/MQLUXOYIN/OlQ==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/s2i-core&#34;,&#xA;      &#34;version&#34;: &#34;1764601991&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;BLrNfmomqpFT8qecLZ99jQ==&#34;,&#xA;        &#34;name&#34;: &#34;ubi9/s2i-core&#34;,&#xA;        &#34;version&#34;: &#34;1764601991&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;source&#34;: {&#xA;          &#34;id&#34;: &#34;&#34;,&#xA;          &#34;name&#34;: &#34;&#34;,&#xA;          &#34;version&#34;: &#34;&#34;,&#xA;          &#34;normalized_version&#34;: &#34;&#34;,&#xA;          &#34;cpe&#34;: &#34;&#34;,&#xA;          &#34;detector&#34;: null&#xA;        },&#xA;        &#34;normalized_version&#34;: &#34;unmatchable:1764601991.0.0.0.0.0.0.0.0.0&#34;,&#xA;        &#34;arch&#34;: &#34;x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764601991.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;f2GhXCi0MGW6C5vh1ih8XQ==&#34;: {&#xA;      &#34;id&#34;: &#34;f2GhXCi0MGW6C5vh1ih8XQ==&#34;,&#xA;      &#34;name&#34;: &#34;perl-threads&#34;,&#xA;      &#34;version&#34;: &#34;1:2.25-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-threads&#34;,&#xA;        &#34;version&#34;: &#34;2.25-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;f3K2r1U+QmHjsUiML4ziOQ==&#34;: {&#xA;      &#34;id&#34;: &#34;f3K2r1U+QmHjsUiML4ziOQ==&#34;,&#xA;      &#34;name&#34;: &#34;perl-subs&#34;,&#xA;      &#34;version&#34;: &#34;1.03-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;f86Wc3apFCnJqkXk60X7Cw==&#34;: {&#xA;      &#34;id&#34;: &#34;f86Wc3apFCnJqkXk60X7Cw==&#34;,&#xA;      &#34;name&#34;: &#34;git&#34;,&#xA;      &#34;version&#34;: &#34;2.47.3-1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;git&#34;,&#xA;        &#34;version&#34;: &#34;2.47.3-1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;fDuwmXmKOYEK5h1q2eODXQ==&#34;: {&#xA;      &#34;id&#34;: &#34;fDuwmXmKOYEK5h1q2eODXQ==&#34;,&#xA;      &#34;name&#34;: &#34;python3-urllib3&#34;,&#xA;      &#34;version&#34;: &#34;1.26.5-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-urllib3&#34;,&#xA;        &#34;version&#34;: &#34;1.26.5-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;fVq3Liql8bu1Y+KmIvpQoA==&#34;: {&#xA;      &#34;id&#34;: &#34;fVq3Liql8bu1Y+KmIvpQoA==&#34;,&#xA;      &#34;name&#34;: &#34;rubygem-rdoc&#34;,&#xA;      &#34;version&#34;: &#34;6.6.3.1-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;fao+yXdp7lvp4+d732rCkw==&#34;: {&#xA;      &#34;id&#34;: &#34;fao+yXdp7lvp4+d732rCkw==&#34;,&#xA;      &#34;name&#34;: &#34;libblkid-devel&#34;,&#xA;      &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;gBWlSWdEA8U1+Ep4A/+M2g==&#34;: {&#xA;      &#34;id&#34;: &#34;gBWlSWdEA8U1+Ep4A/+M2g==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Error&#34;,&#xA;      &#34;version&#34;: &#34;1:0.17029-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Error&#34;,&#xA;        &#34;version&#34;: &#34;0.17029-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;gJHwCqer7Rl9ijGK6wpg4A==&#34;: {&#xA;      &#34;id&#34;: &#34;gJHwCqer7Rl9ijGK6wpg4A==&#34;,&#xA;      &#34;name&#34;: &#34;libICE&#34;,&#xA;      &#34;version&#34;: &#34;1.0.10-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libICE&#34;,&#xA;        &#34;version&#34;: &#34;1.0.10-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;gihIEYR/lLwr4ndjyvVROA==&#34;: {&#xA;      &#34;id&#34;: &#34;gihIEYR/lLwr4ndjyvVROA==&#34;,&#xA;      &#34;name&#34;: &#34;ruby&#34;,&#xA;      &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;gjJq4XQiX28zDnKvnb0/jg==&#34;: {&#xA;      &#34;id&#34;: &#34;gjJq4XQiX28zDnKvnb0/jg==&#34;,&#xA;      &#34;name&#34;: &#34;libfdisk&#34;,&#xA;      &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;gngAZQYf0zy4+w3GwgpLmw==&#34;: {&#xA;      &#34;id&#34;: &#34;gngAZQYf0zy4+w3GwgpLmw==&#34;,&#xA;      &#34;name&#34;: &#34;python3-libcomps&#34;,&#xA;      &#34;version&#34;: &#34;0.1.18-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libcomps&#34;,&#xA;        &#34;version&#34;: &#34;0.1.18-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;gsKPriszRNKAqMnHK+dXgw==&#34;: {&#xA;      &#34;id&#34;: &#34;gsKPriszRNKAqMnHK+dXgw==&#34;,&#xA;      &#34;name&#34;: &#34;libksba&#34;,&#xA;      &#34;version&#34;: &#34;1.5.1-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libksba&#34;,&#xA;        &#34;version&#34;: &#34;1.5.1-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;hKJ3xmpaes4B2vxd2C5M1Q==&#34;: {&#xA;      &#34;id&#34;: &#34;hKJ3xmpaes4B2vxd2C5M1Q==&#34;,&#xA;      &#34;name&#34;: &#34;ocaml-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;6-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ocaml-srpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;6-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;hWZOSd0A+iLGAwoMoW6sgw==&#34;: {&#xA;      &#34;id&#34;: &#34;hWZOSd0A+iLGAwoMoW6sgw==&#34;,&#xA;      &#34;name&#34;: &#34;systemd&#34;,&#xA;      &#34;version&#34;: &#34;252-55.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd&#34;,&#xA;        &#34;version&#34;: &#34;252-55.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;hYEisV19Dxn4PvCvxJFm5A==&#34;: {&#xA;      &#34;id&#34;: &#34;hYEisV19Dxn4PvCvxJFm5A==&#34;,&#xA;      &#34;name&#34;: &#34;lz4-libs&#34;,&#xA;      &#34;version&#34;: &#34;1.9.3-5.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;lz4&#34;,&#xA;        &#34;version&#34;: &#34;1.9.3-5.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;hgsVhmCR+D+pPaE1yMWDsg==&#34;: {&#xA;      &#34;id&#34;: &#34;hgsVhmCR+D+pPaE1yMWDsg==&#34;,&#xA;      &#34;name&#34;: &#34;libicu-devel&#34;,&#xA;      &#34;version&#34;: &#34;67.1-10.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;icu&#34;,&#xA;        &#34;version&#34;: &#34;67.1-10.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;hjikQWtnmVPaWts63wYw4Q==&#34;: {&#xA;      &#34;id&#34;: &#34;hjikQWtnmVPaWts63wYw4Q==&#34;,&#xA;      &#34;name&#34;: &#34;passwd&#34;,&#xA;      &#34;version&#34;: &#34;0.80-12.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;passwd&#34;,&#xA;        &#34;version&#34;: &#34;0.80-12.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;hktk4wXij5O6pY5X6Pdp/Q==&#34;: {&#xA;      &#34;id&#34;: &#34;hktk4wXij5O6pY5X6Pdp/Q==&#34;,&#xA;      &#34;name&#34;: &#34;elfutils-debuginfod-client&#34;,&#xA;      &#34;version&#34;: &#34;0.193-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;elfutils&#34;,&#xA;        &#34;version&#34;: &#34;0.193-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;iMLMqCcRXnm6QslpJnCS7w==&#34;: {&#xA;      &#34;id&#34;: &#34;iMLMqCcRXnm6QslpJnCS7w==&#34;,&#xA;      &#34;name&#34;: &#34;cairo&#34;,&#xA;      &#34;version&#34;: &#34;1.17.4-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;cairo&#34;,&#xA;        &#34;version&#34;: &#34;1.17.4-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;iQByZpdRXgW/fl3SoDuoAA==&#34;: {&#xA;      &#34;id&#34;: &#34;iQByZpdRXgW/fl3SoDuoAA==&#34;,&#xA;      &#34;name&#34;: &#34;libipt&#34;,&#xA;      &#34;version&#34;: &#34;2.0.4-5.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libipt&#34;,&#xA;        &#34;version&#34;: &#34;2.0.4-5.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ipG1YUFrN7KyPdU8o+2M6Q==&#34;: {&#xA;      &#34;id&#34;: &#34;ipG1YUFrN7KyPdU8o+2M6Q==&#34;,&#xA;      &#34;name&#34;: &#34;libicu&#34;,&#xA;      &#34;version&#34;: &#34;67.1-10.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;icu&#34;,&#xA;        &#34;version&#34;: &#34;67.1-10.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;irdTBCwmsDefJyVDw+cS3A==&#34;: {&#xA;      &#34;id&#34;: &#34;irdTBCwmsDefJyVDw+cS3A==&#34;,&#xA;      &#34;name&#34;: &#34;ima-evm-utils&#34;,&#xA;      &#34;version&#34;: &#34;1.6.2-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ima-evm-utils&#34;,&#xA;        &#34;version&#34;: &#34;1.6.2-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;isMk2o0BvgtLnlqdbo7sxQ==&#34;: {&#xA;      &#34;id&#34;: &#34;isMk2o0BvgtLnlqdbo7sxQ==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/ubi&#34;,&#xA;      &#34;version&#34;: &#34;1764578730&#34;,&#xA;      &#34;kind&#34;: &#34;source&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764578730.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;iswhVSntR4QnIsTAyM6ydQ==&#34;: {&#xA;      &#34;id&#34;: &#34;iswhVSntR4QnIsTAyM6ydQ==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Pod-Escapes&#34;,&#xA;      &#34;version&#34;: &#34;1:1.07-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Pod-Escapes&#34;,&#xA;        &#34;version&#34;: &#34;1.07-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ix3lD4/Nn7qLbcpDm0AIhg==&#34;: {&#xA;      &#34;id&#34;: &#34;ix3lD4/Nn7qLbcpDm0AIhg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-constant&#34;,&#xA;      &#34;version&#34;: &#34;1.33-461.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-constant&#34;,&#xA;        &#34;version&#34;: &#34;1.33-461.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;izKk4aK07ZN99JT+tBsSBg==&#34;: {&#xA;      &#34;id&#34;: &#34;izKk4aK07ZN99JT+tBsSBg==&#34;,&#xA;      &#34;name&#34;: &#34;libpq&#34;,&#xA;      &#34;version&#34;: &#34;13.20-1.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpq&#34;,&#xA;        &#34;version&#34;: &#34;13.20-1.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;j+mzBjs+9Rp1lGL7uVd5sA==&#34;: {&#xA;      &#34;id&#34;: &#34;j+mzBjs+9Rp1lGL7uVd5sA==&#34;,&#xA;      &#34;name&#34;: &#34;llvm-libs&#34;,&#xA;      &#34;version&#34;: &#34;20.1.8-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;llvm&#34;,&#xA;        &#34;version&#34;: &#34;20.1.8-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;j3sZgUo/K49ejMiEqbRAtg==&#34;: {&#xA;      &#34;id&#34;: &#34;j3sZgUo/K49ejMiEqbRAtg==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/s2i-base&#34;,&#xA;      &#34;version&#34;: &#34;1764621512&#34;,&#xA;      &#34;kind&#34;: &#34;ancestry&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;ck/z6XzYDT2o8eVJI5IO+Q==&#34;,&#xA;        &#34;name&#34;: &#34;ubi9/s2i-base&#34;,&#xA;        &#34;version&#34;: &#34;1764621512&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;source&#34;: {&#xA;          &#34;id&#34;: &#34;&#34;,&#xA;          &#34;name&#34;: &#34;&#34;,&#xA;          &#34;version&#34;: &#34;&#34;,&#xA;          &#34;normalized_version&#34;: &#34;&#34;,&#xA;          &#34;cpe&#34;: &#34;&#34;,&#xA;          &#34;detector&#34;: null&#xA;        },&#xA;        &#34;normalized_version&#34;: &#34;unmatchable:1764621512.0.0.0.0.0.0.0.0.0&#34;,&#xA;        &#34;arch&#34;: &#34;x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764621512.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;j5f/exLQUf/AfnuQvtw1ag==&#34;: {&#xA;      &#34;id&#34;: &#34;j5f/exLQUf/AfnuQvtw1ag==&#34;,&#xA;      &#34;name&#34;: &#34;perl-overload&#34;,&#xA;      &#34;version&#34;: &#34;1.31-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;jAjaNW7NMGiv7HfByDu4RQ==&#34;: {&#xA;      &#34;id&#34;: &#34;jAjaNW7NMGiv7HfByDu4RQ==&#34;,&#xA;      &#34;name&#34;: &#34;alternatives&#34;,&#xA;      &#34;version&#34;: &#34;1.24-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;chkconfig&#34;,&#xA;        &#34;version&#34;: &#34;1.24-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;jDIVpAdvhjPN/gmOBNQuag==&#34;: {&#xA;      &#34;id&#34;: &#34;jDIVpAdvhjPN/gmOBNQuag==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Time-Local&#34;,&#xA;      &#34;version&#34;: &#34;2:1.300-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Time-Local&#34;,&#xA;        &#34;version&#34;: &#34;1.300-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;jDR7o2j2gfJePh/5YNDLjw==&#34;: {&#xA;      &#34;id&#34;: &#34;jDR7o2j2gfJePh/5YNDLjw==&#34;,&#xA;      &#34;name&#34;: &#34;systemd-pam&#34;,&#xA;      &#34;version&#34;: &#34;252-55.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd&#34;,&#xA;        &#34;version&#34;: &#34;252-55.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;jH43ZEoPP2TpNiUJXUizMw==&#34;: {&#xA;      &#34;id&#34;: &#34;jH43ZEoPP2TpNiUJXUizMw==&#34;,&#xA;      &#34;name&#34;: &#34;libutempter&#34;,&#xA;      &#34;version&#34;: &#34;1.2.1-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libutempter&#34;,&#xA;        &#34;version&#34;: &#34;1.2.1-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;jMxy8GAhrrA2mTT5vqlfcg==&#34;: {&#xA;      &#34;id&#34;: &#34;jMxy8GAhrrA2mTT5vqlfcg==&#34;,&#xA;      &#34;name&#34;: &#34;gcc&#34;,&#xA;      &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gcc&#34;,&#xA;        &#34;version&#34;: &#34;11.5.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;jXo3rXdhdYGkiXYZpQxZ3Q==&#34;: {&#xA;      &#34;id&#34;: &#34;jXo3rXdhdYGkiXYZpQxZ3Q==&#34;,&#xA;      &#34;name&#34;: &#34;python3-chardet&#34;,&#xA;      &#34;version&#34;: &#34;4.0.0-5.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-chardet&#34;,&#xA;        &#34;version&#34;: &#34;4.0.0-5.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;jrYNd66NtmHdHhjnoxRx/A==&#34;: {&#xA;      &#34;id&#34;: &#34;jrYNd66NtmHdHhjnoxRx/A==&#34;,&#xA;      &#34;name&#34;: &#34;perl-FileHandle&#34;,&#xA;      &#34;version&#34;: &#34;2.03-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;kDzRHkg3txncDWuyd5771g==&#34;: {&#xA;      &#34;id&#34;: &#34;kDzRHkg3txncDWuyd5771g==&#34;,&#xA;      &#34;name&#34;: &#34;fontconfig&#34;,&#xA;      &#34;version&#34;: &#34;2.14.0-2.el9_1&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;fontconfig&#34;,&#xA;        &#34;version&#34;: &#34;2.14.0-2.el9_1&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;kFxhSjWy84mTZBM4XiZaeQ==&#34;: {&#xA;      &#34;id&#34;: &#34;kFxhSjWy84mTZBM4XiZaeQ==&#34;,&#xA;      &#34;name&#34;: &#34;setup&#34;,&#xA;      &#34;version&#34;: &#34;2.13.7-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;setup&#34;,&#xA;        &#34;version&#34;: &#34;2.13.7-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;kQDs6otjkbsijCAC8Ln06g==&#34;: {&#xA;      &#34;id&#34;: &#34;kQDs6otjkbsijCAC8Ln06g==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/ubi&#34;,&#xA;      &#34;version&#34;: &#34;1764578730&#34;,&#xA;      &#34;kind&#34;: &#34;ancestry&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;isMk2o0BvgtLnlqdbo7sxQ==&#34;,&#xA;        &#34;name&#34;: &#34;ubi9/ubi&#34;,&#xA;        &#34;version&#34;: &#34;1764578730&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;source&#34;: {&#xA;          &#34;id&#34;: &#34;&#34;,&#xA;          &#34;name&#34;: &#34;&#34;,&#xA;          &#34;version&#34;: &#34;&#34;,&#xA;          &#34;normalized_version&#34;: &#34;&#34;,&#xA;          &#34;cpe&#34;: &#34;&#34;,&#xA;          &#34;detector&#34;: null&#xA;        },&#xA;        &#34;normalized_version&#34;: &#34;unmatchable:1764578730.0.0.0.0.0.0.0.0.0&#34;,&#xA;        &#34;arch&#34;: &#34;x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764578730.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;kigiD4fuysu8/DeCr+ONKQ==&#34;: {&#xA;      &#34;id&#34;: &#34;kigiD4fuysu8/DeCr+ONKQ==&#34;,&#xA;      &#34;name&#34;: &#34;basesystem&#34;,&#xA;      &#34;version&#34;: &#34;11-13.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;basesystem&#34;,&#xA;        &#34;version&#34;: &#34;11-13.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;kp6BaioAZ30jbVeZkkzokA==&#34;: {&#xA;      &#34;id&#34;: &#34;kp6BaioAZ30jbVeZkkzokA==&#34;,&#xA;      &#34;name&#34;: &#34;libzstd&#34;,&#xA;      &#34;version&#34;: &#34;1.5.5-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;zstd&#34;,&#xA;        &#34;version&#34;: &#34;1.5.5-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;kqjucdtmnvYZVSGwSyc0aA==&#34;: {&#xA;      &#34;id&#34;: &#34;kqjucdtmnvYZVSGwSyc0aA==&#34;,&#xA;      &#34;name&#34;: &#34;iproute&#34;,&#xA;      &#34;version&#34;: &#34;6.14.0-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;iproute&#34;,&#xA;        &#34;version&#34;: &#34;6.14.0-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;l36Y8lL0dC04c9AnKIpOCw==&#34;: {&#xA;      &#34;id&#34;: &#34;l36Y8lL0dC04c9AnKIpOCw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-vars&#34;,&#xA;      &#34;version&#34;: &#34;1.05-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;lCuOAKu3TEbLIlxlfIdxkg==&#34;: {&#xA;      &#34;id&#34;: &#34;lCuOAKu3TEbLIlxlfIdxkg==&#34;,&#xA;      &#34;name&#34;: &#34;diff-lcs&#34;,&#xA;      &#34;version&#34;: &#34;1.6.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;lNWcYbl6h71sUZV6B4E+bw==&#34;: {&#xA;      &#34;id&#34;: &#34;lNWcYbl6h71sUZV6B4E+bw==&#34;,&#xA;      &#34;name&#34;: &#34;pkgconf-m4&#34;,&#xA;      &#34;version&#34;: &#34;1.7.3-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pkgconf&#34;,&#xA;        &#34;version&#34;: &#34;1.7.3-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;lV2MRz2nTh21rS47LJ6XIQ==&#34;: {&#xA;      &#34;id&#34;: &#34;lV2MRz2nTh21rS47LJ6XIQ==&#34;,&#xA;      &#34;name&#34;: &#34;python3-pip-wheel&#34;,&#xA;      &#34;version&#34;: &#34;21.3.1-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-pip&#34;,&#xA;        &#34;version&#34;: &#34;21.3.1-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;lbcitH3ttNejz+IVDee9kA==&#34;: {&#xA;      &#34;id&#34;: &#34;lbcitH3ttNejz+IVDee9kA==&#34;,&#xA;      &#34;name&#34;: &#34;dnf-data&#34;,&#xA;      &#34;version&#34;: &#34;4.14.0-31.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dnf&#34;,&#xA;        &#34;version&#34;: &#34;4.14.0-31.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;lqKUNuoxzC8zSaSnPi26WQ==&#34;: {&#xA;      &#34;id&#34;: &#34;lqKUNuoxzC8zSaSnPi26WQ==&#34;,&#xA;      &#34;name&#34;: &#34;perl-overloading&#34;,&#xA;      &#34;version&#34;: &#34;0.02-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;m7hOFCjo7x6PMvux7htFOg==&#34;: {&#xA;      &#34;id&#34;: &#34;m7hOFCjo7x6PMvux7htFOg==&#34;,&#xA;      &#34;name&#34;: &#34;cracklib-dicts&#34;,&#xA;      &#34;version&#34;: &#34;2.9.6-27.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;cracklib&#34;,&#xA;        &#34;version&#34;: &#34;2.9.6-27.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;mK/FUfODp3MR7WS2xegPsw==&#34;: {&#xA;      &#34;id&#34;: &#34;mK/FUfODp3MR7WS2xegPsw==&#34;,&#xA;      &#34;name&#34;: &#34;langpacks-core-en&#34;,&#xA;      &#34;version&#34;: &#34;3.0-16.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;langpacks&#34;,&#xA;        &#34;version&#34;: &#34;3.0-16.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;mPqGnMbiXN6jP61aGbHvOA==&#34;: {&#xA;      &#34;id&#34;: &#34;mPqGnMbiXN6jP61aGbHvOA==&#34;,&#xA;      &#34;name&#34;: &#34;libyaml&#34;,&#xA;      &#34;version&#34;: &#34;0.2.5-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libyaml&#34;,&#xA;        &#34;version&#34;: &#34;0.2.5-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;mWpxQAUiV6nN451/LkTR5w==&#34;: {&#xA;      &#34;id&#34;: &#34;mWpxQAUiV6nN451/LkTR5w==&#34;,&#xA;      &#34;name&#34;: &#34;git-core&#34;,&#xA;      &#34;version&#34;: &#34;2.47.3-1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;git&#34;,&#xA;        &#34;version&#34;: &#34;2.47.3-1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;mkPyuhaF03PTIjEd+8p5XQ==&#34;: {&#xA;      &#34;id&#34;: &#34;mkPyuhaF03PTIjEd+8p5XQ==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/s2i-base&#34;,&#xA;      &#34;version&#34;: &#34;1764621512&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;ck/z6XzYDT2o8eVJI5IO+Q==&#34;,&#xA;        &#34;name&#34;: &#34;ubi9/s2i-base&#34;,&#xA;        &#34;version&#34;: &#34;1764621512&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;source&#34;: {&#xA;          &#34;id&#34;: &#34;&#34;,&#xA;          &#34;name&#34;: &#34;&#34;,&#xA;          &#34;version&#34;: &#34;&#34;,&#xA;          &#34;normalized_version&#34;: &#34;&#34;,&#xA;          &#34;cpe&#34;: &#34;&#34;,&#xA;          &#34;detector&#34;: null&#xA;        },&#xA;        &#34;normalized_version&#34;: &#34;unmatchable:1764621512.0.0.0.0.0.0.0.0.0&#34;,&#xA;        &#34;arch&#34;: &#34;x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764621512.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;mqINnrlOZQGPnpnT9GZG5w==&#34;: {&#xA;      &#34;id&#34;: &#34;mqINnrlOZQGPnpnT9GZG5w==&#34;,&#xA;      &#34;name&#34;: &#34;rubygem-bundler&#34;,&#xA;      &#34;version&#34;: &#34;2.5.22-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;mx/6FfeunMu7M9pQ9cRKkQ==&#34;: {&#xA;      &#34;id&#34;: &#34;mx/6FfeunMu7M9pQ9cRKkQ==&#34;,&#xA;      &#34;name&#34;: &#34;glib2-devel&#34;,&#xA;      &#34;version&#34;: &#34;2.68.4-18.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;2.68.4-18.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;n9GoYS9J7jkIET4QDQWijA==&#34;: {&#xA;      &#34;id&#34;: &#34;n9GoYS9J7jkIET4QDQWijA==&#34;,&#xA;      &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;      &#34;version&#34;: &#34;1:3.5.1-4.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;3.5.1-4.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;na4ojyfFHL07xf5Yr8wxsg==&#34;: {&#xA;      &#34;id&#34;: &#34;na4ojyfFHL07xf5Yr8wxsg==&#34;,&#xA;      &#34;name&#34;: &#34;libgpg-error-devel&#34;,&#xA;      &#34;version&#34;: &#34;1.42-5.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libgpg-error&#34;,&#xA;        &#34;version&#34;: &#34;1.42-5.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;niOKQxfAYGHJ3oUq3VHjdA==&#34;: {&#xA;      &#34;id&#34;: &#34;niOKQxfAYGHJ3oUq3VHjdA==&#34;,&#xA;      &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;      &#34;version&#34;: &#34;1:22.19.0-2.module+el9.6.0+23473+45664c2d&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;22.19.0-2.module+el9.6.0+23473+45664c2d&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;nqniqNEVhrfub8cS+os87A==&#34;: {&#xA;      &#34;id&#34;: &#34;nqniqNEVhrfub8cS+os87A==&#34;,&#xA;      &#34;name&#34;: &#34;fonts-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;1:2.0.5-7.el9.1&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;fonts-rpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;2.0.5-7.el9.1&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;nuIyutUqK6hTmg/S9ojklw==&#34;: {&#xA;      &#34;id&#34;: &#34;nuIyutUqK6hTmg/S9ojklw==&#34;,&#xA;      &#34;name&#34;: &#34;yum&#34;,&#xA;      &#34;version&#34;: &#34;4.14.0-31.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dnf&#34;,&#xA;        &#34;version&#34;: &#34;4.14.0-31.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;nzQEyt4JfkGeZIIHPiBhog==&#34;: {&#xA;      &#34;id&#34;: &#34;nzQEyt4JfkGeZIIHPiBhog==&#34;,&#xA;      &#34;name&#34;: &#34;libuuid&#34;,&#xA;      &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;oIqBLVUdTw3vIPAyQdS/tA==&#34;: {&#xA;      &#34;id&#34;: &#34;oIqBLVUdTw3vIPAyQdS/tA==&#34;,&#xA;      &#34;name&#34;: &#34;python3-subscription-manager-rhsm&#34;,&#xA;      &#34;version&#34;: &#34;1.29.47.1-1.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;subscription-manager&#34;,&#xA;        &#34;version&#34;: &#34;1.29.47.1-1.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;oK41W21MyjS/j+5BoCQjuA==&#34;: {&#xA;      &#34;id&#34;: &#34;oK41W21MyjS/j+5BoCQjuA==&#34;,&#xA;      &#34;name&#34;: &#34;tcl&#34;,&#xA;      &#34;version&#34;: &#34;1:8.6.10-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tcl&#34;,&#xA;        &#34;version&#34;: &#34;8.6.10-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;obNuQXzAwE3TzjUoRN1yEw==&#34;: {&#xA;      &#34;id&#34;: &#34;obNuQXzAwE3TzjUoRN1yEw==&#34;,&#xA;      &#34;name&#34;: &#34;libbabeltrace&#34;,&#xA;      &#34;version&#34;: &#34;1.5.8-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;babeltrace&#34;,&#xA;        &#34;version&#34;: &#34;1.5.8-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;osuCNzTJ+Fjh0P4Yfe9E1g==&#34;: {&#xA;      &#34;id&#34;: &#34;osuCNzTJ+Fjh0P4Yfe9E1g==&#34;,&#xA;      &#34;name&#34;: &#34;python3-setuptools&#34;,&#xA;      &#34;version&#34;: &#34;53.0.0-15.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-setuptools&#34;,&#xA;        &#34;version&#34;: &#34;53.0.0-15.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;p9E62zY/VzvgMSvTX9UkJg==&#34;: {&#xA;      &#34;id&#34;: &#34;p9E62zY/VzvgMSvTX9UkJg==&#34;,&#xA;      &#34;name&#34;: &#34;crypto-policies-scripts&#34;,&#xA;      &#34;version&#34;: &#34;20250905-1.git377cc42.el9_7&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;crypto-policies&#34;,&#xA;        &#34;version&#34;: &#34;20250905-1.git377cc42.el9_7&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;q4zKXqPU+5vLvZLEG6zEXw==&#34;: {&#xA;      &#34;id&#34;: &#34;q4zKXqPU+5vLvZLEG6zEXw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Getopt-Std&#34;,&#xA;      &#34;version&#34;: &#34;1.12-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;q8h8ag3Ho33Zc/60lMOvVA==&#34;: {&#xA;      &#34;id&#34;: &#34;q8h8ag3Ho33Zc/60lMOvVA==&#34;,&#xA;      &#34;name&#34;: &#34;unzip&#34;,&#xA;      &#34;version&#34;: &#34;6.0-59.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;unzip&#34;,&#xA;        &#34;version&#34;: &#34;6.0-59.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;qGKV3oqLguMWpyzvjv1+wg==&#34;: {&#xA;      &#34;id&#34;: &#34;qGKV3oqLguMWpyzvjv1+wg==&#34;,&#xA;      &#34;name&#34;: &#34;libtiff-devel&#34;,&#xA;      &#34;version&#34;: &#34;4.4.0-15.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtiff&#34;,&#xA;        &#34;version&#34;: &#34;4.4.0-15.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;qKN/Sy8G7n1xl+F5J1m1bg==&#34;: {&#xA;      &#34;id&#34;: &#34;qKN/Sy8G7n1xl+F5J1m1bg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-File-Copy&#34;,&#xA;      &#34;version&#34;: &#34;2.34-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;qYSZ6aKFWol313IOGRXaug==&#34;: {&#xA;      &#34;id&#34;: &#34;qYSZ6aKFWol313IOGRXaug==&#34;,&#xA;      &#34;name&#34;: &#34;json-c&#34;,&#xA;      &#34;version&#34;: &#34;0.14-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;json-c&#34;,&#xA;        &#34;version&#34;: &#34;0.14-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;qc0Yt1AzZC+CY6qdjO+fZA==&#34;: {&#xA;      &#34;id&#34;: &#34;qc0Yt1AzZC+CY6qdjO+fZA==&#34;,&#xA;      &#34;name&#34;: &#34;python3-idna&#34;,&#xA;      &#34;version&#34;: &#34;2.10-7.el9_4.1&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-idna&#34;,&#xA;        &#34;version&#34;: &#34;2.10-7.el9_4.1&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;qco/AqMt9denZ9GeHFnEaA==&#34;: {&#xA;      &#34;id&#34;: &#34;qco/AqMt9denZ9GeHFnEaA==&#34;,&#xA;      &#34;name&#34;: &#34;libbpf&#34;,&#xA;      &#34;version&#34;: &#34;2:1.5.0-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libbpf&#34;,&#xA;        &#34;version&#34;: &#34;1.5.0-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;qklPItzKPipAd2a3RHZZIA==&#34;: {&#xA;      &#34;id&#34;: &#34;qklPItzKPipAd2a3RHZZIA==&#34;,&#xA;      &#34;name&#34;: &#34;libfido2&#34;,&#xA;      &#34;version&#34;: &#34;1.13.0-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libfido2&#34;,&#xA;        &#34;version&#34;: &#34;1.13.0-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;qsJmM3aYeYGdvjHxtaNdaQ==&#34;: {&#xA;      &#34;id&#34;: &#34;qsJmM3aYeYGdvjHxtaNdaQ==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Errno&#34;,&#xA;      &#34;version&#34;: &#34;1.30-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;r0GDCuRXOUGVJzCqB4JFMw==&#34;: {&#xA;      &#34;id&#34;: &#34;r0GDCuRXOUGVJzCqB4JFMw==&#34;,&#xA;      &#34;name&#34;: &#34;bzip2-devel&#34;,&#xA;      &#34;version&#34;: &#34;1.0.8-10.el9_5&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;bzip2&#34;,&#xA;        &#34;version&#34;: &#34;1.0.8-10.el9_5&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rB+tPXab1eESNe/6qy7U4Q==&#34;: {&#xA;      &#34;id&#34;: &#34;rB+tPXab1eESNe/6qy7U4Q==&#34;,&#xA;      &#34;name&#34;: &#34;boost-regex&#34;,&#xA;      &#34;version&#34;: &#34;1.75.0-12.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;boost&#34;,&#xA;        &#34;version&#34;: &#34;1.75.0-12.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rCLp3m64Catai9VuHvh3Lw==&#34;: {&#xA;      &#34;id&#34;: &#34;rCLp3m64Catai9VuHvh3Lw==&#34;,&#xA;      &#34;name&#34;: &#34;keyutils-libs&#34;,&#xA;      &#34;version&#34;: &#34;1.6.3-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;keyutils&#34;,&#xA;        &#34;version&#34;: &#34;1.6.3-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rEU0uZUpz06y9hg0ORc49A==&#34;: {&#xA;      &#34;id&#34;: &#34;rEU0uZUpz06y9hg0ORc49A==&#34;,&#xA;      &#34;name&#34;: &#34;libpwquality&#34;,&#xA;      &#34;version&#34;: &#34;1.4.4-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpwquality&#34;,&#xA;        &#34;version&#34;: &#34;1.4.4-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rOo0eaSDbJ9TZ3lifnsvSQ==&#34;: {&#xA;      &#34;id&#34;: &#34;rOo0eaSDbJ9TZ3lifnsvSQ==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/ruby-33&#34;,&#xA;      &#34;version&#34;: &#34;1764649613&#34;,&#xA;      &#34;kind&#34;: &#34;source&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764649613.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rUUieTQ6JPdOKUOFRfhvNw==&#34;: {&#xA;      &#34;id&#34;: &#34;rUUieTQ6JPdOKUOFRfhvNw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-MIME-Base64&#34;,&#xA;      &#34;version&#34;: &#34;3.16-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-MIME-Base64&#34;,&#xA;        &#34;version&#34;: &#34;3.16-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rY/kE/V4JnxYoqV+lmc9mg==&#34;: {&#xA;      &#34;id&#34;: &#34;rY/kE/V4JnxYoqV+lmc9mg==&#34;,&#xA;      &#34;name&#34;: &#34;gawk&#34;,&#xA;      &#34;version&#34;: &#34;5.1.0-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gawk&#34;,&#xA;        &#34;version&#34;: &#34;5.1.0-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rZckolqfVnE7xInGZn5Zzw==&#34;: {&#xA;      &#34;id&#34;: &#34;rZckolqfVnE7xInGZn5Zzw==&#34;,&#xA;      &#34;name&#34;: &#34;python3-pysocks&#34;,&#xA;      &#34;version&#34;: &#34;1.7.1-12.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-pysocks&#34;,&#xA;        &#34;version&#34;: &#34;1.7.1-12.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rd4/gPEUtK2p++ni1m1dDg==&#34;: {&#xA;      &#34;id&#34;: &#34;rd4/gPEUtK2p++ni1m1dDg==&#34;,&#xA;      &#34;name&#34;: &#34;libsepol&#34;,&#xA;      &#34;version&#34;: &#34;3.6-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libsepol&#34;,&#xA;        &#34;version&#34;: &#34;3.6-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rflqn7XKJvnH8dP67kgM7A==&#34;: {&#xA;      &#34;id&#34;: &#34;rflqn7XKJvnH8dP67kgM7A==&#34;,&#xA;      &#34;name&#34;: &#34;qt5-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;5.15.9-1.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;qt5&#34;,&#xA;        &#34;version&#34;: &#34;5.15.9-1.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rj2k4My0f4W7sR9R0rDeJg==&#34;: {&#xA;      &#34;id&#34;: &#34;rj2k4My0f4W7sR9R0rDeJg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Pod-Usage&#34;,&#xA;      &#34;version&#34;: &#34;4:2.01-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Pod-Usage&#34;,&#xA;        &#34;version&#34;: &#34;2.01-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;rlHYqOr0lkUB/Gs6b1kD2g==&#34;: {&#xA;      &#34;id&#34;: &#34;rlHYqOr0lkUB/Gs6b1kD2g==&#34;,&#xA;      &#34;name&#34;: &#34;mpfr&#34;,&#xA;      &#34;version&#34;: &#34;4.1.0-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;mpfr&#34;,&#xA;        &#34;version&#34;: &#34;4.1.0-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;s/zVhVCY3vRmmv6PJdGLCg==&#34;: {&#xA;      &#34;id&#34;: &#34;s/zVhVCY3vRmmv6PJdGLCg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-IO-Socket-SSL&#34;,&#xA;      &#34;version&#34;: &#34;2.073-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-IO-Socket-SSL&#34;,&#xA;        &#34;version&#34;: &#34;2.073-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;s6wkZ09Eozv3vmfwsPHUvQ==&#34;: {&#xA;      &#34;id&#34;: &#34;s6wkZ09Eozv3vmfwsPHUvQ==&#34;,&#xA;      &#34;name&#34;: &#34;systemd-rpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;252-55.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd&#34;,&#xA;        &#34;version&#34;: &#34;252-55.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;sE1EmQ5Nhv4P4rilE6lODw==&#34;: {&#xA;      &#34;id&#34;: &#34;sE1EmQ5Nhv4P4rilE6lODw==&#34;,&#xA;      &#34;name&#34;: &#34;lsof&#34;,&#xA;      &#34;version&#34;: &#34;4.94.0-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;lsof&#34;,&#xA;        &#34;version&#34;: &#34;4.94.0-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;sJhS0sL3jXf+ZUi4oTiojw==&#34;: {&#xA;      &#34;id&#34;: &#34;sJhS0sL3jXf+ZUi4oTiojw==&#34;,&#xA;      &#34;name&#34;: &#34;ruby-bundled-gems&#34;,&#xA;      &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;sREtPFILPccNXLGF49Cnmw==&#34;: {&#xA;      &#34;id&#34;: &#34;sREtPFILPccNXLGF49Cnmw==&#34;,&#xA;      &#34;name&#34;: &#34;libcurl-devel&#34;,&#xA;      &#34;version&#34;: &#34;7.76.1-34.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;7.76.1-34.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ssPaV1VLDu6d5ZJ6Rrmh3A==&#34;: {&#xA;      &#34;id&#34;: &#34;ssPaV1VLDu6d5ZJ6Rrmh3A==&#34;,&#xA;      &#34;name&#34;: &#34;sed&#34;,&#xA;      &#34;version&#34;: &#34;4.8-9.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;sed&#34;,&#xA;        &#34;version&#34;: &#34;4.8-9.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;sukNATkcLkohYgGrhDtrZA==&#34;: {&#xA;      &#34;id&#34;: &#34;sukNATkcLkohYgGrhDtrZA==&#34;,&#xA;      &#34;name&#34;: &#34;libxcrypt-devel&#34;,&#xA;      &#34;version&#34;: &#34;4.4.18-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxcrypt&#34;,&#xA;        &#34;version&#34;: &#34;4.4.18-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;sx0C6L5COHIkv6yQQyPlbw==&#34;: {&#xA;      &#34;id&#34;: &#34;sx0C6L5COHIkv6yQQyPlbw==&#34;,&#xA;      &#34;name&#34;: &#34;libunistring&#34;,&#xA;      &#34;version&#34;: &#34;0.9.10-15.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libunistring&#34;,&#xA;        &#34;version&#34;: &#34;0.9.10-15.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;t28Zc7/vifVyS7O17xTUSA==&#34;: {&#xA;      &#34;id&#34;: &#34;t28Zc7/vifVyS7O17xTUSA==&#34;,&#xA;      &#34;name&#34;: &#34;pcre-devel&#34;,&#xA;      &#34;version&#34;: &#34;8.44-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre&#34;,&#xA;        &#34;version&#34;: &#34;8.44-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;tGPn3pK3U8y547XMf1WmhQ==&#34;: {&#xA;      &#34;id&#34;: &#34;tGPn3pK3U8y547XMf1WmhQ==&#34;,&#xA;      &#34;name&#34;: &#34;glibc-gconv-extra&#34;,&#xA;      &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;2.34-231.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;tWWw65aFr0Her+B1hlgbqA==&#34;: {&#xA;      &#34;id&#34;: &#34;tWWw65aFr0Her+B1hlgbqA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Pod-Simple&#34;,&#xA;      &#34;version&#34;: &#34;1:3.42-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Pod-Simple&#34;,&#xA;        &#34;version&#34;: &#34;3.42-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;tYvC71hd5ARf4WITmeyfxA==&#34;: {&#xA;      &#34;id&#34;: &#34;tYvC71hd5ARf4WITmeyfxA==&#34;,&#xA;      &#34;name&#34;: &#34;pcre2-utf16&#34;,&#xA;      &#34;version&#34;: &#34;10.40-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre2&#34;,&#xA;        &#34;version&#34;: &#34;10.40-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;tqVXueFBgSdMZpggpUjjjA==&#34;: {&#xA;      &#34;id&#34;: &#34;tqVXueFBgSdMZpggpUjjjA==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/ruby-33&#34;,&#xA;      &#34;version&#34;: &#34;1764649613&#34;,&#xA;      &#34;kind&#34;: &#34;ancestry&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;rOo0eaSDbJ9TZ3lifnsvSQ==&#34;,&#xA;        &#34;name&#34;: &#34;ubi9/ruby-33&#34;,&#xA;        &#34;version&#34;: &#34;1764649613&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;source&#34;: {&#xA;          &#34;id&#34;: &#34;&#34;,&#xA;          &#34;name&#34;: &#34;&#34;,&#xA;          &#34;version&#34;: &#34;&#34;,&#xA;          &#34;normalized_version&#34;: &#34;&#34;,&#xA;          &#34;cpe&#34;: &#34;&#34;,&#xA;          &#34;detector&#34;: null&#xA;        },&#xA;        &#34;normalized_version&#34;: &#34;unmatchable:1764649613.0.0.0.0.0.0.0.0.0&#34;,&#xA;        &#34;arch&#34;: &#34;x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;unmatchable:1764649613.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;txEovS086NkVY5rNikpoEA==&#34;: {&#xA;      &#34;id&#34;: &#34;txEovS086NkVY5rNikpoEA==&#34;,&#xA;      &#34;name&#34;: &#34;python3-hawkey&#34;,&#xA;      &#34;version&#34;: &#34;0.69.0-16.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libdnf&#34;,&#xA;        &#34;version&#34;: &#34;0.69.0-16.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;u3thu0wHuvY+STb8TrhkKQ==&#34;: {&#xA;      &#34;id&#34;: &#34;u3thu0wHuvY+STb8TrhkKQ==&#34;,&#xA;      &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;      &#34;version&#34;: &#34;8.7p1-46.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;8.7p1-46.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;u5TyEoU5GA6Z2czzwhMLiA==&#34;: {&#xA;      &#34;id&#34;: &#34;u5TyEoU5GA6Z2czzwhMLiA==&#34;,&#xA;      &#34;name&#34;: &#34;fonts-filesystem&#34;,&#xA;      &#34;version&#34;: &#34;1:2.0.5-7.el9.1&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;fonts-rpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;2.0.5-7.el9.1&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;v3i4ez5juML2ZWwR+6dFFg==&#34;: {&#xA;      &#34;id&#34;: &#34;v3i4ez5juML2ZWwR+6dFFg==&#34;,&#xA;      &#34;name&#34;: &#34;gnupg2&#34;,&#xA;      &#34;version&#34;: &#34;2.3.3-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnupg2&#34;,&#xA;        &#34;version&#34;: &#34;2.3.3-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;v6X9Dt1wPw8fK6VaHz1Ffw==&#34;: {&#xA;      &#34;id&#34;: &#34;v6X9Dt1wPw8fK6VaHz1Ffw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-threads-shared&#34;,&#xA;      &#34;version&#34;: &#34;1.61-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-threads-shared&#34;,&#xA;        &#34;version&#34;: &#34;1.61-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;v9Q18SPC524XLCjLQkFyLg==&#34;: {&#xA;      &#34;id&#34;: &#34;v9Q18SPC524XLCjLQkFyLg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-AutoLoader&#34;,&#xA;      &#34;version&#34;: &#34;5.74-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;vtNcuXyRth8r8K/W3sfqrQ==&#34;: {&#xA;      &#34;id&#34;: &#34;vtNcuXyRth8r8K/W3sfqrQ==&#34;,&#xA;      &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;      &#34;version&#34;: &#34;2:1.6.37-12.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;1.6.37-12.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;vw1F3IS9ZqFqIEU3E24hLQ==&#34;: {&#xA;      &#34;id&#34;: &#34;vw1F3IS9ZqFqIEU3E24hLQ==&#34;,&#xA;      &#34;name&#34;: &#34;libwebp-devel&#34;,&#xA;      &#34;version&#34;: &#34;1.2.0-8.el9_3&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libwebp&#34;,&#xA;        &#34;version&#34;: &#34;1.2.0-8.el9_3&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;w2DoavvB02S/+BS01jQqJw==&#34;: {&#xA;      &#34;id&#34;: &#34;w2DoavvB02S/+BS01jQqJw==&#34;,&#xA;      &#34;name&#34;: &#34;openblas-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;2-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openblas-srpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;2-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;w9ndxjIpPQXv3PDulnya7A==&#34;: {&#xA;      &#34;id&#34;: &#34;w9ndxjIpPQXv3PDulnya7A==&#34;,&#xA;      &#34;name&#34;: &#34;libX11&#34;,&#xA;      &#34;version&#34;: &#34;1.7.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libX11&#34;,&#xA;        &#34;version&#34;: &#34;1.7.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;wCA3gMNtInqX1xg18QcnQg==&#34;: {&#xA;      &#34;id&#34;: &#34;wCA3gMNtInqX1xg18QcnQg==&#34;,&#xA;      &#34;name&#34;: &#34;ca-certificates&#34;,&#xA;      &#34;version&#34;: &#34;2024.2.69_v8.0.303-91.4.el9_4&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ca-certificates&#34;,&#xA;        &#34;version&#34;: &#34;2024.2.69_v8.0.303-91.4.el9_4&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;wVOHUaFC3qlk+Ft1W2VH7A==&#34;: {&#xA;      &#34;id&#34;: &#34;wVOHUaFC3qlk+Ft1W2VH7A==&#34;,&#xA;      &#34;name&#34;: &#34;python3-gobject-base-noarch&#34;,&#xA;      &#34;version&#34;: &#34;3.40.1-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pygobject3&#34;,&#xA;        &#34;version&#34;: &#34;3.40.1-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;wYIIhtw19AhoRPO0XAvoxw==&#34;: {&#xA;      &#34;id&#34;: &#34;wYIIhtw19AhoRPO0XAvoxw==&#34;,&#xA;      &#34;name&#34;: &#34;bsdtar&#34;,&#xA;      &#34;version&#34;: &#34;3.5.3-6.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;3.5.3-6.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;wdMozBSF06uhI4HOI003SQ==&#34;: {&#xA;      &#34;id&#34;: &#34;wdMozBSF06uhI4HOI003SQ==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Term-Cap&#34;,&#xA;      &#34;version&#34;: &#34;1.17-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Term-Cap&#34;,&#xA;        &#34;version&#34;: &#34;1.17-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;wfJGCqOH8d+IYg/dAepx1A==&#34;: {&#xA;      &#34;id&#34;: &#34;wfJGCqOH8d+IYg/dAepx1A==&#34;,&#xA;      &#34;name&#34;: &#34;libarchive&#34;,&#xA;      &#34;version&#34;: &#34;3.5.3-6.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;3.5.3-6.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;wvtx3JsOUmPyorardjeYSQ==&#34;: {&#xA;      &#34;id&#34;: &#34;wvtx3JsOUmPyorardjeYSQ==&#34;,&#xA;      &#34;name&#34;: &#34;fontconfig-devel&#34;,&#xA;      &#34;version&#34;: &#34;2.14.0-2.el9_1&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;fontconfig&#34;,&#xA;        &#34;version&#34;: &#34;2.14.0-2.el9_1&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ww1NPX/mwmdtd47p1Hp8FQ==&#34;: {&#xA;      &#34;id&#34;: &#34;ww1NPX/mwmdtd47p1Hp8FQ==&#34;,&#xA;      &#34;name&#34;: &#34;libX11-devel&#34;,&#xA;      &#34;version&#34;: &#34;1.7.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libX11&#34;,&#xA;        &#34;version&#34;: &#34;1.7.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;x4oijVhQU8BUwJwoFvk4QA==&#34;: {&#xA;      &#34;id&#34;: &#34;x4oijVhQU8BUwJwoFvk4QA==&#34;,&#xA;      &#34;name&#34;: &#34;libmodulemd&#34;,&#xA;      &#34;version&#34;: &#34;2.13.0-2.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libmodulemd&#34;,&#xA;        &#34;version&#34;: &#34;2.13.0-2.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;xGsFnJNA7f9q/+8cz1QFqg==&#34;: {&#xA;      &#34;id&#34;: &#34;xGsFnJNA7f9q/+8cz1QFqg==&#34;,&#xA;      &#34;name&#34;: &#34;lua-srpm-macros&#34;,&#xA;      &#34;version&#34;: &#34;1-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;lua-rpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;1-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;xItFXMbfthPTJh/VhaoYeA==&#34;: {&#xA;      &#34;id&#34;: &#34;xItFXMbfthPTJh/VhaoYeA==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Fcntl&#34;,&#xA;      &#34;version&#34;: &#34;1.13-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;xMqWNWDJot/UVGgOoRsUVQ==&#34;: {&#xA;      &#34;id&#34;: &#34;xMqWNWDJot/UVGgOoRsUVQ==&#34;,&#xA;      &#34;name&#34;: &#34;rubygems&#34;,&#xA;      &#34;version&#34;: &#34;3.5.22-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;xRkX4SbymzipYnnd/tIGVw==&#34;: {&#xA;      &#34;id&#34;: &#34;xRkX4SbymzipYnnd/tIGVw==&#34;,&#xA;      &#34;name&#34;: &#34;ubi9/ruby-33&#34;,&#xA;      &#34;version&#34;: &#34;1786713372&#34;,&#xA;      &#34;kind&#34;: &#34;ancestry&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;Riemnu+blxsuHCoBGaacLA==&#34;,&#xA;        &#34;name&#34;: &#34;ubi9/ruby-33&#34;,&#xA;        &#34;version&#34;: &#34;1786713372&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;source&#34;: {&#xA;          &#34;id&#34;: &#34;&#34;,&#xA;          &#34;name&#34;: &#34;&#34;,&#xA;          &#34;version&#34;: &#34;&#34;,&#xA;          &#34;normalized_version&#34;: &#34;&#34;,&#xA;          &#34;cpe&#34;: &#34;&#34;,&#xA;          &#34;detector&#34;: null&#xA;        },&#xA;        &#34;normalized_version&#34;: &#34;rhctag:1786713372.0.0.0.0.0.0.0.0.0&#34;,&#xA;        &#34;arch&#34;: &#34;x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;rhctag:1786713372.0.0.0.0.0.0.0.0.0&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;xTea8RVD9wez5DTFDIkCYg==&#34;: {&#xA;      &#34;id&#34;: &#34;xTea8RVD9wez5DTFDIkCYg==&#34;,&#xA;      &#34;name&#34;: &#34;libtiff&#34;,&#xA;      &#34;version&#34;: &#34;4.4.0-15.el9_7.2&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtiff&#34;,&#xA;        &#34;version&#34;: &#34;4.4.0-15.el9_7.2&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;xVpXFb43dZh4HfBX53yyew==&#34;: {&#xA;      &#34;id&#34;: &#34;xVpXFb43dZh4HfBX53yyew==&#34;,&#xA;      &#34;name&#34;: &#34;python3-iniparse&#34;,&#xA;      &#34;version&#34;: &#34;0.4-45.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-iniparse&#34;,&#xA;        &#34;version&#34;: &#34;0.4-45.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;xfiNHrth0bRlTgQnR3IgUw==&#34;: {&#xA;      &#34;id&#34;: &#34;xfiNHrth0bRlTgQnR3IgUw==&#34;,&#xA;      &#34;name&#34;: &#34;libpsl&#34;,&#xA;      &#34;version&#34;: &#34;0.21.1-5.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpsl&#34;,&#xA;        &#34;version&#34;: &#34;0.21.1-5.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;xgCGPQ7CZbjJqBTw2Nmu9w==&#34;: {&#xA;      &#34;id&#34;: &#34;xgCGPQ7CZbjJqBTw2Nmu9w==&#34;,&#xA;      &#34;name&#34;: &#34;groff-base&#34;,&#xA;      &#34;version&#34;: &#34;1.22.4-10.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;groff&#34;,&#xA;        &#34;version&#34;: &#34;1.22.4-10.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;xnmn6fk+/THLJg3emXYMww==&#34;: {&#xA;      &#34;id&#34;: &#34;xnmn6fk+/THLJg3emXYMww==&#34;,&#xA;      &#34;name&#34;: &#34;perl-libnet&#34;,&#xA;      &#34;version&#34;: &#34;3.13-4.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-libnet&#34;,&#xA;        &#34;version&#34;: &#34;3.13-4.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;xuRjbnwW5VkRHg0Huc5RCg==&#34;: {&#xA;      &#34;id&#34;: &#34;xuRjbnwW5VkRHg0Huc5RCg==&#34;,&#xA;      &#34;name&#34;: &#34;util-linux&#34;,&#xA;      &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;2.37.4-21.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;y9sflCLWTaHWSSC+w8u7bQ==&#34;: {&#xA;      &#34;id&#34;: &#34;y9sflCLWTaHWSSC+w8u7bQ==&#34;,&#xA;      &#34;name&#34;: &#34;xz-devel&#34;,&#xA;      &#34;version&#34;: &#34;5.2.5-8.el9_0&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;xz&#34;,&#xA;        &#34;version&#34;: &#34;5.2.5-8.el9_0&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;yEp9fQVFIQAEDPCwC3GLmA==&#34;: {&#xA;      &#34;id&#34;: &#34;yEp9fQVFIQAEDPCwC3GLmA==&#34;,&#xA;      &#34;name&#34;: &#34;libsemanage&#34;,&#xA;      &#34;version&#34;: &#34;3.6-5.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libsemanage&#34;,&#xA;        &#34;version&#34;: &#34;3.6-5.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;yHwqZ1KSVBKOdg3PvZkURg==&#34;: {&#xA;      &#34;id&#34;: &#34;yHwqZ1KSVBKOdg3PvZkURg==&#34;,&#xA;      &#34;name&#34;: &#34;perl-NDBM_File&#34;,&#xA;      &#34;version&#34;: &#34;1.15-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;yMfhY0UxLchgIpNP2r2lyQ==&#34;: {&#xA;      &#34;id&#34;: &#34;yMfhY0UxLchgIpNP2r2lyQ==&#34;,&#xA;      &#34;name&#34;: &#34;make&#34;,&#xA;      &#34;version&#34;: &#34;1:4.3-8.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;make&#34;,&#xA;        &#34;version&#34;: &#34;4.3-8.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;yY469KfvqdHWbJwmOcIU1Q==&#34;: {&#xA;      &#34;id&#34;: &#34;yY469KfvqdHWbJwmOcIU1Q==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Carp&#34;,&#xA;      &#34;version&#34;: &#34;1.50-460.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Carp&#34;,&#xA;        &#34;version&#34;: &#34;1.50-460.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;ycSS8xsUDu5nMwsql04xfQ==&#34;: {&#xA;      &#34;id&#34;: &#34;ycSS8xsUDu5nMwsql04xfQ==&#34;,&#xA;      &#34;name&#34;: &#34;gd&#34;,&#xA;      &#34;version&#34;: &#34;2.3.2-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gd&#34;,&#xA;        &#34;version&#34;: &#34;2.3.2-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;z+4p7UhT99HApht5JWOY7w==&#34;: {&#xA;      &#34;id&#34;: &#34;z+4p7UhT99HApht5JWOY7w==&#34;,&#xA;      &#34;name&#34;: &#34;libselinux-devel&#34;,&#xA;      &#34;version&#34;: &#34;3.6-3.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libselinux&#34;,&#xA;        &#34;version&#34;: &#34;3.6-3.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;zDt2Vfv35KL/GbH9JG8H3A==&#34;: {&#xA;      &#34;id&#34;: &#34;zDt2Vfv35KL/GbH9JG8H3A==&#34;,&#xA;      &#34;name&#34;: &#34;libX11-common&#34;,&#xA;      &#34;version&#34;: &#34;1.7.0-11.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libX11&#34;,&#xA;        &#34;version&#34;: &#34;1.7.0-11.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;zLbmCpiDy68qsFvtKNzmgQ==&#34;: {&#xA;      &#34;id&#34;: &#34;zLbmCpiDy68qsFvtKNzmgQ==&#34;,&#xA;      &#34;name&#34;: &#34;xml-common&#34;,&#xA;      &#34;version&#34;: &#34;0.6.3-58.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;sgml-common&#34;,&#xA;        &#34;version&#34;: &#34;0.6.3-58.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;zYkGoXzaE5np8s88FoALNQ==&#34;: {&#xA;      &#34;id&#34;: &#34;zYkGoXzaE5np8s88FoALNQ==&#34;,&#xA;      &#34;name&#34;: &#34;usermode&#34;,&#xA;      &#34;version&#34;: &#34;1.114-7.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;usermode&#34;,&#xA;        &#34;version&#34;: &#34;1.114-7.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;zbfsUtSlKsegyV6mTxR13A==&#34;: {&#xA;      &#34;id&#34;: &#34;zbfsUtSlKsegyV6mTxR13A==&#34;,&#xA;      &#34;name&#34;: &#34;dnf&#34;,&#xA;      &#34;version&#34;: &#34;4.14.0-31.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dnf&#34;,&#xA;        &#34;version&#34;: &#34;4.14.0-31.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;zfyfWkP+jPZaONI2HeiXQw==&#34;: {&#xA;      &#34;id&#34;: &#34;zfyfWkP+jPZaONI2HeiXQw==&#34;,&#xA;      &#34;name&#34;: &#34;perl-B&#34;,&#xA;      &#34;version&#34;: &#34;1.80-481.1.el9_6&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl&#34;,&#xA;        &#34;version&#34;: &#34;5.32.1-481.1.el9_6&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;zmiWZ9YjduqgYQPI8rU4ug==&#34;: {&#xA;      &#34;id&#34;: &#34;zmiWZ9YjduqgYQPI8rU4ug==&#34;,&#xA;      &#34;name&#34;: &#34;libwebp&#34;,&#xA;      &#34;version&#34;: &#34;1.2.0-8.el9_3&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libwebp&#34;,&#xA;        &#34;version&#34;: &#34;1.2.0-8.el9_3&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;x86_64&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;znACbAN0JGBPtCXNh1d0Ng==&#34;: {&#xA;      &#34;id&#34;: &#34;znACbAN0JGBPtCXNh1d0Ng==&#34;,&#xA;      &#34;name&#34;: &#34;rubygem-rake&#34;,&#xA;      &#34;version&#34;: &#34;13.1.0-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;3.3.8-4.module+el9.7.0+23096+6a95897f&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    },&#xA;    &#34;zxuLMmxubC84XoLpkfxZ3w==&#34;: {&#xA;      &#34;id&#34;: &#34;zxuLMmxubC84XoLpkfxZ3w==&#34;,&#xA;      &#34;name&#34;: &#34;perl-Mozilla-CA&#34;,&#xA;      &#34;version&#34;: &#34;20200520-6.el9&#34;,&#xA;      &#34;kind&#34;: &#34;binary&#34;,&#xA;      &#34;source&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;perl-Mozilla-CA&#34;,&#xA;        &#34;version&#34;: &#34;20200520-6.el9&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;normalized_version&#34;: &#34;&#34;,&#xA;      &#34;arch&#34;: &#34;noarch&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;,&#xA;      &#34;detector&#34;: null&#xA;    }&#xA;  },&#xA;  &#34;distributions&#34;: {&#xA;    &#34;0e229e17-d459-4174-a862-4ac814070695&#34;: {&#xA;      &#34;id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;      &#34;did&#34;: &#34;rhel&#34;,&#xA;      &#34;name&#34;: &#34;Red Hat Enterprise Linux Server&#34;,&#xA;      &#34;version&#34;: &#34;9&#34;,&#xA;      &#34;version_code_name&#34;: &#34;&#34;,&#xA;      &#34;version_id&#34;: &#34;9&#34;,&#xA;      &#34;arch&#34;: &#34;&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;      &#34;pretty_name&#34;: &#34;Red Hat Enterprise Linux Server 9&#34;&#xA;    }&#xA;  },&#xA;  &#34;repository&#34;: {&#xA;    &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;: {&#xA;      &#34;id&#34;: &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-baseos-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;094b57a8-611b-45bd-b338-0f1e3ba94b76&#34;: {&#xA;      &#34;id&#34;: &#34;094b57a8-611b-45bd-b338-0f1e3ba94b76&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-appstream-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;2ae3eccc-f14d-44e2-9b7e-ceb5684ea595&#34;: {&#xA;      &#34;id&#34;: &#34;2ae3eccc-f14d-44e2-9b7e-ceb5684ea595&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-baseos-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;49620a67-2a69-4965-87b7-cf8e91792454&#34;: {&#xA;      &#34;id&#34;: &#34;49620a67-2a69-4965-87b7-cf8e91792454&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhcc-container-repository&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;: {&#xA;      &#34;id&#34;: &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-baseos-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;624606e7-9195-428c-b44c-9a363be0d39e&#34;: {&#xA;      &#34;id&#34;: &#34;624606e7-9195-428c-b44c-9a363be0d39e&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhcc-container-repository&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;68a7ce1a-f8e4-4fc3-b254-6cbbc1f1e251&#34;: {&#xA;      &#34;id&#34;: &#34;68a7ce1a-f8e4-4fc3-b254-6cbbc1f1e251&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhcc-container-repository&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;7c0fcdb8-6748-4d51-8c0f-22d062631cfe&#34;: {&#xA;      &#34;id&#34;: &#34;7c0fcdb8-6748-4d51-8c0f-22d062631cfe&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhcc-container-repository&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;7e98fa1e-1ff8-49b5-a6d1-c48a9213af4a&#34;: {&#xA;      &#34;id&#34;: &#34;7e98fa1e-1ff8-49b5-a6d1-c48a9213af4a&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-appstream-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;81447011-d8ab-46e4-8fc1-e6abb52d52ca&#34;: {&#xA;      &#34;id&#34;: &#34;81447011-d8ab-46e4-8fc1-e6abb52d52ca&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-baseos-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;: {&#xA;      &#34;id&#34;: &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-appstream-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;: {&#xA;      &#34;id&#34;: &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-baseos-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;99dfe52b-c38e-4726-a51a-93ad820c4596&#34;: {&#xA;      &#34;id&#34;: &#34;99dfe52b-c38e-4726-a51a-93ad820c4596&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhcc-container-repository&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;: {&#xA;      &#34;id&#34;: &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-baseos-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;ac41f493-ae0a-4233-8d1f-2e3b9706fb57&#34;: {&#xA;      &#34;id&#34;: &#34;ac41f493-ae0a-4233-8d1f-2e3b9706fb57&#34;,&#xA;      &#34;name&#34;: &#34;rubygems&#34;,&#xA;      &#34;uri&#34;: &#34;https://rubygems.org/gems/&#34;,&#xA;      &#34;cpe&#34;: &#34;&#34;&#xA;    },&#xA;    &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;: {&#xA;      &#34;id&#34;: &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-baseos-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;: {&#xA;      &#34;id&#34;: &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-baseos-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;    },&#xA;    &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;: {&#xA;      &#34;id&#34;: &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;,&#xA;      &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;      &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;      &#34;uri&#34;: &#34;repoid=rhel-9-for-x86_64-appstream-rpms&#34;,&#xA;      &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;    }&#xA;  },&#xA;  &#34;environments&#34;: {&#xA;    &#34;+8b2rLdXTkZ4Ylx7vWU2tQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;+A7/nzEXX3Q/xJZ50VMnlQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;+B22ALb6YCnXu+3s6afaLg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;+ELGclZlzVhkDoWJwZc9OA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;+HmNQdmjJTL5gC4nHHd6rw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;+X1MdmtPTbyDb/wq7joJhA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;+bwl6UbMaWOBWdHNekJsEw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;+kdviPHeaPmwEsPQK85KjQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;+v/DtyduRnxay/g57zCBpw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;+y+as2YNBEvOddTPxl73DA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;/Bb6eVO+je9kbuIGTvt6Ww==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;/L1kFEoHZTukrNTCQLypFQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;/O7rOBo1qRMFm3q3Kf3mEw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;/THiuz93dsCZJETS3A4Xtw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;/XUXPfxfCal3j0ldx+af3A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;/h/TBQhfoSMCmey5oN87jA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;/l8wc0qlQdZdqgMIy+AX4w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;/oIjTiZph8FPjlWNL5s82w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;/oLe91LMLglvpqo76adFGw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;/ub7EE8Da46T0x7lRdlVJg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;0133y/ZC+9hrvuSzgka7cw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;04b0yaCHYk5DVzS89hVjvw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;09fH92fqoWDOaYEpwQ9p2g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;09r8DbZFJmI1tQW/a+ZlWQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;0NHnPl3pNsT2FH8oGcfyEw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;0fqyUk3Q4wjepXsEzVTbuQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;0gNpYdx7/dHkr8z85zHOSg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;0kf4C6OH9tp4+UaKjumyEg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;1+Lg0PO3SMtKcC7avbi64w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;13LJ8VSSR7Q+r1oKIOzegw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;49620a67-2a69-4965-87b7-cf8e91792454&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;1XXuvf69/0I2dNHaU2UndQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;1Xbb0MgMTadhlE/gdXAC9g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;7c0fcdb8-6748-4d51-8c0f-22d062631cfe&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;1atoBfoH0mJ0bCpetQ7/0g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;1c78imYwGnF54k326pUleA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;1h2bWnAaSbAMrDYM8V/8sw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;1m9sKqHTfU4F/K4fidg9cg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;1p1wTPVFlokLdC9/X3ksGg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;1pWwHIWE2UYOVNkFfcPZhQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;1pqtMQqVpCMzDCv8KXVyuA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;20ttMIcZDyeRDwHLGLpY5g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;2QUKRSh7NN4cTp6+OOEm8w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;2gCbp4kt+cF44NF/LqukDg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;2hVeGisxeIl5ZCVdBXxWKg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;2tnKv76FL7fQoypGU9dvWQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;2w8qE/d9mqIY/9+1qBBrPg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;35MvZs/A5NUjD+xZ1Vlnyw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;38FdUixzs3eDg/NPZRiJIA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;3YAw8el/3rSN8/26QNTqsA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;3adzKM06LvCWYFXCgwdnjA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;3kiQXJjCV5HlO0qf9OFzoQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;3nZGfOwzhExfw1oIgyJNUg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;4DALE9qlRQsocTmGTN3jhg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;094b57a8-611b-45bd-b338-0f1e3ba94b76&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;4Kw/w2gH7CYCOCv19cdYYA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;4U8NwfIL6oZ9HtlVrK/5EQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;4xm12R/wZXmG2Cs/ve2Zjw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;5+tHFkkNi+1rUDSrmgYdkw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;582nBqlxZXz0sTRmkFvU4Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;5GtYmv+rWUY9Nq0zLzVwuQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;5JAFUJWmy04+T6x2oJw2jg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;5hkeK2sS5i1OF8czY7eD+A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;5w6Z1FeiHTUU7Pzs/S0tow==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;ruby:app/vendor/bundle/ruby/3.3.0/specifications/rspec-mocks-3.13.7.gemspec&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:2b73e0ac411b60e005011e13106f30b5be55574d1ec9ce15ae5f20618930f9d1&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;ac41f493-ae0a-4233-8d1f-2e3b9706fb57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;5x6eb7pZ/EuGII0pLw9fTg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;60b1mOIk+ncF/benyKWfug==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;60pEkQUMtqjJkDtrBnZkZw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;65vQ2fJTp0DlFVHdZmyGLw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;6AYt+NWt55432RGa/HxiQg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;6G1ytjIPgX0NNsVwuPQKkQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;6HUC1/dPziZpbtWEymw0nQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;6MFxZDjn6ZxVQspQib4VSA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;6yTvnPP57NJPXUaaMuHa5Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;7/k2KO9ZYtIX1WvnibuCwg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;71E7ojyMFQ1Uwy0VMr2WLg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;7NGPdoQ8CufgoRI2a0XI0g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;7cpIREEQnkaI7dbmWgmrvg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;7mDaaxs3ev+uNEDYC97U3Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;7oPP0/pHHdyRIJK6pYsCbQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;7qAMBOvJ2FYxpK9n05pI7Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;7ra56f21gLrcSpBD8a9+NQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;7yB5oIQve4tWIMlUmHbdQQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;8+AT+dHyoFXmtWYeClg3hQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;8/+OIixLXu+fX/6UoQwl/g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;87VUAbsTn2cSvq70x9SIKw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;88jYB91M4ddvxo2XjMJKmQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;8Al1Y3mQILwPqoFjfjIK0Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;8OE8ax/E0UXByEoVMTfkbA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;8dKij0lKhp8eGM5ynaMPfg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;8gpmX0NZa9MMhcqi6FUGtg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;8k+Ulo3wv2SSKo3DSJNJ6A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;8n6bVUPPsV3vtnz+vLHqKQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;8uME+PFu6p/OAD7q+ZTVLw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;8uNlRHm24HlCfj4vRuzAgA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;9HjCH3SeUwgItfYZysNlOw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;9bMXqD09C2r4s8P+HNy2uw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;9olIUlLHZMdoUMju+8diyQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;A5zg77FwqyQ7YbgSi5bkFw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ACNA1cjsRpihwLsZYxMiYQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;AMvlCR3g+vHIXnbjgXeX2Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;AUjudWCWcMUZtLYqynIMkg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;AbW1lRpGUjSEKNnr/Toz6A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;At9otkYcx2c7gDG/+qxMog==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;BIzbOPagaosMprtM0oW/UQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;BLrNfmomqpFT8qecLZ99jQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;49620a67-2a69-4965-87b7-cf8e91792454&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;BQhiFmX4hLYteW4oRCLTSA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;BRLVvSCW1qZQlEQR2x48fQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;BUmLEOIviku9guiDM/J5qA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Be3u3fxCSx0yV9rW5tn7+A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;CM/XLOAV8nEwvYEgfvOluA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;CQ7LW8sdHcbka0B3IpMM1Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;CS6z0/SKwjMOr6VBFQ1+lw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;CfMo51dlSGLRWNluoKfMUQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Cn4UOizx3r/8sEEZ0cgGfw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;CpfomSYboaXPZ9yn9NgGgw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Cwut2mrMMUaIvKenvO1qWw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;CyeMFBrESWOU4r5NgnAVEQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;D3RCrUIdQ+uwLTm+GGcqSA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;D5m7YK6SRxMXWJzbEMw9qw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;DK0d2bPQCX0xz6Lec7u1cg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;DNyIkrd4IXePRueLDNc6ZA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;DVT5EsNYhhc4TADNn+PvwA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;DVWG3mWD7odZzCgFCUPZPw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;DXPX19bdN5nJbVwnxKFlOA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;DrLq8qfU1bfE8o8AfdvkrQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;DyVc00dL0fB/TbUtdImPIA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;EEcEMKhGMvXAfnMhboIpqw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;EhaFwS5l8+kj0ips0KX28g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;EjrCko4EN35q3gOrHdIWjw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Ep9qjtRg5KBEw8RkogSOKQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Esfj4A6yCPG0aR5IhgHmUg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Exv8+xTp+7Y4AfuM+ph47Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;F5S3/GN2uyb/+Q/5rj2gBA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;F6sWmqQXkobYs1E0otG8/A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;F90x58kELkC16MbTpMw3vg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;FDdpwYO23GZzR/6AZCdQZA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;FEF27h+V5TzrUeQsFddapA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;FEW4+DY0GhovHIdRCyqYhg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;FFSNe661VBElA1asGZ7k3g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;FKD/ouYSWOOZHy4i43SaxA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;FW8ByCOP6ljvNWDQolahwg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;FaNO6QWs1mWPp40PrBiBUQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;FiLBkAWUUsnpX53xBEBwNw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;FoNZoDzlktTR7m0xbn6aAw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;FoncQi9chif7gDbfNIi6VQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;G1YDEd7+V95Qa+PMxB8sJw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;G61ZL2SOHR2qgvQfi118gw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;GIScmMWQrnoFNoEgq3fg2w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;GSkR2SOuqWQN8NtOvU4cgw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;GdLrcchvFseDsR7KOv0vSQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Gfvf4LQKHStcGqbzaAe/lA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;GrPCC9ybwOy98qwLdeCX6A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;GrohJMl/MISMll2qndOSGg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;GtFO3rQtk4lExV/Q1qfFOg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;GwNK8p9XcJLynTdoZWdCxg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;H3zfV58LzeEUiNQbZbZb2A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;HF0BuzgGNjLOUKqVyjw0oA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;HKlRsQZtXaa3HoNDv500tg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;HQLCuUiHA+476ax5LmI78Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;HQdWvmyUSqtI3UTY0T4JiQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;HaOoNwb8lV6rMAwKRGxXbA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;HyWYXl8ZaOY6wtr4mKF7qA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;HyjfzS7o9NZj6mKbOA36wA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;I16VSEydeiRYB1TSf5694A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;I4xeNeKgfXcsAYIlRhjPiQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;IC3qYOgP07zDDhN8OMm04Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;IDaB7M+//88qbPppM+LpUw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;IG/inuDbgBm/XuY2u/Aumw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;IZ65O3ZOapykHwhaOX1/YA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;IqB8E1ANUG9NXQorLZJDiQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;IxIhH0Z+Om/E2wWJgs7oqA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;J4wVTpjsd90BinvJHS7Zqw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;J9Ac2zSOxpvD4YQ2MZMs6w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;JF/KXrYQKwPQyQXcXBUzkQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;JFKff4xqwvXPuYTu9WPwUQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;JKP7JzVg7UGaAz4VrH03lQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;7e98fa1e-1ff8-49b5-a6d1-c48a9213af4a&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;JaeGSHoaw5r486gmcDmRVA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;KEwhWR+KmcE0gZ+mC6lSDw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;KF5C+zKu/uFB7knCqOvDAQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;KH0/KbRUi7KL6UvWa8i6Pg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;KS0gfrpBqK77mtupKmitjw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;KcPAdOork3AFYl8WLwr8lQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;KcftiMkhTw4x89HNJI8NNg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;KnsryeYjIOfmvupUdl8bDg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;094b57a8-611b-45bd-b338-0f1e3ba94b76&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;KyRw1LumZrRo6AKKkHgP7w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;L1CJW90/qIOW7PuGFCWT3g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;L2RUW2Fm5EOgoqwyitY3bg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;LDIMlzOywHz1+CG5FwjKdQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;LEyuwSco7tb1WIyWy42H8g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;LPNXQi0V2EN73HoDD+RYaw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;LW/iN16rWtvIqrNuZRqrvA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Leh3RdsGa1oyRcl5Dz4SdA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;LjtOegR/S/Y0KwJeOuSl/w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Lwqn0aweLQLZmo12VvYcog==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;M2qdPAOOvb+CWXJwouP4Rw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;MDH8Zt4oQWDiYk9qFV5Lbg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;MORX6hW9ZLZCt/52w71zTg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;MdGkZ055CI+TZYqVm7FIPg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Mp61fGpK3II0W8dIQgk3hA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Mta8K+tWCjAV6ERlLy6JNw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;MvInuV8lMA+9LBSzIEvv5g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;N2AxbBO2ySQgGMgkdbfo+w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;N9SQ1VZ/1zaqG0gdsMW91g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;NCC3wkuc6lwSKJH9fwRaTQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;99dfe52b-c38e-4726-a51a-93ad820c4596&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;NDKmI4fvu2M/TtapvknDEg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;NSiprMdkK5/5pxuNNJOh2A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Nak/NGhCYVubG4CsEbHhug==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;NdCY2/S+syamLH224R4hug==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;7e98fa1e-1ff8-49b5-a6d1-c48a9213af4a&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;NsU0bgQSA1JrKw3zvB+XBw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;O6NCE8KkqNnnBGJrWxfPwA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;OCIjbR16ktOEiFK36r0WNw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;OgwdUybWl/HQYbnPTE4Psw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Ohssf0Jzlafd9vtrrUKCXg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;OkY4XBjh2jDTkYhGjNkrUA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Ol1YWxU11Z64v1nA/zb/5w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;OvOSK0YS4U6j2gyFBATNXg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;P5Om9zCJ/QZ+hnrEvj6fGw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;PCxuTBi9SbzcxEcQiiLesg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;PIk2BBAWexCFofMi5q03RA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;PQJujrJagYV+Ey8n4uQ95g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Q4EH8dHdml+oN5T9LssIRw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Q8V6CJq+uIfjVUujX4I61Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;QG9+UTOvnb8kW+im/fjlJQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;QbZd82FdnCLBtn8fUkWn0A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;QcXiQZ6UKeueoaxjtrYKog==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Qk1bxbjfumdXF7/eZ6qhuw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;QlHijPVbW9yTtx/mAeIhAg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;QpWwMw97N/44PyIvwMh0cA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;R9sC7SuM6vJmJZYq/bMHWw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;RH5gHxMLfgSMn5ktJt/VXA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;RIdJTslNAIfH4yKbDsoK9Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;RXh3fimX8fGZeCt4chJEiA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Riemnu+blxsuHCoBGaacLA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:2b73e0ac411b60e005011e13106f30b5be55574d1ec9ce15ae5f20618930f9d1&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;68a7ce1a-f8e4-4fc3-b254-6cbbc1f1e251&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;RlkbUDRj6k1VsLWBs4sx5g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;ruby:app/vendor/bundle/ruby/3.3.0/specifications/rspec-support-3.13.6.gemspec&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:2b73e0ac411b60e005011e13106f30b5be55574d1ec9ce15ae5f20618930f9d1&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;ac41f493-ae0a-4233-8d1f-2e3b9706fb57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Rmp+/J0Vf6Z1c/jUFbiVFw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;RmtwCYp+M3KMl7TiyHKwMA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;S8p9UGak1oycptcpYp/1eg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;SDcVZRLpwAQNjUwZ+PuxkA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;SZllfeGD2yJm0VL0H7onLg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ScSZYXWuosUrTT47e6vL3g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;SjQtW3gQmgt+Qj8JlnY4Mg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;SsUshR21MZuli8B+sjKoRg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Su8bfW9ijc0V5CiAum2V1g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;TPIRq84Pr3a6ywzPeCr3Pw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;TSs+KS9B9pkzz7FIgxu+aw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Tniy6w9fMQe2ISrhGqJ8ww==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;ruby:app/vendor/bundle/ruby/3.3.0/specifications/rspec-core-3.13.6.gemspec&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:2b73e0ac411b60e005011e13106f30b5be55574d1ec9ce15ae5f20618930f9d1&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;ac41f493-ae0a-4233-8d1f-2e3b9706fb57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;To0NR+oyXDu1CYJfmVGurQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ULrmZHuHE64atjgQOV1lWQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;UPcwub579LDL6kq2lq/xZw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;UTNN7VK61RHl/IW+g5aMJA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;UWXJUZfGCJSFYUff3zhl3g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;UcGy2+DIOqObBfK9GBmDEw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;UnaL8VteZLsad5rFJhaXcw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;VPMvwiwbrTXjPkPpxmP3sw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;VV2Z1ngTs6sGvt5SrayPCg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;VX9V+Y680L2xf2tBREdpCw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;VhjrPOGZ9XGEFgLnQWc+KQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Vk7Abr1qzxUEVjteKWWX5g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;W7uBqJb8l9AhSXjNg1JZQg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;WCQtqHWXoTXna7IAIUuLVg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;WKbv3dOPjWYMO8/3E5KlHQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;WQqPFo8Asn86tAeRqCxr1w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;WVajSGKLGm8z6I23XYAhLQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;WifWl02dLM2pp5urxOSuNg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;WrJXEOHH0Gy0bbmWqGmrDg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:2b73e0ac411b60e005011e13106f30b5be55574d1ec9ce15ae5f20618930f9d1&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;68a7ce1a-f8e4-4fc3-b254-6cbbc1f1e251&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;WzYxymAFFZiduGsTG/o8gA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XG5+bW8np2NedSy/od6z8Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XGaIL7YJmyr8vz8ETC4dAA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XIcr6HdP94Dud7DtFrfMZg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XMI2bnJZdxdcHnKc3zgCUA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XP0LiIWbLisoI52ZCyFcLg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XTnX2VddNvCYpYt/meLgYA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XgE+qDogkObCc5XPQHN25A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XliA1VgMzM5VjjSZdnmlQw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XpiKzmFjoUH4P3gzIyNStg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;ruby:app/vendor/bundle/ruby/3.3.0/specifications/rspec-3.13.2.gemspec&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:2b73e0ac411b60e005011e13106f30b5be55574d1ec9ce15ae5f20618930f9d1&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;ac41f493-ae0a-4233-8d1f-2e3b9706fb57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XvQXlm/D2h/0lO6HdF8+7g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;ruby:app/vendor/bundle/ruby/3.3.0/specifications/rspec-expectations-3.13.5.gemspec&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:2b73e0ac411b60e005011e13106f30b5be55574d1ec9ce15ae5f20618930f9d1&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;ac41f493-ae0a-4233-8d1f-2e3b9706fb57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;XwbkaIGCYyq6BjBMVZ1wzw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Y35yrxWjtTUkUbNtS9+p6g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Y5PnxdiaM8nGZKt9U6sMKw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;YMB2ro5tOcEm81D0RjHxXA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;YuMHdRatKmZ56mnoWUwdqw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;YwobqP8raRKIH+wXi7ZS4g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;Z+lO9FXEjKlmAeYPAHGorA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ZX4vKkXsoMfQ2HH9oPb0TA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ZhfyLrfrE9A0xmCI9BiGXA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;aJNccc76ay90akro/A82ww==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;afL/h/3XzYq6me3BTaFWlA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;al0lbET4LJsNSGMw0pP5wg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;arLt5War9yeQ8auYn/Idmw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;bEsPytE/ZdCMbfuAgQc9AA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;bFvWffGqJWr7FWnI7K9NVw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;bemGVBhbDe9iV1Kjvd9hAA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;cHAJILwEV0OAQcBBnKqncg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;cZtZpGQDMJ8/qYUdQbgb3Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ck/z6XzYDT2o8eVJI5IO+Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;624606e7-9195-428c-b44c-9a363be0d39e&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;cpIirH9DE6nFQZA6wIpxLg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;7e98fa1e-1ff8-49b5-a6d1-c48a9213af4a&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ct/ndQfSB+G17YP34ufDBA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;dBKXgz7fNBsMAqmGTkj8sQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;dC9CoYt17eaqinGSVCfCxw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;dH7n2Ct/z7JALFNo9SCMDg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;de44cUqF23LvU0fOSvNRjA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;dj7DwOHHHI+8+9QuzFaSUA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;dpQG/pUwAqVv1OdQqnvylQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;e+CtHsEaBCLbHEFWXwHRyg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;e40n/77uWc/t2R+0m7WchA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;e7W78NrdwYaVEcBcXhDv5Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;e9e6iwwufr2qvMYpuZgq7Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;eEjpOxWkwvzzJN5kkeVUcg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;eRa7MZyiHBvsv7GPhkGKdg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ejmVM2MTGmDkkntlZCpYEw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ev4LjEwclLnf3ehIi3l8oA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ewbqmzgK8Rzf739yT7IKUQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ez3E/Jxg/MQLUXOYIN/OlQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;49620a67-2a69-4965-87b7-cf8e91792454&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;f2GhXCi0MGW6C5vh1ih8XQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;f3K2r1U+QmHjsUiML4ziOQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;f86Wc3apFCnJqkXk60X7Cw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;fDuwmXmKOYEK5h1q2eODXQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;fVq3Liql8bu1Y+KmIvpQoA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;fao+yXdp7lvp4+d732rCkw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;gBWlSWdEA8U1+Ep4A/+M2g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;gJHwCqer7Rl9ijGK6wpg4A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;gihIEYR/lLwr4ndjyvVROA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;gjJq4XQiX28zDnKvnb0/jg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;gngAZQYf0zy4+w3GwgpLmw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;gsKPriszRNKAqMnHK+dXgw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;hKJ3xmpaes4B2vxd2C5M1Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;hWZOSd0A+iLGAwoMoW6sgw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;hYEisV19Dxn4PvCvxJFm5A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;hgsVhmCR+D+pPaE1yMWDsg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;hjikQWtnmVPaWts63wYw4Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;hktk4wXij5O6pY5X6Pdp/Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;iMLMqCcRXnm6QslpJnCS7w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;iQByZpdRXgW/fl3SoDuoAA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ipG1YUFrN7KyPdU8o+2M6Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;irdTBCwmsDefJyVDw+cS3A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;isMk2o0BvgtLnlqdbo7sxQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;99dfe52b-c38e-4726-a51a-93ad820c4596&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;iswhVSntR4QnIsTAyM6ydQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ix3lD4/Nn7qLbcpDm0AIhg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;izKk4aK07ZN99JT+tBsSBg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;j+mzBjs+9Rp1lGL7uVd5sA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;j3sZgUo/K49ejMiEqbRAtg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;624606e7-9195-428c-b44c-9a363be0d39e&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;j5f/exLQUf/AfnuQvtw1ag==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;jAjaNW7NMGiv7HfByDu4RQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;jDIVpAdvhjPN/gmOBNQuag==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;jDR7o2j2gfJePh/5YNDLjw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;jH43ZEoPP2TpNiUJXUizMw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;jMxy8GAhrrA2mTT5vqlfcg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;jXo3rXdhdYGkiXYZpQxZ3Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;jrYNd66NtmHdHhjnoxRx/A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;kDzRHkg3txncDWuyd5771g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;kFxhSjWy84mTZBM4XiZaeQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;kQDs6otjkbsijCAC8Ln06g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;99dfe52b-c38e-4726-a51a-93ad820c4596&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;kigiD4fuysu8/DeCr+ONKQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;kp6BaioAZ30jbVeZkkzokA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;kqjucdtmnvYZVSGwSyc0aA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;l36Y8lL0dC04c9AnKIpOCw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;lCuOAKu3TEbLIlxlfIdxkg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;ruby:app/vendor/bundle/ruby/3.3.0/specifications/diff-lcs-1.6.2.gemspec&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:2b73e0ac411b60e005011e13106f30b5be55574d1ec9ce15ae5f20618930f9d1&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;ac41f493-ae0a-4233-8d1f-2e3b9706fb57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;lNWcYbl6h71sUZV6B4E+bw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;lV2MRz2nTh21rS47LJ6XIQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;lbcitH3ttNejz+IVDee9kA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;lqKUNuoxzC8zSaSnPi26WQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;m7hOFCjo7x6PMvux7htFOg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;mK/FUfODp3MR7WS2xegPsw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;7e98fa1e-1ff8-49b5-a6d1-c48a9213af4a&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;mPqGnMbiXN6jP61aGbHvOA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;mWpxQAUiV6nN451/LkTR5w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;mkPyuhaF03PTIjEd+8p5XQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;624606e7-9195-428c-b44c-9a363be0d39e&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;mqINnrlOZQGPnpnT9GZG5w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;mx/6FfeunMu7M9pQ9cRKkQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;n9GoYS9J7jkIET4QDQWijA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;na4ojyfFHL07xf5Yr8wxsg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;niOKQxfAYGHJ3oUq3VHjdA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;nqniqNEVhrfub8cS+os87A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;nuIyutUqK6hTmg/S9ojklw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;nzQEyt4JfkGeZIIHPiBhog==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;oIqBLVUdTw3vIPAyQdS/tA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;oK41W21MyjS/j+5BoCQjuA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;obNuQXzAwE3TzjUoRN1yEw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;osuCNzTJ+Fjh0P4Yfe9E1g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;p9E62zY/VzvgMSvTX9UkJg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;q4zKXqPU+5vLvZLEG6zEXw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;q8h8ag3Ho33Zc/60lMOvVA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;qGKV3oqLguMWpyzvjv1+wg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;qKN/Sy8G7n1xl+F5J1m1bg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;qYSZ6aKFWol313IOGRXaug==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;qc0Yt1AzZC+CY6qdjO+fZA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;qco/AqMt9denZ9GeHFnEaA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;qklPItzKPipAd2a3RHZZIA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;qsJmM3aYeYGdvjHxtaNdaQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;r0GDCuRXOUGVJzCqB4JFMw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rB+tPXab1eESNe/6qy7U4Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rCLp3m64Catai9VuHvh3Lw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rEU0uZUpz06y9hg0ORc49A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rOo0eaSDbJ9TZ3lifnsvSQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;7c0fcdb8-6748-4d51-8c0f-22d062631cfe&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rUUieTQ6JPdOKUOFRfhvNw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rY/kE/V4JnxYoqV+lmc9mg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rZckolqfVnE7xInGZn5Zzw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rd4/gPEUtK2p++ni1m1dDg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rflqn7XKJvnH8dP67kgM7A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rj2k4My0f4W7sR9R0rDeJg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;rlHYqOr0lkUB/Gs6b1kD2g==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;s/zVhVCY3vRmmv6PJdGLCg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;s6wkZ09Eozv3vmfwsPHUvQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;sE1EmQ5Nhv4P4rilE6lODw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;sJhS0sL3jXf+ZUi4oTiojw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;sREtPFILPccNXLGF49Cnmw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ssPaV1VLDu6d5ZJ6Rrmh3A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;sukNATkcLkohYgGrhDtrZA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;sx0C6L5COHIkv6yQQyPlbw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;t28Zc7/vifVyS7O17xTUSA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;tGPn3pK3U8y547XMf1WmhQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;tWWw65aFr0Her+B1hlgbqA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;tYvC71hd5ARf4WITmeyfxA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;tqVXueFBgSdMZpggpUjjjA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;7c0fcdb8-6748-4d51-8c0f-22d062631cfe&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;txEovS086NkVY5rNikpoEA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;u3thu0wHuvY+STb8TrhkKQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;u5TyEoU5GA6Z2czzwhMLiA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;v3i4ez5juML2ZWwR+6dFFg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;v6X9Dt1wPw8fK6VaHz1Ffw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;v9Q18SPC524XLCjLQkFyLg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;vtNcuXyRth8r8K/W3sfqrQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;vw1F3IS9ZqFqIEU3E24hLQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;w2DoavvB02S/+BS01jQqJw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;w9ndxjIpPQXv3PDulnya7A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;wCA3gMNtInqX1xg18QcnQg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;wVOHUaFC3qlk+Ft1W2VH7A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;wYIIhtw19AhoRPO0XAvoxw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;094b57a8-611b-45bd-b338-0f1e3ba94b76&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;wdMozBSF06uhI4HOI003SQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;wfJGCqOH8d+IYg/dAepx1A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;wvtx3JsOUmPyorardjeYSQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ww1NPX/mwmdtd47p1Hp8FQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;x4oijVhQU8BUwJwoFvk4QA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;xGsFnJNA7f9q/+8cz1QFqg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;xItFXMbfthPTJh/VhaoYeA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;xMqWNWDJot/UVGgOoRsUVQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;xRkX4SbymzipYnnd/tIGVw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;root/buildinfo/labels.json&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:2b73e0ac411b60e005011e13106f30b5be55574d1ec9ce15ae5f20618930f9d1&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;68a7ce1a-f8e4-4fc3-b254-6cbbc1f1e251&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;xTea8RVD9wez5DTFDIkCYg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;xVpXFb43dZh4HfBX53yyew==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;xfiNHrth0bRlTgQnR3IgUw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;xgCGPQ7CZbjJqBTw2Nmu9w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:9f35f2b57577774b834118db7188bdec31b167b8fbd2f9b426e9a088125aba15&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;9233afa2-d32f-47ca-a768-d2fc0c05a540&#34;,&#xA;          &#34;c25f9d12-eee8-46f8-82d5-9b736db168d4&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;xnmn6fk+/THLJg3emXYMww==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;xuRjbnwW5VkRHg0Huc5RCg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;y9sflCLWTaHWSSC+w8u7bQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;yEp9fQVFIQAEDPCwC3GLmA==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;yHwqZ1KSVBKOdg3PvZkURg==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;yMfhY0UxLchgIpNP2r2lyQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;616b4892-2aee-4a60-a46a-6cac7161a964&#34;,&#xA;          &#34;9eaa4267-c64e-4348-a45b-c0b836f4d708&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;yY469KfvqdHWbJwmOcIU1Q==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;ycSS8xsUDu5nMwsql04xfQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;z+4p7UhT99HApht5JWOY7w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;zDt2Vfv35KL/GbH9JG8H3A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;zLbmCpiDy68qsFvtKNzmgQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;zYkGoXzaE5np8s88FoALNQ==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;zbfsUtSlKsegyV6mTxR13A==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:3f34e2ccedac73cfa38f9c3bb7cab93a0a339e8627c85e4e62a4239e63528b04&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;dfaef1f7-0917-41e7-90f7-f6a298a5464e&#34;,&#xA;          &#34;0401d292-a8ff-4814-9a7c-11d864fa5f84&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;zfyfWkP+jPZaONI2HeiXQw==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;zmiWZ9YjduqgYQPI8rU4ug==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;znACbAN0JGBPtCXNh1d0Ng==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:f01f404db6433dada5ec30e0f4d793ede39a963d0f9825c822fbbb074082b604&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;f02093ed-178d-479c-badc-f189b0146a57&#34;&#xA;        ]&#xA;      }&#xA;    ],&#xA;    &#34;zxuLMmxubC84XoLpkfxZ3w==&#34;: [&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;&#34;,&#xA;        &#34;repository_ids&#34;: null&#xA;      },&#xA;      {&#xA;        &#34;package_db&#34;: &#34;sqlite:var/lib/rpm&#34;,&#xA;        &#34;introduced_in&#34;: &#34;sha256:65a376416bc864d56cc3b260a129dec059886e98e9e40350ecb87435827d2288&#34;,&#xA;        &#34;distribution_id&#34;: &#34;0e229e17-d459-4174-a862-4ac814070695&#34;,&#xA;        &#34;repository_ids&#34;: [&#xA;          &#34;8acf35a1-1db8-4a07-970d-62eeb6cc2eb7&#34;&#xA;        ]&#xA;      }&#xA;    ]&#xA;  },&#xA;  &#34;vulnerabilities&#34;: {&#xA;    &#34;+20onLS/dWLg9saGZqMvvA==&#34;: {&#xA;      &#34;id&#34;: &#34;+20onLS/dWLg9saGZqMvvA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42766&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42766 https://bugzilla.redhat.com/show_bug.cgi?id=2481890 https://www.cve.org/CVERecord?id=CVE-2026-42766 https://nvd.nist.gov/vuln/detail/CVE-2026-42766 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42766.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+4boUUXSpak/++mwJDcv/A==&#34;: {&#xA;      &#34;id&#34;: &#34;+4boUUXSpak/++mwJDcv/A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14104&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1913&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.37.4-21.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+81WHs4+NlxNNP8OWMLJ2g==&#34;: {&#xA;      &#34;id&#34;: &#34;+81WHs4+NlxNNP8OWMLJ2g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33056&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in tar-rs, a Rust library for reading and writing tar archives. When unpacking a crafted tar archive, an attacker can exploit a symbolic link vulnerability. By including a symlink followed by a directory with the same name, the library incorrectly applies file permissions to the symlink&#39;s target. This allows an attacker to modify the permissions of arbitrary directories outside the intended extraction location.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T07:11:10Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33056 https://bugzilla.redhat.com/show_bug.cgi?id=2449490 https://www.cve.org/CVERecord?id=CVE-2026-33056 https://nvd.nist.gov/vuln/detail/CVE-2026-33056 https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446 https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33056.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+CgZKiM2jpLyW2jlIXneLw==&#34;: {&#xA;      &#34;id&#34;: &#34;+CgZKiM2jpLyW2jlIXneLw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-default-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+DR5Qfe30tw0byM4w3zykQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+DR5Qfe30tw0byM4w3zykQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-16118&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-16118 https://bugzilla.redhat.com/show_bug.cgi?id=2501732 https://www.cve.org/CVERecord?id=CVE-2026-16118 https://nvd.nist.gov/vuln/detail/CVE-2026-16118 https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16118.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+JlLlfOobk7OBriIdQRELQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+JlLlfOobk7OBriIdQRELQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+Jox86Lr4olzZZpeF2W5Cg==&#34;: {&#xA;      &#34;id&#34;: &#34;+Jox86Lr4olzZZpeF2W5Cg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-12818&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability has been identified in PostgreSQL’s libpq client library, where integer wraparound in several allocation-size calculations allows a peer or input provider to cause an undersized buffer and then write out-of-bounds by hundreds of megabytes. This can lead to a client application segmentation fault or crash when using libpq to connect to a PostgreSQL server.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-13T13:00:12Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-12818 https://bugzilla.redhat.com/show_bug.cgi?id=2414826 https://www.cve.org/CVERecord?id=CVE-2025-12818 https://nvd.nist.gov/vuln/detail/CVE-2025-12818 https://www.postgresql.org/support/security/CVE-2025-12818/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-12818.json https://access.redhat.com/errata/RHSA-2026:0458&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpq-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:13.23-1.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+Kc8jbRzLLDVqPaeFngWtQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+Kc8jbRzLLDVqPaeFngWtQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48618&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. This flaw involves a mismatch in how Node.js handles TLS (Transport Layer Security) hostnames and unicode dot separators during authentication. This mismatch can lead to a wildcard-depth authentication bypass. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access and confidentiality impact.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48618 https://bugzilla.redhat.com/show_bug.cgi?id=2493337 https://www.cve.org/CVERecord?id=CVE-2026-48618 https://nvd.nist.gov/vuln/detail/CVE-2026-48618 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+Ny4TpLzLiX1vAXKrYuRkg==&#34;: {&#xA;      &#34;id&#34;: &#34;+Ny4TpLzLiX1vAXKrYuRkg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5435&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T11:58:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-gconv-extra&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+PjI2yN4wCMPyf1oygeT5Q==&#34;: {&#xA;      &#34;id&#34;: &#34;+PjI2yN4wCMPyf1oygeT5Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-48237&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open source command line text editor. In affected versions, when shifting lines in operator pending mode and using a large value, it may be possible to overflow the size of the integer. The impact is low because user interaction is required and a crash may not happen in all situations.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-11-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-48237 https://bugzilla.redhat.com/show_bug.cgi?id=2250274 https://www.cve.org/CVERecord?id=CVE-2023-48237 https://nvd.nist.gov/vuln/detail/CVE-2023-48237 http://www.openwall.com/lists/oss-security/2023/11/16/1 https://github.com/vim/vim/commit/6bf131888a3d1de62bbfa8a7ea03c0ddccfd496e https://github.com/vim/vim/security/advisories/GHSA-f2m2-v387-gv87 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-48237.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+R/6bpHEFR4SpBeguCorTQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+R/6bpHEFR4SpBeguCorTQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-2673&#34;,&#xA;      &#34;description&#34;: &#34;A key group selection preference flaw has been discovered in OpenSSL. An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the \&#34;DEFAULT\&#34; keyword. A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client&#39;s initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-13T13:23:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-2673 https://bugzilla.redhat.com/show_bug.cgi?id=2447327 https://www.cve.org/CVERecord?id=CVE-2026-2673 https://nvd.nist.gov/vuln/detail/CVE-2026-2673 https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34 https://openssl-library.org/news/secadv/20260313.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2673.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-fips-provider&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+TrS27bZKgEeir9pISurnQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+TrS27bZKgEeir9pISurnQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5773&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5773 https://bugzilla.redhat.com/show_bug.cgi?id=2461201 https://www.cve.org/CVERecord?id=CVE-2026-5773 https://nvd.nist.gov/vuln/detail/CVE-2026-5773 https://curl.se/docs/CVE-2026-5773.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5773.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+U7CyAHaY71mhNm2Xnq2uw==&#34;: {&#xA;      &#34;id&#34;: &#34;+U7CyAHaY71mhNm2Xnq2uw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-68160&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This vulnerability involves an out-of-bounds write in the line-buffering BIO filter, which can lead to memory corruption. While exploitation is unlikely to be under direct attacker control, a successful attack could cause an application to crash, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-68160 https://bugzilla.redhat.com/show_bug.cgi?id=2430380 https://www.cve.org/CVERecord?id=CVE-2025-68160 https://nvd.nist.gov/vuln/detail/CVE-2025-68160 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68160.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+UOyQgpOAnrWS+mVMK5k1Q==&#34;: {&#xA;      &#34;id&#34;: &#34;+UOyQgpOAnrWS+mVMK5k1Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0861&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the glibc library. Passing an excessively large alignment value to the memalign suite of functions, such as memalign, posix_memalign, aligned_alloc, valloc and pvalloc, an integer overflow can occur during internal size calculations due to improper overflow checks, causing an allocation of a small chunk of memory which is subsequently used for writing. This issue can result in an application crash or heap memory corruption.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-14T21:01:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0861 https://bugzilla.redhat.com/show_bug.cgi?id=2429771 https://www.cve.org/CVERecord?id=CVE-2026-0861 https://nvd.nist.gov/vuln/detail/CVE-2026-0861 https://sourceware.org/bugzilla/show_bug.cgi?id=33796 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0861.json https://access.redhat.com/errata/RHSA-2026:2786&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-231.el9_7.10&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+X2XfuAS28uyjxaPoK8Ysw==&#34;: {&#xA;      &#34;id&#34;: &#34;+X2XfuAS28uyjxaPoK8Ysw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-58016&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-08T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-58016 https://bugzilla.redhat.com/show_bug.cgi?id=2492257 https://www.cve.org/CVERecord?id=CVE-2026-58016 https://nvd.nist.gov/vuln/detail/CVE-2026-58016 https://gitlab.gnome.org/GNOME/glib/-/issues/3932 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58016.json https://access.redhat.com/errata/RHSA-2026:42089&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-19.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+ba3qhqho8lfMXJQtKiMwQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+ba3qhqho8lfMXJQtKiMwQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1526&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A remote attacker can exploit this vulnerability by sending a specially crafted compressed frame, known as a \&#34;decompression bomb,\&#34; during permessage-deflate decompression. The undici WebSocket client does not properly limit the size of decompressed data, leading to unbounded memory consumption. This can cause the Node.js process to exhaust available memory, resulting in a denial of service (DoS) where the process crashes or becomes unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:08:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1526 https://bugzilla.redhat.com/show_bug.cgi?id=2447142 https://www.cve.org/CVERecord?id=CVE-2026-1526 https://nvd.nist.gov/vuln/detail/CVE-2026-1526 https://cna.openjsf.org/security-advisories.html https://datatracker.ietf.org/doc/html/rfc7692 https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q https://hackerone.com/reports/3481206 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1526.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+fYUom03o4taYF0LdBwDsg==&#34;: {&#xA;      &#34;id&#34;: &#34;+fYUom03o4taYF0LdBwDsg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66199&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker can exploit this vulnerability by sending a specially crafted CompressedCertificate message during the TLS 1.3 handshake. This can cause excessive per-connection memory allocations, leading to resource exhaustion and a Denial of Service (DoS) for affected clients and servers. This issue occurs when TLS 1.3 certificate compression is enabled and negotiated.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66199 https://bugzilla.redhat.com/show_bug.cgi?id=2430379 https://www.cve.org/CVERecord?id=CVE-2025-66199 https://nvd.nist.gov/vuln/detail/CVE-2025-66199 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66199.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+hBhqk1qKnkU+nqn6a96qg==&#34;: {&#xA;      &#34;id&#34;: &#34;+hBhqk1qKnkU+nqn6a96qg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-48233&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open source command line text editor. If the count after the :s command is larger than what fits into a signed long variable, abort with e_value_too_large. The impact is low because user interaction is required and a crash may not happen in all situations.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-11-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-48233 https://bugzilla.redhat.com/show_bug.cgi?id=2250270 https://www.cve.org/CVERecord?id=CVE-2023-48233 https://nvd.nist.gov/vuln/detail/CVE-2023-48233 http://www.openwall.com/lists/oss-security/2023/11/16/1 https://github.com/vim/vim/commit/ac63787734fda2e294e477af52b3bd601517fa78 https://github.com/vim/vim/security/advisories/GHSA-3xx4-hcq6-r2vj https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-48233.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+ihXD4KFgwxouHTRyQ5EbA==&#34;: {&#xA;      &#34;id&#34;: &#34;+ihXD4KFgwxouHTRyQ5EbA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45232&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in rsync. A network attacker can exploit an off-by-one out-of-bounds stack write vulnerability in the `establish_proxy_connection()` function by sending a malformed HTTP proxy response. This occurs when the `RSYNC_PROXY` environment variable is set and the attacker sends a response line of 1023 or more bytes without a newline terminator. This can corrupt stack memory, potentially leading to a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-20T00:45:28Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45232 https://bugzilla.redhat.com/show_bug.cgi?id=2480057 https://www.cve.org/CVERecord?id=CVE-2026-45232 https://nvd.nist.gov/vuln/detail/CVE-2026-45232 https://github.com/RsyncProject/rsync/releases/tag/v3.4.3 https://github.com/RsyncProject/rsync/security/advisories/GHSA-8f85-j2cv-59m8 https://www.vulncheck.com/advisories/rsync-off-by-one-stack-write-via-http-proxy https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45232.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+mMVfpx9oV/yykDKHrEHwQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+mMVfpx9oV/yykDKHrEHwQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-29111&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-23T21:03:56Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-29111 https://bugzilla.redhat.com/show_bug.cgi?id=2450505 https://www.cve.org/CVERecord?id=CVE-2026-29111 https://nvd.nist.gov/vuln/detail/CVE-2026-29111 https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6 https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8 https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29111.json https://access.redhat.com/errata/RHSA-2026:19213&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-67.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+p1B+LZP5hvhPeU88puOfg==&#34;: {&#xA;      &#34;id&#34;: &#34;+p1B+LZP5hvhPeU88puOfg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48930&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. This vulnerability in the TLS (Transport Layer Security) hostname handling allows embedded null characters in hostnames. This can lead to silent authority rebinding, potentially enabling an attacker to redirect network traffic to an unintended server and disclose sensitive information.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:37Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48930 https://bugzilla.redhat.com/show_bug.cgi?id=2493326 https://www.cve.org/CVERecord?id=CVE-2026-48930 https://nvd.nist.gov/vuln/detail/CVE-2026-48930 https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e https://hackerone.com/reports/3656716 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48930.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+uMSPU5jbqI0+jsP/eX6PA==&#34;: {&#xA;      &#34;id&#34;: &#34;+uMSPU5jbqI0+jsP/eX6PA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3037&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim, where it is vulnerable to a use-after-free in the qf_buf_add_line() function. This flaw allows a specially crafted file to crash a program, use unexpected values, or execute code.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-30T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3037 https://bugzilla.redhat.com/show_bug.cgi?id=2122907 https://www.cve.org/CVERecord?id=CVE-2022-3037 https://nvd.nist.gov/vuln/detail/CVE-2022-3037 https://huntr.dev/bounties/af4c2f2d-d754-4607-b565-9e92f3f717b5 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3037.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+usEQpepP7UaLaTDZ7AUHQ==&#34;: {&#xA;      &#34;id&#34;: &#34;+usEQpepP7UaLaTDZ7AUHQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rake&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:13.1.0-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+vYcckG24NBhOrHM/LGq8A==&#34;: {&#xA;      &#34;id&#34;: &#34;+vYcckG24NBhOrHM/LGq8A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4878&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4878 https://bugzilla.redhat.com/show_bug.cgi?id=2451615 https://www.cve.org/CVERecord?id=CVE-2026-4878 https://nvd.nist.gov/vuln/detail/CVE-2026-4878 https://bugzilla.redhat.com/show_bug.cgi?id=2447554 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4878.json https://access.redhat.com/errata/RHSA-2026:19346&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libcap&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.48-10.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;+yuesL9NY5Qpvu7wv7kHHA==&#34;: {&#xA;      &#34;id&#34;: &#34;+yuesL9NY5Qpvu7wv7kHHA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4046&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T17:16:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-locale-source&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;//8buewiV8gb20qv4g1cqQ==&#34;: {&#xA;      &#34;id&#34;: &#34;//8buewiV8gb20qv4g1cqQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-65018&#34;,&#xA;      &#34;description&#34;: &#34;A buffer overflow flaw has been discovered in libpng. There is a heap buffer overflow vulnerability in the libpng simplified API function png_image_finish_read when processing 16-bit interlaced PNGs with 8-bit output format. Attacker-crafted interlaced PNG files cause heap writes beyond allocated buffer bounds.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-24T23:50:18Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-65018 https://bugzilla.redhat.com/show_bug.cgi?id=2416907 https://www.cve.org/CVERecord?id=CVE-2025-65018 https://nvd.nist.gov/vuln/detail/CVE-2025-65018 https://github.com/pnggroup/libpng/commit/16b5e3823918840aae65c0a6da57c78a5a496a4d https://github.com/pnggroup/libpng/commit/218612ddd6b17944e21eda56caf8b4bf7779d1ea https://github.com/pnggroup/libpng/issues/755 https://github.com/pnggroup/libpng/pull/757 https://github.com/pnggroup/libpng/security/advisories/GHSA-7wv6-48j4-hj3g https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-65018.json https://access.redhat.com/errata/RHSA-2026:0238&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/9MMSCBwxCiKjJobh+tDpw==&#34;: {&#xA;      &#34;id&#34;: &#34;/9MMSCBwxCiKjJobh+tDpw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42766&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42766 https://bugzilla.redhat.com/show_bug.cgi?id=2481890 https://www.cve.org/CVERecord?id=CVE-2026-42766 https://nvd.nist.gov/vuln/detail/CVE-2026-42766 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42766.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/DjJHQ4LUqD/kDDEZQnGMQ==&#34;: {&#xA;      &#34;id&#34;: &#34;/DjJHQ4LUqD/kDDEZQnGMQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-18477&#34;,&#xA;      &#34;description&#34;: &#34;A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar&#39;s incremental dumpdir &#39;X&#39; rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-31T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-18477 https://bugzilla.redhat.com/show_bug.cgi?id=2509735 https://www.cve.org/CVERecord?id=CVE-2026-18477 https://nvd.nist.gov/vuln/detail/CVE-2026-18477 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18477.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/GP9UYzgnUNp/vOMMDf7mw==&#34;: {&#xA;      &#34;id&#34;: &#34;/GP9UYzgnUNp/vOMMDf7mw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-16517&#34;,&#xA;      &#34;description&#34;: &#34;A signed integer overflow vulnerability was found in libarchive&#39;s ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-03T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-16517 https://bugzilla.redhat.com/show_bug.cgi?id=2505492 https://www.cve.org/CVERecord?id=CVE-2026-16517 https://nvd.nist.gov/vuln/detail/CVE-2026-16517 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16517.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/M50+nAheHXCE2atpE2VJA==&#34;: {&#xA;      &#34;id&#34;: &#34;/M50+nAheHXCE2atpE2VJA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4438&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4438 https://bugzilla.redhat.com/show_bug.cgi?id=2449783 https://www.cve.org/CVERecord?id=CVE-2026-4438 https://nvd.nist.gov/vuln/detail/CVE-2026-4438 https://sourceware.org/bugzilla/show_bug.cgi?id=34015 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4438.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-common&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/MgFHW097IAGIZkNc/Fltw==&#34;: {&#xA;      &#34;id&#34;: &#34;/MgFHW097IAGIZkNc/Fltw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-5245&#34;,&#xA;      &#34;description&#34;: &#34;A denial-of-service vulnerability has been identified in GNU Binutils, affecting versions up to 2.44. The flaw resides within the debug_type_samep function in the /binutils/debug.c file of the objdump component. An attacker with local access can trigger a program crash by manipulating input data, leading to a denial of service for the objdump utility.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-27T14:31:12Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-5245 https://bugzilla.redhat.com/show_bug.cgi?id=2368771 https://www.cve.org/CVERecord?id=CVE-2025-5245 https://nvd.nist.gov/vuln/detail/CVE-2025-5245 https://sourceware.org/bugzilla/attachment.cgi?id=16004 https://sourceware.org/bugzilla/show_bug.cgi?id=32829 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a https://vuldb.com/?ctiid.310347 https://vuldb.com/?id.310347 https://vuldb.com/?submit.584635 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5245.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/Q70+j219nLwNP4Phg4sag==&#34;: {&#xA;      &#34;id&#34;: &#34;/Q70+j219nLwNP4Phg4sag==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6653&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libxml2. A remote attacker can exploit a use-after-free vulnerability in the `xmlParseInternalSubset` function by providing maliciously crafted XML input. This improper handling of entity resolution can lead to a denial-of-service (DoS), making the affected system or application unavailable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-22T12:40:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6653 https://bugzilla.redhat.com/show_bug.cgi?id=2491354 https://www.cve.org/CVERecord?id=CVE-2026-6653 https://nvd.nist.gov/vuln/detail/CVE-2026-6653 https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260 https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6653.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/YcdipQjiqJUDpddwhDiIw==&#34;: {&#xA;      &#34;id&#34;: &#34;/YcdipQjiqJUDpddwhDiIw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2345&#34;,&#xA;      &#34;description&#34;: &#34;A use-after-free vulnerability was found in Vim in the skipwhite function in the charset.c file. This issue occurs because an already freed memory is used when a specially crafted input is processed. This flaw allows an attacker who can trick a user into opening a specially crafted file into triggering the use-after-free, and cause the application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-07-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2345 https://bugzilla.redhat.com/show_bug.cgi?id=2106775 https://www.cve.org/CVERecord?id=CVE-2022-2345 https://nvd.nist.gov/vuln/detail/CVE-2022-2345 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2345.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/Zbh/oTVYOn4fLQqcvLFNw==&#34;: {&#xA;      &#34;id&#34;: &#34;/Zbh/oTVYOn4fLQqcvLFNw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-io-console&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.7.1-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/eHyvb2Yvu/vFkWHODEbfw==&#34;: {&#xA;      &#34;id&#34;: &#34;/eHyvb2Yvu/vFkWHODEbfw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0865&#34;,&#xA;      &#34;description&#34;: &#34;Missing newline filtering has been discovered in Python. User-controlled header names and values containing newlines can allow injecting HTTP headers.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:26:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0865 https://bugzilla.redhat.com/show_bug.cgi?id=2431367 https://www.cve.org/CVERecord?id=CVE-2026-0865 https://nvd.nist.gov/vuln/detail/CVE-2026-0865 https://github.com/python/cpython/issues/143916 https://github.com/python/cpython/pull/143917 https://mail.python.org/archives/list/security-announce@python.org/thread/BJ6QPHNSHJTS3A7CFV6IBMCAP2DWRVNT/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0865.json https://access.redhat.com/errata/RHSA-2026:4168&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/h81Nr0GSz2fO9zGO8rpYw==&#34;: {&#xA;      &#34;id&#34;: &#34;/h81Nr0GSz2fO9zGO8rpYw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69421&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by providing a specially crafted, malformed PKCS#12 file to an application that processes it. The flaw occurs due to a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function when handling the malformed file, leading to an application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69421 https://bugzilla.redhat.com/show_bug.cgi?id=2430387 https://www.cve.org/CVERecord?id=CVE-2025-69421 https://nvd.nist.gov/vuln/detail/CVE-2025-69421 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69421.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/jvSCV2RwJ6c/Llx9z8uvA==&#34;: {&#xA;      &#34;id&#34;: &#34;/jvSCV2RwJ6c/Llx9z8uvA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15469&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. When a user signs or verifies files larger than 16MB using the `openssl dgst` command with one-shot algorithms, the tool silently truncates the input to 16MB. This creates an integrity gap, allowing trailing data beyond the initial 16MB to be modified without detection because it remains unauthenticated. This vulnerability primarily impacts workflows that both sign and verify files using the affected `openssl dgst` command.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15469 https://bugzilla.redhat.com/show_bug.cgi?id=2430378 https://www.cve.org/CVERecord?id=CVE-2025-15469 https://nvd.nist.gov/vuln/detail/CVE-2025-15469 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15469.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/km0PGGx5jgJEo1YpWisAQ==&#34;: {&#xA;      &#34;id&#34;: &#34;/km0PGGx5jgJEo1YpWisAQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-29518&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in rsync. An rsync daemon configured with \&#34;use chroot = no\&#34; is exposed\nto a time-of-check / time-of-use race on parent path components. A local\nattacker with write access to a module can replace a parent directory\ncomponent with a symlink between the receiver&#39;s check and its open(),\nredirecting reads (basis-file disclosure) and writes (file overwrite)\noutside the module. Under elevated daemon privilege this allows privilege\nescalation. Default \&#34;use chroot = yes\&#34; is not exposed.\nReach: local attacker on the daemon host, write access to a module path,\ndaemon configured with use chroot = no.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-20T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-29518 https://bugzilla.redhat.com/show_bug.cgi?id=2469055 https://www.cve.org/CVERecord?id=CVE-2026-29518 https://nvd.nist.gov/vuln/detail/CVE-2026-29518 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29518.json https://access.redhat.com/errata/RHSA-2026:26410&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.2.5-7.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/pEYCNwBz8VXiXwXl+mS3w==&#34;: {&#xA;      &#34;id&#34;: &#34;/pEYCNwBz8VXiXwXl+mS3w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6238&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T16:43:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/rKG82d/RCig7yYmsr6Kpg==&#34;: {&#xA;      &#34;id&#34;: &#34;/rKG82d/RCig7yYmsr6Kpg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-44432&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in urllib3, an HTTP client library for Python. This vulnerability allows a remote attacker to cause excessive resource consumption, such as high CPU usage and massive memory allocation, on the client side. This occurs when urllib3 attempts to decompress an entire HTTP response, even if only a partial read was requested, or when draining the connection after a partial decompression. This can lead to a Denial of Service (DoS) condition.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-13T15:17:12Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-44432 https://bugzilla.redhat.com/show_bug.cgi?id=2477154 https://www.cve.org/CVERecord?id=CVE-2026-44432 https://nvd.nist.gov/vuln/detail/CVE-2026-44432 https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44432.json https://access.redhat.com/errata/RHSA-2026:28158&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-urllib3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.26.5-8.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/rrV/dLSeVDaHUnAvPeh7A==&#34;: {&#xA;      &#34;id&#34;: &#34;/rrV/dLSeVDaHUnAvPeh7A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-8927&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcurl. When reusing a libcurl handle for sequential transfers with environment-variable proxy configuration, the library does not properly clear the proxy authentication state. This oversight can lead to the unintended disclosure of `Proxy-Authorization` headers to an incorrect proxy, potentially exposing sensitive authentication information to an unauthorized entity. This is an information disclosure vulnerability.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-03T06:16:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-8927 https://bugzilla.redhat.com/show_bug.cgi?id=2496769 https://www.cve.org/CVERecord?id=CVE-2026-8927 https://nvd.nist.gov/vuln/detail/CVE-2026-8927 https://curl.se/docs/CVE-2026-8927.html https://curl.se/docs/CVE-2026-8927.json https://hackerone.com/reports/3744543 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8927.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/s8Q0HsneAZhk9Mgclm/OA==&#34;: {&#xA;      &#34;id&#34;: &#34;/s8Q0HsneAZhk9Mgclm/OA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45445&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. Applications that use the AES-OCB encryption method with a specific one-shot interface (EVP_Cipher()) will have their provided Initialization Vector (IV) silently discarded. This leads to the same internal cryptographic value being used repeatedly, which compromises the confidentiality of encrypted data. Additionally, this issue allows for the universal forgery of authentication tags, undermining the integrity of communications.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45445 https://bugzilla.redhat.com/show_bug.cgi?id=2481896 https://www.cve.org/CVERecord?id=CVE-2026-45445 https://nvd.nist.gov/vuln/detail/CVE-2026-45445 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45445.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;/wEypZTr5run3SLjfJxcSA==&#34;: {&#xA;      &#34;id&#34;: &#34;/wEypZTr5run3SLjfJxcSA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34982&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. A modeline is used to set specific editor options directly from a text file. However, the `complete`, `guitabtooltip`, `printheader` options and the `mapset` function lack proper security checks, allowing an attacker to bypass restrictions and cause arbitrary OS command execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-06T15:16:48Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34982 https://bugzilla.redhat.com/show_bug.cgi?id=2455400 https://www.cve.org/CVERecord?id=CVE-2026-34982 https://nvd.nist.gov/vuln/detail/CVE-2026-34982 http://www.openwall.com/lists/oss-security/2026/04/01/1 https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615 https://github.com/vim/vim/releases/tag/v9.2.0276 https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.json https://access.redhat.com/errata/RHSA-2026:19224&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim-minimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:8.2.2637-26.el9_8.4&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0+lfA724ypJdmbNfIKjiog==&#34;: {&#xA;      &#34;id&#34;: &#34;0+lfA724ypJdmbNfIKjiog==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4437&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4437 https://bugzilla.redhat.com/show_bug.cgi?id=2449777 https://www.cve.org/CVERecord?id=CVE-2026-4437 https://nvd.nist.gov/vuln/detail/CVE-2026-4437 https://sourceware.org/bugzilla/show_bug.cgi?id=34014 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4437.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-langpack-en&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;00cDk2w3qfvdzMbO27c/+w==&#34;: {&#xA;      &#34;id&#34;: &#34;00cDk2w3qfvdzMbO27c/+w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2982&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free vulnerability was found in vim&#39;s qf_fill_buffer() function of the src/quickfix.c file. The issue occurs because vim uses freed memory when recursively using &#39;quickfixtextfunc.&#39; This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap use-after-free that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-25T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2982 https://bugzilla.redhat.com/show_bug.cgi?id=2123714 https://www.cve.org/CVERecord?id=CVE-2022-2982 https://nvd.nist.gov/vuln/detail/CVE-2022-2982 https://huntr.dev/bounties/53f53d9a-ba8a-4985-b7ba-23efbe6833be/ https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2982.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;041SU8x5Wrw6mRfaRurHIg==&#34;: {&#xA;      &#34;id&#34;: &#34;041SU8x5Wrw6mRfaRurHIg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69419&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When processing a specially crafted PKCS#12 (Personal Information Exchange Syntax Standard) file, a remote attacker can exploit an out-of-bounds write vulnerability. This issue, occurring within the OPENSSL_uni2utf8() function, leads to memory corruption by writing data beyond its allocated buffer. Successful exploitation could result in a denial of service or potentially allow for arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69419 https://bugzilla.redhat.com/show_bug.cgi?id=2430386 https://www.cve.org/CVERecord?id=CVE-2025-69419 https://nvd.nist.gov/vuln/detail/CVE-2025-69419 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69419.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;05N5Len6XyuiKITeFewI+A==&#34;: {&#xA;      &#34;id&#34;: &#34;05N5Len6XyuiKITeFewI+A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-bundled-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;07xwapz2PAAGV6vMF10zQw==&#34;: {&#xA;      &#34;id&#34;: &#34;07xwapz2PAAGV6vMF10zQw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:37:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-minimal-langpack&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;08ogBuWXS+d72R0TAjgJaQ==&#34;: {&#xA;      &#34;id&#34;: &#34;08ogBuWXS+d72R0TAjgJaQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-52859&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open-source command-line text editor. This vulnerability allows a program displaying output in a Vim terminal window to trigger an out-of-bounds write by sending a specific byte sequence. This can lead to a crash of the Vim application, resulting in a Denial of Service (DoS) for the user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-11T18:33:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-52859 https://bugzilla.redhat.com/show_bug.cgi?id=2487989 https://www.cve.org/CVERecord?id=CVE-2026-52859 https://nvd.nist.gov/vuln/detail/CVE-2026-52859 https://github.com/vim/vim/commit/63680c6d3d52477817b49cd1a66e7aabe8a7aa19 https://github.com/vim/vim/releases/tag/v9.2.0565 https://github.com/vim/vim/security/advisories/GHSA-47gw-8gc3-mgcm https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52859.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0E1VjQWdmolR9lr9ElIZZQ==&#34;: {&#xA;      &#34;id&#34;: &#34;0E1VjQWdmolR9lr9ElIZZQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-28389&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-28389 https://bugzilla.redhat.com/show_bug.cgi?id=2451096 https://www.cve.org/CVERecord?id=CVE-2026-28389 https://nvd.nist.gov/vuln/detail/CVE-2026-28389 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28389.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0HbetX2gSM32682C6raRqA==&#34;: {&#xA;      &#34;id&#34;: &#34;0HbetX2gSM32682C6raRqA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55132&#34;,&#xA;      &#34;description&#34;: &#34;A file access flaw has been discovered in NodeJS. A file&#39;s access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55132 https://bugzilla.redhat.com/show_bug.cgi?id=2431338 https://www.cve.org/CVERecord?id=CVE-2025-55132 https://nvd.nist.gov/vuln/detail/CVE-2025-55132 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55132.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0RDuhfilAG8dJEO2Fvk46w==&#34;: {&#xA;      &#34;id&#34;: &#34;0RDuhfilAG8dJEO2Fvk46w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1526&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A remote attacker can exploit this vulnerability by sending a specially crafted compressed frame, known as a \&#34;decompression bomb,\&#34; during permessage-deflate decompression. The undici WebSocket client does not properly limit the size of decompressed data, leading to unbounded memory consumption. This can cause the Node.js process to exhaust available memory, resulting in a denial of service (DoS) where the process crashes or becomes unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:08:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1526 https://bugzilla.redhat.com/show_bug.cgi?id=2447142 https://www.cve.org/CVERecord?id=CVE-2026-1526 https://nvd.nist.gov/vuln/detail/CVE-2026-1526 https://cna.openjsf.org/security-advisories.html https://datatracker.ietf.org/doc/html/rfc7692 https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q https://hackerone.com/reports/3481206 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1526.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0YVxD0vSH+0MhijemP/Jmg==&#34;: {&#xA;      &#34;id&#34;: &#34;0YVxD0vSH+0MhijemP/Jmg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3705&#34;,&#xA;      &#34;description&#34;: &#34;A use-after-free flaw was found in the qf_update_buffer function in vim. This issue allows a specially crafted file to crash a program, use unexpected values, or execute code.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-10-26T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3705 https://bugzilla.redhat.com/show_bug.cgi?id=2139086 https://www.cve.org/CVERecord?id=CVE-2022-3705 https://nvd.nist.gov/vuln/detail/CVE-2022-3705 https://vuldb.com/?id.212324 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3705.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0bK7Vo3x9SXQYvDvMmgzXA==&#34;: {&#xA;      &#34;id&#34;: &#34;0bK7Vo3x9SXQYvDvMmgzXA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2208&#34;,&#xA;      &#34;description&#34;: &#34;NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2208 https://bugzilla.redhat.com/show_bug.cgi?id=2102183 https://www.cve.org/CVERecord?id=CVE-2022-2208 https://nvd.nist.gov/vuln/detail/CVE-2022-2208 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2208.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0hc+Z9xWtVy4dEgLyf7GUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;0hc+Z9xWtVy4dEgLyf7GUQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59873&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:22:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59873 https://bugzilla.redhat.com/show_bug.cgi?id=2498120 https://www.cve.org/CVERecord?id=CVE-2026-59873 https://nvd.nist.gov/vuln/detail/CVE-2026-59873 https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3 https://github.com/isaacs/node-tar/releases/tag/v7.5.19 https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59873.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0lUHXQNoRQLden1OTY/5/w==&#34;: {&#xA;      &#34;id&#34;: &#34;0lUHXQNoRQLden1OTY/5/w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-55654&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-22T23:18:14Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-55654 https://bugzilla.redhat.com/show_bug.cgi?id=2462493 https://www.cve.org/CVERecord?id=CVE-2026-55654 https://nvd.nist.gov/vuln/detail/CVE-2026-55654 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55654.json https://access.redhat.com/errata/RHSA-2026:47756&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-9.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0n2Q+dTJnzCs850WQs7VXA==&#34;: {&#xA;      &#34;id&#34;: &#34;0n2Q+dTJnzCs850WQs7VXA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33636&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng. A remote attacker could exploit an out-of-bounds read and write vulnerability in the ARM/AArch64 Neon-optimized palette expansion path. This occurs when processing a final partial chunk of 8-bit paletted rows without verifying sufficient input pixels, leading to dereferencing pointers before the start of the row buffer and writing expanded pixel data to underflowed positions. This flaw can result in information disclosure and denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-26T16:51:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33636 https://bugzilla.redhat.com/show_bug.cgi?id=2451819 https://www.cve.org/CVERecord?id=CVE-2026-33636 https://nvd.nist.gov/vuln/detail/CVE-2026-33636 https://github.com/pnggroup/libpng/commit/7734cda20cf1236aef60f3bbd2267c97bbb40869 https://github.com/pnggroup/libpng/commit/aba9f18eba870d14fb52c5ba5d73451349e339c3 https://github.com/pnggroup/libpng/security/advisories/GHSA-wjr5-c57x-95m2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33636.json https://access.redhat.com/errata/RHSA-2026:28255&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-15.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0nKksdratD87mbqRPBOINQ==&#34;: {&#xA;      &#34;id&#34;: &#34;0nKksdratD87mbqRPBOINQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21637&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21637 https://bugzilla.redhat.com/show_bug.cgi?id=2431340 https://www.cve.org/CVERecord?id=CVE-2026-21637 https://nvd.nist.gov/vuln/detail/CVE-2026-21637 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21637.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0q4mJ3RDNOZ/qRqKXOz7Tg==&#34;: {&#xA;      &#34;id&#34;: &#34;0q4mJ3RDNOZ/qRqKXOz7Tg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48864&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-26T16:07:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48864 https://bugzilla.redhat.com/show_bug.cgi?id=2460425 https://www.cve.org/CVERecord?id=CVE-2026-48864 https://nvd.nist.gov/vuln/detail/CVE-2026-48864 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48864.json https://access.redhat.com/errata/RHSA-2026:39315&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libsolv&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.7.24-6.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0rfFR2EPlCkjUqAxx57NoA==&#34;: {&#xA;      &#34;id&#34;: &#34;0rfFR2EPlCkjUqAxx57NoA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6477&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in PostgreSQL libpq. A server superuser can exploit a buffer overflow vulnerability in the PQfn function, which is used by client functions such as lo_export(), lo_read(), lo_lseek64(), and lo_tell64(). This allows the superuser to send an arbitrarily large response, overwriting the client&#39;s stack memory, specifically in tools like psql and pg_dump. This could lead to arbitrary code execution on the client system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-14T13:00:12Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6477 https://bugzilla.redhat.com/show_bug.cgi?id=2477442 https://www.cve.org/CVERecord?id=CVE-2026-6477 https://nvd.nist.gov/vuln/detail/CVE-2026-6477 https://www.postgresql.org/support/security/CVE-2026-6477/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6477.json https://access.redhat.com/errata/RHSA-2026:44308&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpq-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:13.23-3.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0u4nnKNMeZ58/8R+sWLPSQ==&#34;: {&#xA;      &#34;id&#34;: &#34;0u4nnKNMeZ58/8R+sWLPSQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48928 https://bugzilla.redhat.com/show_bug.cgi?id=2493333 https://www.cve.org/CVERecord?id=CVE-2026-48928 https://nvd.nist.gov/vuln/detail/CVE-2026-48928 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48928.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;0v5F4x1W0RxkklLvRs6NKQ==&#34;: {&#xA;      &#34;id&#34;: &#34;0v5F4x1W0RxkklLvRs6NKQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-0433&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-01-21T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-0433 https://bugzilla.redhat.com/show_bug.cgi?id=2163612 https://www.cve.org/CVERecord?id=CVE-2023-0433 https://nvd.nist.gov/vuln/detail/CVE-2023-0433 https://huntr.dev/bounties/ae933869-a1ec-402a-bbea-d51764c6618e/ https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0433.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;14Ky/IzCleKAYRnLtZIRFw==&#34;: {&#xA;      &#34;id&#34;: &#34;14Ky/IzCleKAYRnLtZIRFw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4046&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T17:16:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-gconv-extra&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;19Kvl4LS7MCiBo2cRD5fxQ==&#34;: {&#xA;      &#34;id&#34;: &#34;19Kvl4LS7MCiBo2cRD5fxQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-3974&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. A possible use-after-free vulnerability could allow an attacker to input a specially crafted file leading to a crash or code execution. The highest threat from this vulnerability is to system availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-11-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-3974 https://bugzilla.redhat.com/show_bug.cgi?id=2025061 https://www.cve.org/CVERecord?id=CVE-2021-3974 https://nvd.nist.gov/vuln/detail/CVE-2021-3974 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-3974.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1CCABRgs/s9xxQcDgxw00A==&#34;: {&#xA;      &#34;id&#34;: &#34;1CCABRgs/s9xxQcDgxw00A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69645&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils, specifically in the `objdump` utility. A local attacker can exploit this vulnerability by providing a specially crafted binary file containing malformed DWARF (Debugging With Attributed Record Formats) debug information. This can lead to a logic error during the processing of DWARF compilation units, causing the `objdump` utility to crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69645 https://bugzilla.redhat.com/show_bug.cgi?id=2445261 https://www.cve.org/CVERecord?id=CVE-2025-69645 https://nvd.nist.gov/vuln/detail/CVE-2025-69645 https://sourceware.org/bugzilla/show_bug.cgi?id=33637 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69645.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1I5Zdk3zr6CO9kf+WEea4Q==&#34;: {&#xA;      &#34;id&#34;: &#34;1I5Zdk3zr6CO9kf+WEea4Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5450&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:55:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-common&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-272.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1NSoxvCfCFl4ic84FsWulA==&#34;: {&#xA;      &#34;id&#34;: &#34;1NSoxvCfCFl4ic84FsWulA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6100&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python&#39;s decompression modules, including `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile`. This vulnerability, a use-after-free, can occur if a program attempts to re-use a decompression object after a memory allocation error, especially when the system is experiencing high memory usage. Exploitation of this flaw could potentially allow an attacker to execute arbitrary code or access sensitive data. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-13T17:15:47Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6100 https://bugzilla.redhat.com/show_bug.cgi?id=2457932 https://www.cve.org/CVERecord?id=CVE-2026-6100 https://nvd.nist.gov/vuln/detail/CVE-2026-6100 https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2 https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20 https://github.com/python/cpython/issues/148395 https://github.com/python/cpython/pull/148396 https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json https://access.redhat.com/errata/RHSA-2026:19216&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1PA9NgR35/MRqgXqIHuktA==&#34;: {&#xA;      &#34;id&#34;: &#34;1PA9NgR35/MRqgXqIHuktA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33416&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng, a library used for processing PNG (Portable Network Graphics) image files. This vulnerability arises from improper memory management where a heap-allocated buffer is aliased between internal data structures. When specific functions are called, a freed memory region can still be referenced, leading to a use-after-free condition. An attacker could potentially exploit this to achieve arbitrary code execution or cause a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-26T16:48:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33416 https://bugzilla.redhat.com/show_bug.cgi?id=2451805 https://www.cve.org/CVERecord?id=CVE-2026-33416 https://nvd.nist.gov/vuln/detail/CVE-2026-33416 https://github.com/pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb https://github.com/pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667 https://github.com/pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25 https://github.com/pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1 https://github.com/pnggroup/libpng/pull/824 https://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33416.json https://access.redhat.com/errata/RHSA-2026:18028&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.4&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1WQ/LJu/kefEuHRv58l0Lw==&#34;: {&#xA;      &#34;id&#34;: &#34;1WQ/LJu/kefEuHRv58l0Lw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-4734&#34;,&#xA;      &#34;description&#34;: &#34;Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-09-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-4734 https://bugzilla.redhat.com/show_bug.cgi?id=2237161 https://www.cve.org/CVERecord?id=CVE-2023-4734 https://nvd.nist.gov/vuln/detail/CVE-2023-4734 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4734.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1WaijHYxan9df8+fB0SQJQ==&#34;: {&#xA;      &#34;id&#34;: &#34;1WaijHYxan9df8+fB0SQJQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-43620&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in rsync. A malicious rsync server can exploit an out-of-bounds read vulnerability in the `recv_files()` function. By manipulating compatibility flags and transfer records, the server can cause a connecting client to attempt to read memory outside of allocated bounds. This can lead to a segmentation fault, resulting in a denial of service for the client.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-20T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-43620 https://bugzilla.redhat.com/show_bug.cgi?id=2469057 https://www.cve.org/CVERecord?id=CVE-2026-43620 https://nvd.nist.gov/vuln/detail/CVE-2026-43620 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43620.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1cSKTg9cjDeVqfRjC+3dyA==&#34;: {&#xA;      &#34;id&#34;: &#34;1cSKTg9cjDeVqfRjC+3dyA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-59466&#34;,&#xA;      &#34;description&#34;: &#34;A stack overflow flaw has been discovered in Node.js error handling where \&#34;Maximum call stack size exceeded\&#34; errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on(&#39;uncaughtException&#39;)`, the process terminates, making the crash unrecoverable. Applications that rely on `AsyncLocalStorage` (v22, v20) or `async_hooks.createHook()` (v24, v22, v20) become vulnerable to denial-of-service crashes triggered by deep recursion under specific conditions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-59466 https://bugzilla.redhat.com/show_bug.cgi?id=2431343 https://www.cve.org/CVERecord?id=CVE-2025-59466 https://nvd.nist.gov/vuln/detail/CVE-2025-59466 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59466.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.4-1.22.22.0.1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1cpz1Hzz2hsR9fx5YrxP3g==&#34;: {&#xA;      &#34;id&#34;: &#34;1cpz1Hzz2hsR9fx5YrxP3g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-6176&#34;,&#xA;      &#34;description&#34;: &#34;Scrapy are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-31T00:00:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-6176 https://bugzilla.redhat.com/show_bug.cgi?id=2408762 https://www.cve.org/CVERecord?id=CVE-2025-6176 https://nvd.nist.gov/vuln/detail/CVE-2025-6176 https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6176.json https://access.redhat.com/errata/RHSA-2026:2042&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;brotli-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.0.9-9.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1geoBO6lBMXVRM+dfApwgw==&#34;: {&#xA;      &#34;id&#34;: &#34;1geoBO6lBMXVRM+dfApwgw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-32776&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted XML content with empty external parameter entities. This could lead to a NULL pointer dereference, causing the application to crash and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-16T06:54:20Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-32776 https://bugzilla.redhat.com/show_bug.cgi?id=2447888 https://www.cve.org/CVERecord?id=CVE-2026-32776 https://nvd.nist.gov/vuln/detail/CVE-2026-32776 https://github.com/libexpat/libexpat/pull/1158 https://github.com/libexpat/libexpat/pull/1159 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32776.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1npmxgSnoYj2MyAhQMaE7g==&#34;: {&#xA;      &#34;id&#34;: &#34;1npmxgSnoYj2MyAhQMaE7g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27171&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in zlib. An attacker providing specially crafted input to the `crc32_combine64` or `crc32_combine_gen64` functions could trigger an infinite loop within the `x2nmodp` function. This leads to excessive CPU consumption, which can result in a Denial of Service (DoS) for the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-18T02:36:19Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27171 https://bugzilla.redhat.com/show_bug.cgi?id=2440530 https://www.cve.org/CVERecord?id=CVE-2026-27171 https://nvd.nist.gov/vuln/detail/CVE-2026-27171 https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/ https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf https://github.com/madler/zlib/issues/904 https://github.com/madler/zlib/releases/tag/v1.3.2 https://ostif.org/zlib-audit-complete/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27171.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;zlib&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1r+syFhyATToDtkOkMLqDw==&#34;: {&#xA;      &#34;id&#34;: &#34;1r+syFhyATToDtkOkMLqDw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48930&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. This vulnerability in the TLS (Transport Layer Security) hostname handling allows embedded null characters in hostnames. This can lead to silent authority rebinding, potentially enabling an attacker to redirect network traffic to an unintended server and disclose sensitive information.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:37Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48930 https://bugzilla.redhat.com/show_bug.cgi?id=2493326 https://www.cve.org/CVERecord?id=CVE-2026-48930 https://nvd.nist.gov/vuln/detail/CVE-2026-48930 https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e https://hackerone.com/reports/3656716 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48930.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;1w+glHHFE32ql3XJuIAYWQ==&#34;: {&#xA;      &#34;id&#34;: &#34;1w+glHHFE32ql3XJuIAYWQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66862&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted PE file with cxxfilt can trigger a heap-based buffer over-read in the gnu_special function in the cplus-dem.c file, causing a crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66862 https://bugzilla.redhat.com/show_bug.cgi?id=2425825 https://www.cve.org/CVERecord?id=CVE-2025-66862 https://nvd.nist.gov/vuln/detail/CVE-2025-66862 https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66862.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;269Lb6JhyjdTwif2gzpsMQ==&#34;: {&#xA;      &#34;id&#34;: &#34;269Lb6JhyjdTwif2gzpsMQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69418&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When applications directly call the low-level CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions with non-block-aligned lengths in a single call on hardware-accelerated builds, the trailing 1-15 bytes of a message may be exposed in cleartext. These exposed bytes are not covered by the authentication tag, allowing an attacker to read or tamper with them without detection.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69418 https://bugzilla.redhat.com/show_bug.cgi?id=2430381 https://www.cve.org/CVERecord?id=CVE-2025-69418 https://nvd.nist.gov/vuln/detail/CVE-2025-69418 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69418.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2Apbu80O6R41VOd2ICqODw==&#34;: {&#xA;      &#34;id&#34;: &#34;2Apbu80O6R41VOd2ICqODw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9076&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9076 https://bugzilla.redhat.com/show_bug.cgi?id=2481880 https://www.cve.org/CVERecord?id=CVE-2026-9076 https://nvd.nist.gov/vuln/detail/CVE-2026-9076 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9076.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2BvFtePbGxsdaSFZvYiVWQ==&#34;: {&#xA;      &#34;id&#34;: &#34;2BvFtePbGxsdaSFZvYiVWQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6238&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T16:43:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-langpack-en&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2Cyt+PunG/cjJJ5UZqrqrg==&#34;: {&#xA;      &#34;id&#34;: &#34;2Cyt+PunG/cjJJ5UZqrqrg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1299&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the email module in the Python standard library. When serializing an email message, the BytesGenerator class fails to properly quote newline characters for email headers. This issue is exploitable when the LiteralHeader class is used as it does not respect email folding rules, allowing an attacker to inject email headers and potentially modify message recipients or the email body, and spoof sender information.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-23T16:27:13Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1299 https://bugzilla.redhat.com/show_bug.cgi?id=2432437 https://www.cve.org/CVERecord?id=CVE-2026-1299 https://nvd.nist.gov/vuln/detail/CVE-2026-1299 https://cve.org/CVERecord?id=CVE-2024-6923 https://github.com/python/cpython/commit/052e55e7d44718fe46cbba0ca995cb8fcc359413 https://github.com/python/cpython/issues/144125 https://github.com/python/cpython/pull/144126 https://mail.python.org/archives/list/security-announce@python.org/thread/6ZZULGALJTITEAGEXLDJE2C6FORDXPBT/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1299.json https://access.redhat.com/errata/RHSA-2026:4168&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2EHc3aND0ui/TYRnIdJ/WA==&#34;: {&#xA;      &#34;id&#34;: &#34;2EHc3aND0ui/TYRnIdJ/WA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-psych&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:5.1.2-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2F6XtsAYpNWm5w+Rwl/tuQ==&#34;: {&#xA;      &#34;id&#34;: &#34;2F6XtsAYpNWm5w+Rwl/tuQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-57062&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in GnuPG&#39;s gpgsm component improperly handles the Cryptographic Message Syntax (CMS) format for AES-GCM. By accepting an authentication tag length of 4 bytes instead of the required 12 bytes, this vulnerability allows for a low-impact data integrity issue where the cryptographic validity of messages could be compromised.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-23T17:26:25Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-57062 https://bugzilla.redhat.com/show_bug.cgi?id=2491859 https://www.cve.org/CVERecord?id=CVE-2026-57062 https://nvd.nist.gov/vuln/detail/CVE-2026-57062 https://blog.calif.io/p/how-to-format-a-ciphertext https://www.gnupg.org/download/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57062.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnupg2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2I/0B+uXhxpPJWXGwNGlLw==&#34;: {&#xA;      &#34;id&#34;: &#34;2I/0B+uXhxpPJWXGwNGlLw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-5344&#34;,&#xA;      &#34;description&#34;: &#34;A heap-based buffer overflow vulnerability was found in Vim&#39;s trunc_string() function of the src/message.c file. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap-based buffer overflow that causes an application to crash, leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-10-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-5344 https://bugzilla.redhat.com/show_bug.cgi?id=2242141 https://www.cve.org/CVERecord?id=CVE-2023-5344 https://nvd.nist.gov/vuln/detail/CVE-2023-5344 https://huntr.dev/bounties/530cb762-899e-48d7-b50e-dad09eb775bf/ https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-5344.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2Jpm8Zc5oiON+VhscwC/4w==&#34;: {&#xA;      &#34;id&#34;: &#34;2Jpm8Zc5oiON+VhscwC/4w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15469&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. When a user signs or verifies files larger than 16MB using the `openssl dgst` command with one-shot algorithms, the tool silently truncates the input to 16MB. This creates an integrity gap, allowing trailing data beyond the initial 16MB to be modified without detection because it remains unauthenticated. This vulnerability primarily impacts workflows that both sign and verify files using the affected `openssl dgst` command.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15469 https://bugzilla.redhat.com/show_bug.cgi?id=2430378 https://www.cve.org/CVERecord?id=CVE-2025-15469 https://nvd.nist.gov/vuln/detail/CVE-2025-15469 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15469.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2No3jCnnmCwOEpCbk+TZGA==&#34;: {&#xA;      &#34;id&#34;: &#34;2No3jCnnmCwOEpCbk+TZGA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-25646&#34;,&#xA;      &#34;description&#34;: &#34;A heap based buffer overflow flaw has been discovered in LibPNG. Prior to version 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user&#39;s display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-10T17:04:38Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-25646 https://bugzilla.redhat.com/show_bug.cgi?id=2438542 https://www.cve.org/CVERecord?id=CVE-2026-25646 https://nvd.nist.gov/vuln/detail/CVE-2026-25646 http://www.openwall.com/lists/oss-security/2026/02/09/7 https://github.com/pnggroup/libpng/commit/01d03b8453eb30ade759cd45c707e5a1c7277d88 https://github.com/pnggroup/libpng/security/advisories/GHSA-g8hp-mq4h-rqm3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25646.json https://access.redhat.com/errata/RHSA-2026:3405&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2RZ3u6UmceVG9iB/xb73SA==&#34;: {&#xA;      &#34;id&#34;: &#34;2RZ3u6UmceVG9iB/xb73SA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2206&#34;,&#xA;      &#34;description&#34;: &#34;Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-26T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2206 https://bugzilla.redhat.com/show_bug.cgi?id=2102188 https://www.cve.org/CVERecord?id=CVE-2022-2206 https://nvd.nist.gov/vuln/detail/CVE-2022-2206 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2206.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2TDjlt2gAEWsLyBBPigFYw==&#34;: {&#xA;      &#34;id&#34;: &#34;2TDjlt2gAEWsLyBBPigFYw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-13176&#34;,&#xA;      &#34;description&#34;: &#34;A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-01-20T13:29:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-13176 https://bugzilla.redhat.com/show_bug.cgi?id=2338999 https://www.cve.org/CVERecord?id=CVE-2024-13176 https://nvd.nist.gov/vuln/detail/CVE-2024-13176 https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-13176.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2UHqEqfMIIn53NkDlDEppQ==&#34;: {&#xA;      &#34;id&#34;: &#34;2UHqEqfMIIn53NkDlDEppQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2923&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim, where it is vulnerable to a NULL pointer dereference in the sug_filltree function. This flaw allows a specially crafted file to crash the software.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-22T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2923 https://bugzilla.redhat.com/show_bug.cgi?id=2120989 https://www.cve.org/CVERecord?id=CVE-2022-2923 https://nvd.nist.gov/vuln/detail/CVE-2022-2923 https://huntr.dev/bounties/fd3a3ab8-ab0f-452f-afea-8c613e283fd2 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2923.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2Yo5V5wVVXhJ0VU+H57P9g==&#34;: {&#xA;      &#34;id&#34;: &#34;2Yo5V5wVVXhJ0VU+H57P9g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1299&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the email module in the Python standard library. When serializing an email message, the BytesGenerator class fails to properly quote newline characters for email headers. This issue is exploitable when the LiteralHeader class is used as it does not respect email folding rules, allowing an attacker to inject email headers and potentially modify message recipients or the email body, and spoof sender information.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-23T16:27:13Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1299 https://bugzilla.redhat.com/show_bug.cgi?id=2432437 https://www.cve.org/CVERecord?id=CVE-2026-1299 https://nvd.nist.gov/vuln/detail/CVE-2026-1299 https://cve.org/CVERecord?id=CVE-2024-6923 https://github.com/python/cpython/commit/052e55e7d44718fe46cbba0ca995cb8fcc359413 https://github.com/python/cpython/issues/144125 https://github.com/python/cpython/pull/144126 https://mail.python.org/archives/list/security-announce@python.org/thread/6ZZULGALJTITEAGEXLDJE2C6FORDXPBT/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1299.json https://access.redhat.com/errata/RHSA-2026:4168&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2d2KejA0Nrz6tVNnB1dB5A==&#34;: {&#xA;      &#34;id&#34;: &#34;2d2KejA0Nrz6tVNnB1dB5A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-59466&#34;,&#xA;      &#34;description&#34;: &#34;A stack overflow flaw has been discovered in Node.js error handling where \&#34;Maximum call stack size exceeded\&#34; errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on(&#39;uncaughtException&#39;)`, the process terminates, making the crash unrecoverable. Applications that rely on `AsyncLocalStorage` (v22, v20) or `async_hooks.createHook()` (v24, v22, v20) become vulnerable to denial-of-service crashes triggered by deep recursion under specific conditions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-59466 https://bugzilla.redhat.com/show_bug.cgi?id=2431343 https://www.cve.org/CVERecord?id=CVE-2025-59466 https://nvd.nist.gov/vuln/detail/CVE-2025-59466 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59466.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2eh/JThmMghcGbhP7jHOJw==&#34;: {&#xA;      &#34;id&#34;: &#34;2eh/JThmMghcGbhP7jHOJw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-31790&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-31790 https://bugzilla.redhat.com/show_bug.cgi?id=2451094 https://www.cve.org/CVERecord?id=CVE-2026-31790 https://nvd.nist.gov/vuln/detail/CVE-2026-31790 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31790.json https://access.redhat.com/errata/RHSA-2026:27744&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-fips-provider&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.0.7-11.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2fFhV4f06vNDz4aMbkPOZA==&#34;: {&#xA;      &#34;id&#34;: &#34;2fFhV4f06vNDz4aMbkPOZA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-28390&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T22:00:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-28390 https://bugzilla.redhat.com/show_bug.cgi?id=2456314 https://www.cve.org/CVERecord?id=CVE-2026-28390 https://nvd.nist.gov/vuln/detail/CVE-2026-28390 https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6 https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4 https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788 https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28390.json https://access.redhat.com/errata/RHSA-2026:22312&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-3.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2fxlvvJDIsNRRQuBzDD4oA==&#34;: {&#xA;      &#34;id&#34;: &#34;2fxlvvJDIsNRRQuBzDD4oA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-43619&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in rsync. A local attacker with filesystem access on the daemon host can exploit a symlink race vulnerability (CWE-367 Time-of-check to time-of-use) in rsync daemons configured with &#39;use chroot = no&#39;. This allows the attacker to redirect path-based system calls, such as chmod, lchown, or unlink, outside the intended module. This could lead to unauthorized file operations or other security bypasses.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-20T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-43619 https://bugzilla.redhat.com/show_bug.cgi?id=2469058 https://www.cve.org/CVERecord?id=CVE-2026-43619 https://nvd.nist.gov/vuln/detail/CVE-2026-43619 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43619.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2luu38jiVQvy6qOXHFgpAg==&#34;: {&#xA;      &#34;id&#34;: &#34;2luu38jiVQvy6qOXHFgpAg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2042&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free vulnerability was found in Vim&#39;s skipwhite() function of the src/charset.c file. This flaw occurs because of an uninitialized attribute value and freed memory in the spell command. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap use-after-free that causes an application to crash and corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-10T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2042 https://bugzilla.redhat.com/show_bug.cgi?id=2097768 https://www.cve.org/CVERecord?id=CVE-2022-2042 https://nvd.nist.gov/vuln/detail/CVE-2022-2042 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2042.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2sm08sXcjWtT2Gtu3CdSug==&#34;: {&#xA;      &#34;id&#34;: &#34;2sm08sXcjWtT2Gtu3CdSug==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-1725&#34;,&#xA;      &#34;description&#34;: &#34;A NULL pointer dereference vulnerability was found in Vim&#39;s vim_regexec_string() function of the src/regexp.c file. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a NULL pointer dereference that causes a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-1725 https://bugzilla.redhat.com/show_bug.cgi?id=2132561 https://www.cve.org/CVERecord?id=CVE-2022-1725 https://nvd.nist.gov/vuln/detail/CVE-2022-1725 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-1725.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2w9brA/+oZ5OEdpav+Dkzw==&#34;: {&#xA;      &#34;id&#34;: &#34;2w9brA/+oZ5OEdpav+Dkzw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-31790&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-31790 https://bugzilla.redhat.com/show_bug.cgi?id=2451094 https://www.cve.org/CVERecord?id=CVE-2026-31790 https://nvd.nist.gov/vuln/detail/CVE-2026-31790 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31790.json https://access.redhat.com/errata/RHSA-2026:27744&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-fips-provider-so&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.0.7-11.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;2wdtg9odVWp21dq/2MNviQ==&#34;: {&#xA;      &#34;id&#34;: &#34;2wdtg9odVWp21dq/2MNviQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14512&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib&#39;s GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-11T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14512 https://bugzilla.redhat.com/show_bug.cgi?id=2421339 https://www.cve.org/CVERecord?id=CVE-2025-14512 https://nvd.nist.gov/vuln/detail/CVE-2025-14512 https://gitlab.gnome.org/GNOME/glib/-/issues/3845 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14512.json https://access.redhat.com/errata/RHSA-2026:19361&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-19.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3285RkL43CGSYbmius5+sg==&#34;: {&#xA;      &#34;id&#34;: &#34;3285RkL43CGSYbmius5+sg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45186&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. When processing a specially crafted XML input containing a specific pattern of attributes, the parsing time increases quadratically due to checks for attribute name collisions. This consumes excessive CPU resources and eventually results in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-10T06:36:16Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45186 https://bugzilla.redhat.com/show_bug.cgi?id=2468575 https://www.cve.org/CVERecord?id=CVE-2026-45186 https://nvd.nist.gov/vuln/detail/CVE-2026-45186 https://github.com/libexpat/libexpat/pull/1216 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json https://access.redhat.com/errata/RHSA-2026:23230&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.5.0-6.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;352rQmt68kXSxd4G583XXA==&#34;: {&#xA;      &#34;id&#34;: &#34;352rQmt68kXSxd4G583XXA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rdoc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:6.6.3.1-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;38nk80Avdc96iwBjm0zdqA==&#34;: {&#xA;      &#34;id&#34;: &#34;38nk80Avdc96iwBjm0zdqA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48930&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. This vulnerability in the TLS (Transport Layer Security) hostname handling allows embedded null characters in hostnames. This can lead to silent authority rebinding, potentially enabling an attacker to redirect network traffic to an unintended server and disclose sensitive information.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:37Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48930 https://bugzilla.redhat.com/show_bug.cgi?id=2493326 https://www.cve.org/CVERecord?id=CVE-2026-48930 https://nvd.nist.gov/vuln/detail/CVE-2026-48930 https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e https://hackerone.com/reports/3656716 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48930.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3FpQibjt3OzhrwoSJ9I0Mg==&#34;: {&#xA;      &#34;id&#34;: &#34;3FpQibjt3OzhrwoSJ9I0Mg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-4598&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original&#39;s privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner&#39;s permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original&#39;s SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-4598 https://bugzilla.redhat.com/show_bug.cgi?id=2369242 https://www.cve.org/CVERecord?id=CVE-2025-4598 https://nvd.nist.gov/vuln/detail/CVE-2025-4598 https://www.openwall.com/lists/oss-security/2025/05/29/3 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4598.json https://access.redhat.com/errata/RHSA-2025:22660&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd-pam&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-55.el9_7.7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3KVKKCxdWl+iCbo/o6cUCw==&#34;: {&#xA;      &#34;id&#34;: &#34;3KVKKCxdWl+iCbo/o6cUCw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-61984&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH where control characters in usernames were not properly validated when sourced from untrusted inputs like the command line or configuration expansion. If a ProxyCommand is used, these control characters could modify command behavior, potentially leading to code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-61984 https://bugzilla.redhat.com/show_bug.cgi?id=2401960 https://www.cve.org/CVERecord?id=CVE-2025-61984 https://nvd.nist.gov/vuln/detail/CVE-2025-61984 https://marc.info/?l=openssh-unix-dev\u0026m=175974522032149\u0026w=2 https://www.openssh.com/releasenotes.html#10.1p1 https://www.openwall.com/lists/oss-security/2025/10/06/1 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61984.json https://access.redhat.com/errata/RHSA-2025:23480&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-47.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3Lvdmj//2sze9S8I3n8yrw==&#34;: {&#xA;      &#34;id&#34;: &#34;3Lvdmj//2sze9S8I3n8yrw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-0288&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-01-12T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-0288 https://bugzilla.redhat.com/show_bug.cgi?id=2163130 https://www.cve.org/CVERecord?id=CVE-2023-0288 https://nvd.nist.gov/vuln/detail/CVE-2023-0288 https://huntr.dev/bounties/5d389a18-5026-47df-a5d0-1548a9b555d5 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0288.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3R40oInfBrzPyywU8VZGOA==&#34;: {&#xA;      &#34;id&#34;: &#34;3R40oInfBrzPyywU8VZGOA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-61985&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH where the SSH client accepted \\0 (null) characters in ssh:// URIs. When a ProxyCommand is configured, these characters could alter how the command is parsed, potentially leading to code execution depending on how the proxy is set up.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-61985 https://bugzilla.redhat.com/show_bug.cgi?id=2401962 https://www.cve.org/CVERecord?id=CVE-2025-61985 https://nvd.nist.gov/vuln/detail/CVE-2025-61985 https://marc.info/?l=openssh-unix-dev\u0026m=175974522032149\u0026w=2 https://www.openssh.com/releasenotes.html#10.1p1 https://www.openwall.com/lists/oss-security/2025/10/06/1 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61985.json https://access.redhat.com/errata/RHSA-2025:23480&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-47.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3UNcgW64Eji4iyY2ZDB1cg==&#34;: {&#xA;      &#34;id&#34;: &#34;3UNcgW64Eji4iyY2ZDB1cg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-3783&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. When an OAuth2 bearer token is used for an HTTP(S) transfer that redirects to a second URL, curl could unintentionally leak the token. This occurs if the second hostname has entries in the `.netrc` file, allowing the bearer token intended for the first host to be sent to the redirected host. This information disclosure could allow an attacker to gain unauthorized access.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-11T10:09:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-3783 https://bugzilla.redhat.com/show_bug.cgi?id=2446450 https://www.cve.org/CVERecord?id=CVE-2026-3783 https://nvd.nist.gov/vuln/detail/CVE-2026-3783 http://www.openwall.com/lists/oss-security/2026/03/11/2 https://curl.se/docs/CVE-2026-3783.html https://curl.se/docs/CVE-2026-3783.json https://hackerone.com/reports/3583983 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3783.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3WRC4Vl08/leTJ1MFHuCEg==&#34;: {&#xA;      &#34;id&#34;: &#34;3WRC4Vl08/leTJ1MFHuCEg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3297&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free vulnerability was found in Vim&#39;s process_next_cpt_value() function of the src/insexpand.c file. This flaw occurs due to the usage of freed memory when &#39;tagfunc&#39; wipes out the buffer that holds &#39;complete.&#39; This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap use-after-free issue that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-25T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3297 https://bugzilla.redhat.com/show_bug.cgi?id=2129838 https://www.cve.org/CVERecord?id=CVE-2022-3297 https://nvd.nist.gov/vuln/detail/CVE-2022-3297 https://huntr.dev/bounties/1aa9ec92-0355-4710-bf85-5bce9effa01c https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3297.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3khZTPo1sdTxnkTY+5ATQg==&#34;: {&#xA;      &#34;id&#34;: &#34;3khZTPo1sdTxnkTY+5ATQg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1528&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a specially crafted WebSocket frame with an extremely large 64-bit length. This causes undici&#39;s ByteParser to overflow its internal calculations, leading to an invalid state and a fatal TypeError. The primary consequence is a Denial of Service (DoS), which terminates the process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:21:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1528 https://bugzilla.redhat.com/show_bug.cgi?id=2447145 https://www.cve.org/CVERecord?id=CVE-2026-1528 https://nvd.nist.gov/vuln/detail/CVE-2026-1528 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj https://hackerone.com/reports/3537648 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1528.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3lmx9lr/AS2B0oQRtI5gOA==&#34;: {&#xA;      &#34;id&#34;: &#34;3lmx9lr/AS2B0oQRtI5gOA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9076&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9076 https://bugzilla.redhat.com/show_bug.cgi?id=2481880 https://www.cve.org/CVERecord?id=CVE-2026-9076 https://nvd.nist.gov/vuln/detail/CVE-2026-9076 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9076.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3mM/O83kCBM7c1h3oioXHw==&#34;: {&#xA;      &#34;id&#34;: &#34;3mM/O83kCBM7c1h3oioXHw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-2229&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the undici WebSocket client. A remote malicious server can exploit this vulnerability by sending a WebSocket frame with an invalid `server_max_window_bits` parameter within the permessage-deflate extension. This improper validation causes the client&#39;s Node.js process to terminate, leading to a denial-of-service (DoS) condition for the client.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:27:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-2229 https://bugzilla.redhat.com/show_bug.cgi?id=2447143 https://www.cve.org/CVERecord?id=CVE-2026-2229 https://nvd.nist.gov/vuln/detail/CVE-2026-2229 https://cna.openjsf.org/security-advisories.html https://datatracker.ietf.org/doc/html/rfc7692 https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8 https://hackerone.com/reports/3487486 https://nodejs.org/api/zlib.html#class-zlibinflateraw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2229.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3mZTUjJt0v6SBGf7lIXm2Q==&#34;: {&#xA;      &#34;id&#34;: &#34;3mZTUjJt0v6SBGf7lIXm2Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-7383&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-7383 https://bugzilla.redhat.com/show_bug.cgi?id=2481879 https://www.cve.org/CVERecord?id=CVE-2026-7383 https://nvd.nist.gov/vuln/detail/CVE-2026-7383 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7383.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3xFSeDOxGkdisnqW9w6B+Q==&#34;: {&#xA;      &#34;id&#34;: &#34;3xFSeDOxGkdisnqW9w6B+Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-53655&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar. This vulnerability arises because node-tar incorrectly applies PAX extended header size records to subsequent intermediary metadata headers, leading to a desynchronization of the tar stream cursor compared to other standard tar implementations. A remote attacker could exploit this by crafting a malicious archive, causing different interpretations of archive contents between node-tar and other tools. This could allow an attacker to hide malicious files or sensitive information from security scanners that rely on different tar parsing libraries, potentially leading to information disclosure or bypassing security controls.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-22T14:55:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-53655 https://bugzilla.redhat.com/show_bug.cgi?id=2491423 https://www.cve.org/CVERecord?id=CVE-2026-53655 https://nvd.nist.gov/vuln/detail/CVE-2026-53655 https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53655.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;3zxG1J6bDKAhZ9wlUE9Y4g==&#34;: {&#xA;      &#34;id&#34;: &#34;3zxG1J6bDKAhZ9wlUE9Y4g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48935&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. The Permission API allows a local user to modify file metadata on paths that have been explicitly set as read-only. This can lead to unauthorized changes in file properties, impacting the integrity of the file system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48935 https://bugzilla.redhat.com/show_bug.cgi?id=2493329 https://www.cve.org/CVERecord?id=CVE-2026-48935 https://nvd.nist.gov/vuln/detail/CVE-2026-48935 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48935.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;40wPd5q9E1sRluf3JeA8hw==&#34;: {&#xA;      &#34;id&#34;: &#34;40wPd5q9E1sRluf3JeA8hw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42764&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the OpenSSL QUIC (Quick UDP Internet Connections) server. A remote attacker could send a specially crafted QUIC initial packet with an invalid token. If the server&#39;s address validation is explicitly disabled, this could lead to a NULL pointer dereference, causing the server process to terminate abnormally and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42764 https://bugzilla.redhat.com/show_bug.cgi?id=2481887 https://www.cve.org/CVERecord?id=CVE-2026-42764 https://nvd.nist.gov/vuln/detail/CVE-2026-42764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42764.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;41OUTxSbBLQGne4TzJuTQg==&#34;: {&#xA;      &#34;id&#34;: &#34;41OUTxSbBLQGne4TzJuTQg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-2673&#34;,&#xA;      &#34;description&#34;: &#34;A key group selection preference flaw has been discovered in OpenSSL. An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the \&#34;DEFAULT\&#34; keyword. A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client&#39;s initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-13T13:23:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-2673 https://bugzilla.redhat.com/show_bug.cgi?id=2447327 https://www.cve.org/CVERecord?id=CVE-2026-2673 https://nvd.nist.gov/vuln/detail/CVE-2026-2673 https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34 https://openssl-library.org/news/secadv/20260313.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2673.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;49x+aBSIi92s9+9k0YBLsA==&#34;: {&#xA;      &#34;id&#34;: &#34;49x+aBSIi92s9+9k0YBLsA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14087&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14087 https://bugzilla.redhat.com/show_bug.cgi?id=2419093 https://www.cve.org/CVERecord?id=CVE-2025-14087 https://nvd.nist.gov/vuln/detail/CVE-2025-14087 https://gitlab.gnome.org/GNOME/glib/-/issues/3834 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14087.json https://access.redhat.com/errata/RHSA-2026:19361&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-19.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4BI9AbtF5Vb7puMudQmp2w==&#34;: {&#xA;      &#34;id&#34;: &#34;4BI9AbtF5Vb7puMudQmp2w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-2229&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the undici WebSocket client. A remote malicious server can exploit this vulnerability by sending a WebSocket frame with an invalid `server_max_window_bits` parameter within the permessage-deflate extension. This improper validation causes the client&#39;s Node.js process to terminate, leading to a denial-of-service (DoS) condition for the client.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:27:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-2229 https://bugzilla.redhat.com/show_bug.cgi?id=2447143 https://www.cve.org/CVERecord?id=CVE-2026-2229 https://nvd.nist.gov/vuln/detail/CVE-2026-2229 https://cna.openjsf.org/security-advisories.html https://datatracker.ietf.org/doc/html/rfc7692 https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8 https://hackerone.com/reports/3487486 https://nodejs.org/api/zlib.html#class-zlibinflateraw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2229.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4FPYx+QEdkXz09AmCNB74A==&#34;: {&#xA;      &#34;id&#34;: &#34;4FPYx+QEdkXz09AmCNB74A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-2229&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the undici WebSocket client. A remote malicious server can exploit this vulnerability by sending a WebSocket frame with an invalid `server_max_window_bits` parameter within the permessage-deflate extension. This improper validation causes the client&#39;s Node.js process to terminate, leading to a denial-of-service (DoS) condition for the client.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:27:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-2229 https://bugzilla.redhat.com/show_bug.cgi?id=2447143 https://www.cve.org/CVERecord?id=CVE-2026-2229 https://nvd.nist.gov/vuln/detail/CVE-2026-2229 https://cna.openjsf.org/security-advisories.html https://datatracker.ietf.org/doc/html/rfc7692 https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8 https://hackerone.com/reports/3487486 https://nodejs.org/api/zlib.html#class-zlibinflateraw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2229.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4H2TsDPy1XcHidTqNqeZpg==&#34;: {&#xA;      &#34;id&#34;: &#34;4H2TsDPy1XcHidTqNqeZpg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4519&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python. The `webbrowser.open()` API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T15:08:32Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4519 https://bugzilla.redhat.com/show_bug.cgi?id=2449649 https://www.cve.org/CVERecord?id=CVE-2026-4519 https://nvd.nist.gov/vuln/detail/CVE-2026-4519 https://github.com/python/cpython/issues/143930 https://github.com/python/cpython/pull/143931 https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4519.json https://access.redhat.com/errata/RHSA-2026:6766&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4IJCXmCxOCf3t6/rsnea/A==&#34;: {&#xA;      &#34;id&#34;: &#34;4IJCXmCxOCf3t6/rsnea/A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-io-console&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.7.1-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4Ir8FDWM4WPrO3dybbfnYQ==&#34;: {&#xA;      &#34;id&#34;: &#34;4Ir8FDWM4WPrO3dybbfnYQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-13837&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the plistlib module in the Python standard library. The amount of data to read from a Plist file is specified in the file itself. This issue allows a specially crafted Plist file to cause an application to allocate a large amount of memory, potentially resulting in allocations errors, swapping, out-of-memory conditions or even system freezes.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-01T18:13:32Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-13837 https://bugzilla.redhat.com/show_bug.cgi?id=2418084 https://www.cve.org/CVERecord?id=CVE-2025-13837 https://nvd.nist.gov/vuln/detail/CVE-2025-13837 https://github.com/python/cpython/issues/119342 https://github.com/python/cpython/pull/119343 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13837.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4LZWGm07jnOHHBGX2FzAwg==&#34;: {&#xA;      &#34;id&#34;: &#34;4LZWGm07jnOHHBGX2FzAwg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-1153&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GNU Binutils. A specially-crafted payload may be able to trigger a memory leak, which can lead to an application crash or other undefined behavior.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-10T19:00:13Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-1153 https://bugzilla.redhat.com/show_bug.cgi?id=2344743 https://www.cve.org/CVERecord?id=CVE-2025-1153 https://nvd.nist.gov/vuln/detail/CVE-2025-1153 https://sourceware.org/bugzilla/show_bug.cgi?id=32603 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150 https://vuldb.com/?ctiid.295057 https://vuldb.com/?id.295057 https://vuldb.com/?submit.489991 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1153.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4Ocx5vfc88FjutK1oBwpCQ==&#34;: {&#xA;      &#34;id&#34;: &#34;4Ocx5vfc88FjutK1oBwpCQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42013&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42013 https://bugzilla.redhat.com/show_bug.cgi?id=2467448 https://www.cve.org/CVERecord?id=CVE-2026-42013 https://nvd.nist.gov/vuln/detail/CVE-2026-42013 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42013.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4TbG63vud59mo+N/aCOqpg==&#34;: {&#xA;      &#34;id&#34;: &#34;4TbG63vud59mo+N/aCOqpg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15367&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the poplib module in the Python standard library. The poplib module does not reject control characters, such as newlines, in user-controlled input passed to POP3 commands. This issue allows an attacker to inject additional commands to be executed in the POP3 server.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:47:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15367 https://bugzilla.redhat.com/show_bug.cgi?id=2431373 https://www.cve.org/CVERecord?id=CVE-2025-15367 https://nvd.nist.gov/vuln/detail/CVE-2025-15367 https://github.com/python/cpython/issues/143923 https://github.com/python/cpython/pull/143924 https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15367.json https://access.redhat.com/errata/RHSA-2026:4168&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4W4pMj/8K/7jCdYTXT5uEg==&#34;: {&#xA;      &#34;id&#34;: &#34;4W4pMj/8K/7jCdYTXT5uEg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11940&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the `tarfile.extractall()` function within Python. A remote attacker could exploit this vulnerability by providing a specially crafted archive. This archive could bypass security filters by using a hardlink that references a symlink, allowing the symlink to be recreated outside the intended destination directory. This could lead to out-of-destination file reads or writes, potentially resulting in information disclosure or arbitrary file modification.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-23T16:04:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11940 https://bugzilla.redhat.com/show_bug.cgi?id=2491848 https://www.cve.org/CVERecord?id=CVE-2026-11940 https://nvd.nist.gov/vuln/detail/CVE-2026-11940 https://github.com/python/cpython/issues/151558 https://github.com/python/cpython/pull/151559 https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11940.json https://access.redhat.com/errata/RHSA-2026:54268&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-7.el9_8.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4WgtH2AC4w3jDaPCHFqEaw==&#34;: {&#xA;      &#34;id&#34;: &#34;4WgtH2AC4w3jDaPCHFqEaw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11494&#34;,&#xA;      &#34;description&#34;: &#34;An out of bounds read flaw has been discovered in the GNU Binutils package. The impacted function is _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-08T19:32:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11494 https://bugzilla.redhat.com/show_bug.cgi?id=2402559 https://www.cve.org/CVERecord?id=CVE-2025-11494 https://nvd.nist.gov/vuln/detail/CVE-2025-11494 https://sourceware.org/bugzilla/attachment.cgi?id=16389 https://sourceware.org/bugzilla/show_bug.cgi?id=33499 https://sourceware.org/bugzilla/show_bug.cgi?id=33499#c2 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a https://vuldb.com/?ctiid.327619 https://vuldb.com/?id.327619 https://vuldb.com/?submit.668281 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11494.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4XO5TL/zvh/gBT0sz3RSYw==&#34;: {&#xA;      &#34;id&#34;: &#34;4XO5TL/zvh/gBT0sz3RSYw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-13149&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-30T08:30:34Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-13149 https://bugzilla.redhat.com/show_bug.cgi?id=2494813 https://www.cve.org/CVERecord?id=CVE-2026-13149 https://nvd.nist.gov/vuln/detail/CVE-2026-13149 https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754 https://www.npmjs.com/package/brace-expansion https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4aJ6IaFsuGhRpz+mkfUGqQ==&#34;: {&#xA;      &#34;id&#34;: &#34;4aJ6IaFsuGhRpz+mkfUGqQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48615&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48615 https://bugzilla.redhat.com/show_bug.cgi?id=2493335 https://www.cve.org/CVERecord?id=CVE-2026-48615 https://nvd.nist.gov/vuln/detail/CVE-2026-48615 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48615.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4ardx/cPJA31l/GjZ5ssvw==&#34;: {&#xA;      &#34;id&#34;: &#34;4ardx/cPJA31l/GjZ5ssvw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bigdecimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.1.5-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4g6F/e8mwPh04jP3QYJj0w==&#34;: {&#xA;      &#34;id&#34;: &#34;4g6F/e8mwPh04jP3QYJj0w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-json&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.7.2-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4kuxrTpUDtZ3uFOEEztq9g==&#34;: {&#xA;      &#34;id&#34;: &#34;4kuxrTpUDtZ3uFOEEztq9g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48933&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48933 https://bugzilla.redhat.com/show_bug.cgi?id=2493331 https://www.cve.org/CVERecord?id=CVE-2026-48933 https://nvd.nist.gov/vuln/detail/CVE-2026-48933 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4o31bbgKJ2cSqPGCPyFjLQ==&#34;: {&#xA;      &#34;id&#34;: &#34;4o31bbgKJ2cSqPGCPyFjLQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-56404&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. This vulnerability, an integer overflow in the `addBinding` function, could allow a local attacker to execute arbitrary code. By exploiting this, an attacker could gain control over the affected system, compromising its confidentiality and integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-21T15:45:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-56404 https://bugzilla.redhat.com/show_bug.cgi?id=2491185 https://www.cve.org/CVERecord?id=CVE-2026-56404 https://nvd.nist.gov/vuln/detail/CVE-2026-56404 https://github.com/libexpat/libexpat/pull/1249 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56404.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4os+HU28VQ7buZvoEKQ/kg==&#34;: {&#xA;      &#34;id&#34;: &#34;4os+HU28VQ7buZvoEKQ/kg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34757&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng, a library used for handling PNG (Portable Network Graphics) image files. This vulnerability arises when an application reuses a pointer, previously obtained from functions like png_get_PLTE, by passing it back to a corresponding setter function within the same image structure. This action causes the setter to access memory that has already been deallocated, leading to a use-after-free condition. A local attacker could potentially exploit this flaw to corrupt image metadata or disclose sensitive information from the application&#39;s memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-09T14:41:18Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34757 https://bugzilla.redhat.com/show_bug.cgi?id=2456918 https://www.cve.org/CVERecord?id=CVE-2026-34757 https://nvd.nist.gov/vuln/detail/CVE-2026-34757 https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc https://github.com/pnggroup/libpng/issues/836 https://github.com/pnggroup/libpng/issues/837 https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34757.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4u3exWl+MPcCOYOgbQLM+A==&#34;: {&#xA;      &#34;id&#34;: &#34;4u3exWl+MPcCOYOgbQLM+A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69419&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When processing a specially crafted PKCS#12 (Personal Information Exchange Syntax Standard) file, a remote attacker can exploit an out-of-bounds write vulnerability. This issue, occurring within the OPENSSL_uni2utf8() function, leads to memory corruption by writing data beyond its allocated buffer. Successful exploitation could result in a denial of service or potentially allow for arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69419 https://bugzilla.redhat.com/show_bug.cgi?id=2430386 https://www.cve.org/CVERecord?id=CVE-2025-69419 https://nvd.nist.gov/vuln/detail/CVE-2025-69419 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69419.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4ugLfuPhGpzb4ohYABxG+w==&#34;: {&#xA;      &#34;id&#34;: &#34;4ugLfuPhGpzb4ohYABxG+w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-29111&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-23T21:03:56Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-29111 https://bugzilla.redhat.com/show_bug.cgi?id=2450505 https://www.cve.org/CVERecord?id=CVE-2026-29111 https://nvd.nist.gov/vuln/detail/CVE-2026-29111 https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6 https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8 https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29111.json https://access.redhat.com/errata/RHSA-2026:19213&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd-rpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-67.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4w9ia49tOv0+yiq1lgkH0w==&#34;: {&#xA;      &#34;id&#34;: &#34;4w9ia49tOv0+yiq1lgkH0w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-15308&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python. Its incremental HTML parser can be exploited by a remote attacker. By sending specially crafted, uncontrolled data with repeated, incomplete markup declarations, the attacker can cause the system to consume excessive central processing unit (CPU) resources. This leads to a denial of service, making the affected system unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-09T17:10:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-15308 https://bugzilla.redhat.com/show_bug.cgi?id=2498608 https://www.cve.org/CVERecord?id=CVE-2026-15308 https://nvd.nist.gov/vuln/detail/CVE-2026-15308 https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9 https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606 https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd https://github.com/python/cpython/issues/153030 https://github.com/python/cpython/pull/153031 https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15308.json https://access.redhat.com/errata/RHSA-2026:39798&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-7.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;4wegIDtvEZ75QrQWM65auQ==&#34;: {&#xA;      &#34;id&#34;: &#34;4wegIDtvEZ75QrQWM65auQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69650&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted ELF binary file containing malformed relocation data with the readelf program can trigger a double free, causing a crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69650 https://bugzilla.redhat.com/show_bug.cgi?id=2445293 https://www.cve.org/CVERecord?id=CVE-2025-69650 https://nvd.nist.gov/vuln/detail/CVE-2025-69650 https://sourceware.org/bugzilla/show_bug.cgi?id=33698 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69650.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;55p6NGxCWjOVcUCBGiCPzw==&#34;: {&#xA;      &#34;id&#34;: &#34;55p6NGxCWjOVcUCBGiCPzw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-45582&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GNU Tar. An attacker could exploit this vulnerability by providing two specially crafted TAR archives, if those archives were extracted in the same directory. The first archive contains a symbolic link that points to a critical directory. The second archive, when extracted, uses this symbolic link to overwrite sensitive files on the system, bypassing existing directory traversal protections. This could lead to unauthorized file modification or, in some cases, privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-11T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-45582 https://bugzilla.redhat.com/show_bug.cgi?id=2379592 https://www.cve.org/CVERecord?id=CVE-2025-45582 https://nvd.nist.gov/vuln/detail/CVE-2025-45582 https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md https://www.gnu.org/software/tar/ https://www.gnu.org/software/tar/manual/html_node/Integrity.html#Integrity https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-45582.json https://access.redhat.com/errata/RHSA-2026:0067&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.34-9.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;58xLQ2pjmhkIctIR/pZ5pw==&#34;: {&#xA;      &#34;id&#34;: &#34;58xLQ2pjmhkIctIR/pZ5pw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4786&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Python webbrowser.open() API. If a specially crafted URL containing \&#34;%action\&#34; is processed, an attacker could bypass a previous mitigation for CVE-2026-4519. This bypass allows for command injection into the underlying shell, potentially leading to arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-13T21:52:19Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4786 https://bugzilla.redhat.com/show_bug.cgi?id=2458049 https://www.cve.org/CVERecord?id=CVE-2026-4786 https://nvd.nist.gov/vuln/detail/CVE-2026-4786 https://github.com/python/cpython/issues/148169 https://github.com/python/cpython/pull/148170 https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4786.json https://access.redhat.com/errata/RHSA-2026:10949&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5BksN0izCeDRrtFMsNCyvg==&#34;: {&#xA;      &#34;id&#34;: &#34;5BksN0izCeDRrtFMsNCyvg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-9232&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the OpenSSL HTTP client API no_proxy handling. This vulnerability allows an application level denial of service (application crash) via an attacker-controlled IPv6 URL when the no_proxy environment variable is set.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-30T23:59:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-9232 https://bugzilla.redhat.com/show_bug.cgi?id=2396056 https://www.cve.org/CVERecord?id=CVE-2025-9232 https://nvd.nist.gov/vuln/detail/CVE-2025-9232 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9232.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5C8DQrs9fwpmV8rRYlvfCQ==&#34;: {&#xA;      &#34;id&#34;: &#34;5C8DQrs9fwpmV8rRYlvfCQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66865&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted PE file with cxxfilt can trigger a stack overflow in the d_print_comp_inner function in the cp-demangle.c file, causing a crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66865 https://bugzilla.redhat.com/show_bug.cgi?id=2425822 https://www.cve.org/CVERecord?id=CVE-2025-66865 https://nvd.nist.gov/vuln/detail/CVE-2025-66865 https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66865.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5D5WFK01Su4Lrj4hhwDYGQ==&#34;: {&#xA;      &#34;id&#34;: &#34;5D5WFK01Su4Lrj4hhwDYGQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-43374&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free vulnerability was found in Vim&#39;s alist_add() function. Adding a new file to the argument list triggers Buf* autocommands. In an autocommand, if the buffer that was just opened is closed, including the window where it is shown, it causes the window structure to be freed, containing a reference to the argument list that is being modified. Once the autocommands are completed, references to the window and argument list are no longer valid, causing a use-after-free issue. To trigger this issue, a local attacker or user must add unusual autocommands that wipe a buffer during creation, either manually or by sourcing a malicious plugin, which will cause Vim to crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-08-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-43374 https://bugzilla.redhat.com/show_bug.cgi?id=2305259 https://www.cve.org/CVERecord?id=CVE-2024-43374 https://nvd.nist.gov/vuln/detail/CVE-2024-43374 https://github.com/vim/vim/commit/0a6e57b09bc8c76691b367a5babfb79b31b770e8 https://github.com/vim/vim/security/advisories/GHSA-2w8m-443v-cgvw https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-43374.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5JPRWlHhzvwdgcYt2OnpZg==&#34;: {&#xA;      &#34;id&#34;: &#34;5JPRWlHhzvwdgcYt2OnpZg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-58013&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-03T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-58013 https://bugzilla.redhat.com/show_bug.cgi?id=2492248 https://www.cve.org/CVERecord?id=CVE-2026-58013 https://nvd.nist.gov/vuln/detail/CVE-2026-58013 https://gitlab.gnome.org/GNOME/glib/-/issues/3925 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58013.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5LplZpuSZzAiOH2fmk3HWg==&#34;: {&#xA;      &#34;id&#34;: &#34;5LplZpuSZzAiOH2fmk3HWg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14104&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1913&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libblkid-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.37.4-21.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5QvPKgPa787NiewytO5Aqg==&#34;: {&#xA;      &#34;id&#34;: &#34;5QvPKgPa787NiewytO5Aqg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21710&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request that includes a header named `__proto__`. When a Node.js application processes this request and attempts to access distinct headers, it encounters an unhandled error, leading to an application crash. This can result in a Denial of Service (DoS), making the affected service unavailable to users.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T19:07:28Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21710 https://bugzilla.redhat.com/show_bug.cgi?id=2453151 https://www.cve.org/CVERecord?id=CVE-2026-21710 https://nvd.nist.gov/vuln/detail/CVE-2026-21710 https://nodejs.org/en/blog/vulnerability/march-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21710.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5VGw1oph7DgrzGqxDXSJIA==&#34;: {&#xA;      &#34;id&#34;: &#34;5VGw1oph7DgrzGqxDXSJIA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42250&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in bzip2. The bzip2recover utility contains an off-by-one error that allows a local attacker to cause an out-of-bounds write to a global buffer by processing a specially crafted file. This memory corruption can lead to a crash, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-28T13:15:19Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42250 https://bugzilla.redhat.com/show_bug.cgi?id=2482704 https://www.cve.org/CVERecord?id=CVE-2026-42250 https://nvd.nist.gov/vuln/detail/CVE-2026-42250 https://cert.pl/en/posts/2026/05/CVE-2026-42250/ https://sourceware.org/bzip2/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42250.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;bzip2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5Wx/BMcr6FkgwAbn3tdwLA==&#34;: {&#xA;      &#34;id&#34;: &#34;5Wx/BMcr6FkgwAbn3tdwLA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48618&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. This flaw involves a mismatch in how Node.js handles TLS (Transport Layer Security) hostnames and unicode dot separators during authentication. This mismatch can lead to a wildcard-depth authentication bypass. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access and confidentiality impact.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48618 https://bugzilla.redhat.com/show_bug.cgi?id=2493337 https://www.cve.org/CVERecord?id=CVE-2026-48618 https://nvd.nist.gov/vuln/detail/CVE-2026-48618 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5ZeuGlt87r+CNRRQDhU5uw==&#34;: {&#xA;      &#34;id&#34;: &#34;5ZeuGlt87r+CNRRQDhU5uw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5260&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5260 https://bugzilla.redhat.com/show_bug.cgi?id=2467450 https://www.cve.org/CVERecord?id=CVE-2026-5260 https://nvd.nist.gov/vuln/detail/CVE-2026-5260 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-10 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5260.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5amguv6OT1njd8r+RXMCQQ==&#34;: {&#xA;      &#34;id&#34;: &#34;5amguv6OT1njd8r+RXMCQQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66199&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker can exploit this vulnerability by sending a specially crafted CompressedCertificate message during the TLS 1.3 handshake. This can cause excessive per-connection memory allocations, leading to resource exhaustion and a Denial of Service (DoS) for affected clients and servers. This issue occurs when TLS 1.3 certificate compression is enabled and negotiated.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66199 https://bugzilla.redhat.com/show_bug.cgi?id=2430379 https://www.cve.org/CVERecord?id=CVE-2025-66199 https://nvd.nist.gov/vuln/detail/CVE-2025-66199 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66199.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5d35KoGqN7hqoORJbRxrzg==&#34;: {&#xA;      &#34;id&#34;: &#34;5d35KoGqN7hqoORJbRxrzg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4437&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4437 https://bugzilla.redhat.com/show_bug.cgi?id=2449777 https://www.cve.org/CVERecord?id=CVE-2026-4437 https://nvd.nist.gov/vuln/detail/CVE-2026-4437 https://sourceware.org/bugzilla/show_bug.cgi?id=34014 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4437.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-headers&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5kIWJ0hrLSTGTMvu/m2VBg==&#34;: {&#xA;      &#34;id&#34;: &#34;5kIWJ0hrLSTGTMvu/m2VBg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-15003&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-27T13:15:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-15003 https://bugzilla.redhat.com/show_bug.cgi?id=2497805 https://www.cve.org/CVERecord?id=CVE-2026-15003 https://nvd.nist.gov/vuln/detail/CVE-2026-15003 https://sourceware.org/bugzilla/show_bug.cgi?id=34053 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15003.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5mdxwKcXZHEqEguvWMJQ3w==&#34;: {&#xA;      &#34;id&#34;: &#34;5mdxwKcXZHEqEguvWMJQ3w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34183&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL&#39;s QUIC PATH_CHALLENGE handler. A remote attacker can exploit this vulnerability by flooding a QUIC client or server with specially crafted PATH_CHALLENGE frames. This leads to unbounded memory allocation within the local QUIC stack, as the system continuously allocates PATH_RESPONSE frames without them being acknowledged. The primary consequence is a Denial of Service (DoS), causing the affected application to terminate abnormally due to memory exhaustion.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34183 https://bugzilla.redhat.com/show_bug.cgi?id=2481885 https://www.cve.org/CVERecord?id=CVE-2026-34183 https://nvd.nist.gov/vuln/detail/CVE-2026-34183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34183.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5pY8wChj1DLVETzEMa22Ig==&#34;: {&#xA;      &#34;id&#34;: &#34;5pY8wChj1DLVETzEMa22Ig==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-31790&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-31790 https://bugzilla.redhat.com/show_bug.cgi?id=2451094 https://www.cve.org/CVERecord?id=CVE-2026-31790 https://nvd.nist.gov/vuln/detail/CVE-2026-31790 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31790.json https://access.redhat.com/errata/RHSA-2026:19218&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-2.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;5snUlx7ztOquC9N7WioMbg==&#34;: {&#xA;      &#34;id&#34;: &#34;5snUlx7ztOquC9N7WioMbg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6+K4D2mkqcFFftanju984w==&#34;: {&#xA;      &#34;id&#34;: &#34;6+K4D2mkqcFFftanju984w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69420&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A type confusion vulnerability exists in the TimeStamp Response verification code, where an ASN1_TYPE union member is accessed without proper type validation. A remote attacker can exploit this by providing a malformed TimeStamp Response to an application that verifies timestamp responses. This can lead to an invalid or NULL pointer dereference, resulting in a Denial of Service (DoS) due to an application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69420 https://bugzilla.redhat.com/show_bug.cgi?id=2430388 https://www.cve.org/CVERecord?id=CVE-2025-69420 https://nvd.nist.gov/vuln/detail/CVE-2025-69420 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69420.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6+TrxTb+GrNbsX7xQgQW9Q==&#34;: {&#xA;      &#34;id&#34;: &#34;6+TrxTb+GrNbsX7xQgQW9Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11187&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When an application processes a maliciously crafted PKCS#12 file, an attacker can exploit a stack buffer overflow or a NULL pointer dereference. This can lead to a denial of service (DoS) by crashing the application, and in some cases, may enable arbitrary code execution. The vulnerability arises from the lack of validation for PBKDF2 salt and keylength parameters within the PKCS#12 file.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11187 https://bugzilla.redhat.com/show_bug.cgi?id=2430375 https://www.cve.org/CVERecord?id=CVE-2025-11187 https://nvd.nist.gov/vuln/detail/CVE-2025-11187 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11187.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6+rn6nrQrafYloJtAeJ2Bg==&#34;: {&#xA;      &#34;id&#34;: &#34;6+rn6nrQrafYloJtAeJ2Bg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-11053&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. A logic error when processing credentials from the .netrc file while performing redirects allows the transfer of credentials from the original host to the followed-to host under certain circumstances, leaking the credentials to the followed-to host.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-12-11T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-11053 https://bugzilla.redhat.com/show_bug.cgi?id=2331191 https://www.cve.org/CVERecord?id=CVE-2024-11053 https://nvd.nist.gov/vuln/detail/CVE-2024-11053 https://curl.se/docs/CVE-2024-11053.html https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-11053.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6F1zSnZjp7g1twFO1AhdxA==&#34;: {&#xA;      &#34;id&#34;: &#34;6F1zSnZjp7g1twFO1AhdxA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5450&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:55:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-gconv-extra&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-272.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6G2lzRj8p7v2QJ3GPO3i9Q==&#34;: {&#xA;      &#34;id&#34;: &#34;6G2lzRj8p7v2QJ3GPO3i9Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-irb&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.13.1-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6LOgJE44rXWziB7/OMO/ig==&#34;: {&#xA;      &#34;id&#34;: &#34;6LOgJE44rXWziB7/OMO/ig==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-28422&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open-source command-line text editor. A local user could exploit a stack-buffer-overflow vulnerability in the `build_stl_str_hl()` function by rendering a statusline with a multi-byte fill character on a very wide terminal. This could lead to an integrity impact, where data might be modified.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-27T22:08:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-28422 https://bugzilla.redhat.com/show_bug.cgi?id=2443475 https://www.cve.org/CVERecord?id=CVE-2026-28422 https://nvd.nist.gov/vuln/detail/CVE-2026-28422 https://github.com/vim/vim/commit/4e5b9e31cb7484ad156f https://github.com/vim/vim/releases/tag/v9.2.0078 https://github.com/vim/vim/security/advisories/GHSA-gmqx-prf2-8mwf https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28422.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6LazNwUBgu5kQGKPCQnaOw==&#34;: {&#xA;      &#34;id&#34;: &#34;6LazNwUBgu5kQGKPCQnaOw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-26269&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. A stack-based buffer overflow in the NetBeans integration can be triggered in the special_keys function in the src/netbeans.c file via a malicious NetBeans server due to improper bounds checking, most likely resulting in a denial of service or in arbitrary command execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-13T19:18:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-26269 https://bugzilla.redhat.com/show_bug.cgi?id=2439755 https://www.cve.org/CVERecord?id=CVE-2026-26269 https://nvd.nist.gov/vuln/detail/CVE-2026-26269 https://github.com/vim/vim/commit/c5f312aad8e4179e437f81ad39a860cd0ef11970 https://github.com/vim/vim/releases/tag/v9.1.2148 https://github.com/vim/vim/security/advisories/GHSA-9w5c-hwr9-hc68 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26269.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6MW1lRUdNNc4s+6uD2JNvw==&#34;: {&#xA;      &#34;id&#34;: &#34;6MW1lRUdNNc4s+6uD2JNvw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2286&#34;,&#xA;      &#34;description&#34;: &#34;Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-07-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2286 https://bugzilla.redhat.com/show_bug.cgi?id=2103875 https://www.cve.org/CVERecord?id=CVE-2022-2286 https://nvd.nist.gov/vuln/detail/CVE-2022-2286 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2286.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6Mz5HTJNfyHd+tBxi8A32w==&#34;: {&#xA;      &#34;id&#34;: &#34;6Mz5HTJNfyHd+tBxi8A32w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-json&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.7.2-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6QirCtH9GCLBepYrxwQRIg==&#34;: {&#xA;      &#34;id&#34;: &#34;6QirCtH9GCLBepYrxwQRIg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-25646&#34;,&#xA;      &#34;description&#34;: &#34;A heap based buffer overflow flaw has been discovered in LibPNG. Prior to version 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user&#39;s display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-10T17:04:38Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-25646 https://bugzilla.redhat.com/show_bug.cgi?id=2438542 https://www.cve.org/CVERecord?id=CVE-2026-25646 https://nvd.nist.gov/vuln/detail/CVE-2026-25646 http://www.openwall.com/lists/oss-security/2026/02/09/7 https://github.com/pnggroup/libpng/commit/01d03b8453eb30ade759cd45c707e5a1c7277d88 https://github.com/pnggroup/libpng/security/advisories/GHSA-g8hp-mq4h-rqm3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25646.json https://access.redhat.com/errata/RHSA-2026:3405&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6ULb2hTeXRKRWDAjQMdnAQ==&#34;: {&#xA;      &#34;id&#34;: &#34;6ULb2hTeXRKRWDAjQMdnAQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:37:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-headers&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6asSIEJz7ggo9QEXpbSOYg==&#34;: {&#xA;      &#34;id&#34;: &#34;6asSIEJz7ggo9QEXpbSOYg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-48236&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open source command line text editor. When using the z= command, the user may overflow the count with values larger than MAX_INT. The impact is low because user interaction is required and a crash may not happen in all situations.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-11-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-48236 https://bugzilla.redhat.com/show_bug.cgi?id=2250273 https://www.cve.org/CVERecord?id=CVE-2023-48236 https://nvd.nist.gov/vuln/detail/CVE-2023-48236 http://www.openwall.com/lists/oss-security/2023/11/16/1 https://github.com/vim/vim/commit/73b2d3790cad5694fc0ed0db2926e4220c48d968 https://github.com/vim/vim/security/advisories/GHSA-pr4c-932v-8hx5 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-48236.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6dwQWrojfQ/1hgTT2PQckg==&#34;: {&#xA;      &#34;id&#34;: &#34;6dwQWrojfQ/1hgTT2PQckg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2129&#34;,&#xA;      &#34;description&#34;: &#34;Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2129 https://bugzilla.redhat.com/show_bug.cgi?id=2099586 https://www.cve.org/CVERecord?id=CVE-2022-2129 https://nvd.nist.gov/vuln/detail/CVE-2022-2129 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2129.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6hAQW3vY9ZA/8datv1rY4g==&#34;: {&#xA;      &#34;id&#34;: &#34;6hAQW3vY9ZA/8datv1rY4g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-41996&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server&#39;s public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-08-26T06:15:04Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-41996 https://bugzilla.redhat.com/show_bug.cgi?id=2307826 https://www.cve.org/CVERecord?id=CVE-2024-41996 https://nvd.nist.gov/vuln/detail/CVE-2024-41996 https://dheatattack.gitlab.io/details/ https://dheatattack.gitlab.io/faq/ https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1 https://github.com/openssl/openssl/issues/17374 https://openssl-library.org/post/2022-10-21-tls-groups-configuration/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-41996.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6o8ui0RxMttDzkyqTDO5tg==&#34;: {&#xA;      &#34;id&#34;: &#34;6o8ui0RxMttDzkyqTDO5tg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-1616&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim, which is vulnerable to a heap-buffer-overflow in append_command of the src/ex_docmd.c function. This flaw allows a specially crafted file to crash software, modify memory, or execute code when opened in vim.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-05-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-1616 https://bugzilla.redhat.com/show_bug.cgi?id=2083017 https://www.cve.org/CVERecord?id=CVE-2022-1616 https://nvd.nist.gov/vuln/detail/CVE-2022-1616 https://huntr.dev/bounties/40f1d75f-fb2f-4281-b585-a41017f217e2/ https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-1616.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6pxKX6FKH4aTek+6noKFjQ==&#34;: {&#xA;      &#34;id&#34;: &#34;6pxKX6FKH4aTek+6noKFjQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42009&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42009 https://bugzilla.redhat.com/show_bug.cgi?id=2467279 https://www.cve.org/CVERecord?id=CVE-2026-42009 https://nvd.nist.gov/vuln/detail/CVE-2026-42009 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;6rEIsdyQtCC456AuGwgsDQ==&#34;: {&#xA;      &#34;id&#34;: &#34;6rEIsdyQtCC456AuGwgsDQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15079&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15079 https://bugzilla.redhat.com/show_bug.cgi?id=2426409 https://www.cve.org/CVERecord?id=CVE-2025-15079 https://nvd.nist.gov/vuln/detail/CVE-2025-15079 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15079.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;71C1Nt6KoL1+Dpr0rTxWwA==&#34;: {&#xA;      &#34;id&#34;: &#34;71C1Nt6KoL1+Dpr0rTxWwA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-12151&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T16:05:38Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-12151 https://bugzilla.redhat.com/show_bug.cgi?id=2489980 https://www.cve.org/CVERecord?id=CVE-2026-12151 https://nvd.nist.gov/vuln/detail/CVE-2026-12151 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;75iSdAKFlPvTmCAp8d99YQ==&#34;: {&#xA;      &#34;id&#34;: &#34;75iSdAKFlPvTmCAp8d99YQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-44431&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in urllib3, an HTTP client library for Python. When using the low-level API via `ProxyManager.connection_from_url().urlopen()` with `assert_same_host=False`, cross-origin redirects can still forward sensitive headers. This could allow a remote attacker to gain unauthorized access to sensitive information.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-13T15:20:24Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-44431 https://bugzilla.redhat.com/show_bug.cgi?id=2477167 https://www.cve.org/CVERecord?id=CVE-2026-44431 https://nvd.nist.gov/vuln/detail/CVE-2026-44431 https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44431.json https://access.redhat.com/errata/RHSA-2026:28158&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-urllib3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.26.5-8.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;76eg4nI+WwZq6jvunMGVEQ==&#34;: {&#xA;      &#34;id&#34;: &#34;76eg4nI+WwZq6jvunMGVEQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6238&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T16:43:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-common&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;76mWuVYhbmIFsc4DNorK9A==&#34;: {&#xA;      &#34;id&#34;: &#34;76mWuVYhbmIFsc4DNorK9A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-5917&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability has been identified in the libarchive library. This flaw involves an &#39;off-by-one&#39; miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-20T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-5917 https://bugzilla.redhat.com/show_bug.cgi?id=2370874 https://www.cve.org/CVERecord?id=CVE-2025-5917 https://nvd.nist.gov/vuln/detail/CVE-2025-5917 https://github.com/libarchive/libarchive/pull/2588 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5917.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;76z9Mpn8Jp7lhZSPsHTHug==&#34;: {&#xA;      &#34;id&#34;: &#34;76z9Mpn8Jp7lhZSPsHTHug==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-68973&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GnuPG. An attacker can provide crafted input to the `armor_filter` function, which incorrectly increments an index variable, leading to an out-of-bounds write. This memory corruption vulnerability may allow for information disclosure and could potentially lead to arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-28T16:19:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-68973 https://bugzilla.redhat.com/show_bug.cgi?id=2425966 https://www.cve.org/CVERecord?id=CVE-2025-68973 https://nvd.nist.gov/vuln/detail/CVE-2025-68973 https://github.com/gpg/gnupg/blob/ff30683418695f5d2cc9e6cf8c9418e09378ebe4/g10/armor.c#L1305-L1306 https://github.com/gpg/gnupg/commit/115d138ba599328005c5321c0ef9f00355838ca9 https://gpg.fail/memcpy https://news.ycombinator.com/item?id=46403200 https://www.openwall.com/lists/oss-security/2025/12/28/5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68973.json https://access.redhat.com/errata/RHSA-2026:0719&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnupg2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.3.3-5.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;7AoZZiCMmvqX9d9WD62FnQ==&#34;: {&#xA;      &#34;id&#34;: &#34;7AoZZiCMmvqX9d9WD62FnQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-4781&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-09-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-4781 https://bugzilla.redhat.com/show_bug.cgi?id=2237575 https://www.cve.org/CVERecord?id=CVE-2023-4781 https://nvd.nist.gov/vuln/detail/CVE-2023-4781 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4781.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;7CfySs4FmTkWgJPjEar4eg==&#34;: {&#xA;      &#34;id&#34;: &#34;7CfySs4FmTkWgJPjEar4eg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-13595&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-13595 https://bugzilla.redhat.com/show_bug.cgi?id=2494101 https://www.cve.org/CVERecord?id=CVE-2026-13595 https://nvd.nist.gov/vuln/detail/CVE-2026-13595 https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13595.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;7KIsr/dNSaeE3wdgBYfrgQ==&#34;: {&#xA;      &#34;id&#34;: &#34;7KIsr/dNSaeE3wdgBYfrgQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-56392&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a heap-based buffer overflow, occurs due to an integer overflow when `unexpand` processes unusually large tab stop values provided by a local attacker. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries. Successful exploitation can cause the `unexpand` utility to crash, potentially resulting in a denial of service or enabling further memory manipulation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-24T07:44:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-56392 https://bugzilla.redhat.com/show_bug.cgi?id=2506694 https://www.cve.org/CVERecord?id=CVE-2026-56392 https://nvd.nist.gov/vuln/detail/CVE-2026-56392 https://cert.pl/en/posts/2026/07/CVE-2026-56391 https://git.savannah.gnu.org/cgit/coreutils.git/ https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56392.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;coreutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;7d4YdteAff532bV2Gg5lmw==&#34;: {&#xA;      &#34;id&#34;: &#34;7d4YdteAff532bV2Gg5lmw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22795&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a Denial of Service (DoS) by tricking a user or application into processing a maliciously crafted PKCS#12 (Personal Information Exchange Syntax Standard) file. The vulnerability leads to an invalid or NULL pointer dereference, resulting in an application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22795 https://bugzilla.redhat.com/show_bug.cgi?id=2430389 https://www.cve.org/CVERecord?id=CVE-2026-22795 https://nvd.nist.gov/vuln/detail/CVE-2026-22795 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22795.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;7sGexlbSpX41SOBbWHg8BQ==&#34;: {&#xA;      &#34;id&#34;: &#34;7sGexlbSpX41SOBbWHg8BQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-39881&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. A command injection vulnerability in Vim&#39;s NetBeans interface allows a malicious NetBeans server to execute arbitrary Ex commands when Vim connects to it. This occurs due to unsanitized strings in the defineAnnoType and specialKeys protocol messages, leading to arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-08T20:18:19Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-39881 https://bugzilla.redhat.com/show_bug.cgi?id=2456722 https://www.cve.org/CVERecord?id=CVE-2026-39881 https://nvd.nist.gov/vuln/detail/CVE-2026-39881 https://github.com/vim/vim/commit/7ab76a86048ed492374ac6b19 https://github.com/vim/vim/releases/tag/v9.2.0316 https://github.com/vim/vim/security/advisories/GHSA-mr87-rhgv-7pw6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39881.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;7tbcfIdYm3nwAiNQR5eK/Q==&#34;: {&#xA;      &#34;id&#34;: &#34;7tbcfIdYm3nwAiNQR5eK/Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15467&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker can exploit a stack buffer overflow vulnerability by supplying a crafted Cryptographic Message Syntax (CMS) message with an oversized Initialization Vector (IV) when parsing AuthEnvelopedData structures that use Authenticated Encryption with Associated Data (AEAD) ciphers such as AES-GCM. This can lead to a crash, causing a Denial of Service (DoS), or potentially allow for remote code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T14:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15467 https://bugzilla.redhat.com/show_bug.cgi?id=2430376 https://www.cve.org/CVERecord?id=CVE-2025-15467 https://nvd.nist.gov/vuln/detail/CVE-2025-15467 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;8563iLEht/ghMGItALTFUw==&#34;: {&#xA;      &#34;id&#34;: &#34;8563iLEht/ghMGItALTFUw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-28419&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open-source command-line text editor. This vulnerability, a heap-based buffer underflow, occurs when Vim processes a specially crafted Emacs-style tags file. If a malicious file with a delimiter at the start of a line is opened, Vim attempts to read memory outside its designated area. This could lead to the disclosure of sensitive information or cause the application to crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-27T22:02:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-28419 https://bugzilla.redhat.com/show_bug.cgi?id=2443482 https://www.cve.org/CVERecord?id=CVE-2026-28419 https://nvd.nist.gov/vuln/detail/CVE-2026-28419 https://github.com/vim/vim/commit/9b7dfa2948c9e1e5e32a5812 https://github.com/vim/vim/releases/tag/v9.2.0075 https://github.com/vim/vim/security/advisories/GHSA-xcc8-r6c5-hvwv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28419.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;8MfvwX+dRI6Qt2H+x71rZg==&#34;: {&#xA;      &#34;id&#34;: &#34;8MfvwX+dRI6Qt2H+x71rZg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15224&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcurl. When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15224 https://bugzilla.redhat.com/show_bug.cgi?id=2426410 https://www.cve.org/CVERecord?id=CVE-2025-15224 https://nvd.nist.gov/vuln/detail/CVE-2025-15224 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15224.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;8XLKalkulxeAh8qfecmGlA==&#34;: {&#xA;      &#34;id&#34;: &#34;8XLKalkulxeAh8qfecmGlA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66861&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted PE file with cxxfilt can trigger an out-of-bounds read in the d_unqualified_name function in the cp-demangle.c file, causing a crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66861 https://bugzilla.redhat.com/show_bug.cgi?id=2425823 https://www.cve.org/CVERecord?id=CVE-2025-66861 https://nvd.nist.gov/vuln/detail/CVE-2025-66861 https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66861.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;8ZCpE1M7eqNdy615aO2gLQ==&#34;: {&#xA;      &#34;id&#34;: &#34;8ZCpE1M7eqNdy615aO2gLQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0992&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated \u003cnextCatalog\u003e elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-15T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0992 https://bugzilla.redhat.com/show_bug.cgi?id=2429975 https://www.cve.org/CVERecord?id=CVE-2026-0992 https://nvd.nist.gov/vuln/detail/CVE-2026-0992 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0992.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;8efBqSZ3OYqd+nT8a21FNA==&#34;: {&#xA;      &#34;id&#34;: &#34;8efBqSZ3OYqd+nT8a21FNA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2287&#34;,&#xA;      &#34;description&#34;: &#34;Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-07-03T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2287 https://bugzilla.redhat.com/show_bug.cgi?id=2103876 https://www.cve.org/CVERecord?id=CVE-2022-2287 https://nvd.nist.gov/vuln/detail/CVE-2022-2287 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2287.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;8gSzZr+GPWdWrD28SEc1Pg==&#34;: {&#xA;      &#34;id&#34;: &#34;8gSzZr+GPWdWrD28SEc1Pg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5450&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:55:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-272.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;8hlo60BBnOd97TpyGOfaLA==&#34;: {&#xA;      &#34;id&#34;: &#34;8hlo60BBnOd97TpyGOfaLA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:37:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-common&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;8kndQj/aRn+NNJdGVP9v4g==&#34;: {&#xA;      &#34;id&#34;: &#34;8kndQj/aRn+NNJdGVP9v4g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-45322&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libxml2. In an out-of-memory condition or when limiting the memory allocation, processing a XML document using the HTML parser may result in a use-after-free vulnerability.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-08-23T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-45322 https://bugzilla.redhat.com/show_bug.cgi?id=2242945 https://www.cve.org/CVERecord?id=CVE-2023-45322 https://nvd.nist.gov/vuln/detail/CVE-2023-45322 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-45322.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;8zIRit7VqNRaBPLxL/+VAg==&#34;: {&#xA;      &#34;id&#34;: &#34;8zIRit7VqNRaBPLxL/+VAg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66471&#34;,&#xA;      &#34;description&#34;: &#34;A decompression handling flaw has been discovered in urllib3. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data; CWE-409) on the client side, even if the application only requested a small chunk of data.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T16:06:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66471 https://bugzilla.redhat.com/show_bug.cgi?id=2419467 https://www.cve.org/CVERecord?id=CVE-2025-66471 https://nvd.nist.gov/vuln/detail/CVE-2025-66471 https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7 https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66471.json https://access.redhat.com/errata/RHSA-2026:1087&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-urllib3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.26.5-6.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;922No9XwoInf4IDk2/SEuA==&#34;: {&#xA;      &#34;id&#34;: &#34;922No9XwoInf4IDk2/SEuA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9150&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv&#39;s Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-20T22:59:46Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9150 https://bugzilla.redhat.com/show_bug.cgi?id=2460379 https://www.cve.org/CVERecord?id=CVE-2026-9150 https://nvd.nist.gov/vuln/detail/CVE-2026-9150 https://github.com/openSUSE/libsolv/pull/616 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9150.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libsolv&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;93O9BjbBwz1jYmTNCzgkUw==&#34;: {&#xA;      &#34;id&#34;: &#34;93O9BjbBwz1jYmTNCzgkUw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2849&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-17T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2849 https://bugzilla.redhat.com/show_bug.cgi?id=2122137 https://www.cve.org/CVERecord?id=CVE-2022-2849 https://nvd.nist.gov/vuln/detail/CVE-2022-2849 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2849.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9ANhoIvfhYS2Fj0QOQtcOg==&#34;: {&#xA;      &#34;id&#34;: &#34;9ANhoIvfhYS2Fj0QOQtcOg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14512&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib&#39;s GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-11T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14512 https://bugzilla.redhat.com/show_bug.cgi?id=2421339 https://www.cve.org/CVERecord?id=CVE-2025-14512 https://nvd.nist.gov/vuln/detail/CVE-2025-14512 https://gitlab.gnome.org/GNOME/glib/-/issues/3845 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14512.json https://access.redhat.com/errata/RHSA-2026:15971&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-18.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9B4gl+qnaOhRLjmkdKMYbw==&#34;: {&#xA;      &#34;id&#34;: &#34;9B4gl+qnaOhRLjmkdKMYbw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9DXLRStQLAgyQnNJqYTJEA==&#34;: {&#xA;      &#34;id&#34;: &#34;9DXLRStQLAgyQnNJqYTJEA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6733&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici&#39;s HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:14:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6733 https://bugzilla.redhat.com/show_bug.cgi?id=2490006 https://www.cve.org/CVERecord?id=CVE-2026-6733 https://nvd.nist.gov/vuln/detail/CVE-2026-6733 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 https://hackerone.com/reports/3582376 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6733.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9GliauANgklOt4mKxwOygQ==&#34;: {&#xA;      &#34;id&#34;: &#34;9GliauANgklOt4mKxwOygQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rdoc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:6.6.3.1-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9K1bGbpJNlcAkIrOMal8Gw==&#34;: {&#xA;      &#34;id&#34;: &#34;9K1bGbpJNlcAkIrOMal8Gw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-31790&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-31790 https://bugzilla.redhat.com/show_bug.cgi?id=2451094 https://www.cve.org/CVERecord?id=CVE-2026-31790 https://nvd.nist.gov/vuln/detail/CVE-2026-31790 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31790.json https://access.redhat.com/errata/RHSA-2026:19218&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-2.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9PkDHwckTpMGddf70S7UIA==&#34;: {&#xA;      &#34;id&#34;: &#34;9PkDHwckTpMGddf70S7UIA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6238&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T16:43:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9VSflkDgRQsGPkKM4aVDHw==&#34;: {&#xA;      &#34;id&#34;: &#34;9VSflkDgRQsGPkKM4aVDHw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.22-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9iADtyaox0PEZ/SbvPWJcw==&#34;: {&#xA;      &#34;id&#34;: &#34;9iADtyaox0PEZ/SbvPWJcw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45409&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library&#39;s encoding function. This could cause the system to consume significant resources, leading to a Denial of Service (DoS), where the affected application becomes unavailable to legitimate users. This issue stems from an incomplete fix for a previously identified vulnerability.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-05T22:06:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45409 https://bugzilla.redhat.com/show_bug.cgi?id=2485616 https://www.cve.org/CVERecord?id=CVE-2026-45409 https://nvd.nist.gov/vuln/detail/CVE-2026-45409 https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45409.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-pip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9iigvnuYDaC8UzcOIDLjIQ==&#34;: {&#xA;      &#34;id&#34;: &#34;9iigvnuYDaC8UzcOIDLjIQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-24883&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GnuPG. A remote attacker could provide a specially crafted long signature packet that, when processed, causes the application to crash. This vulnerability leads to a denial of service (DoS), making the GnuPG application unavailable to legitimate users.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T18:43:18Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-24883 https://bugzilla.redhat.com/show_bug.cgi?id=2433463 https://www.cve.org/CVERecord?id=CVE-2026-24883 https://nvd.nist.gov/vuln/detail/CVE-2026-24883 https://dev.gnupg.org/T8049 https://www.openwall.com/lists/oss-security/2026/01/27/8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24883.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnupg2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9k9GsZftBlKIenK0IOSwoQ==&#34;: {&#xA;      &#34;id&#34;: &#34;9k9GsZftBlKIenK0IOSwoQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9uC93Z+i1x3p9QMz1A1vlA==&#34;: {&#xA;      &#34;id&#34;: &#34;9uC93Z+i1x3p9QMz1A1vlA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-16730&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-23T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-16730 https://bugzilla.redhat.com/show_bug.cgi?id=2506348 https://www.cve.org/CVERecord?id=CVE-2026-16730 https://nvd.nist.gov/vuln/detail/CVE-2026-16730 https://github.com/bus1/dbus-broker/issues/435 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16730.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;dbus-broker&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;9v8e/1gKgcwShm3I7m4SiQ==&#34;: {&#xA;      &#34;id&#34;: &#34;9v8e/1gKgcwShm3I7m4SiQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59874&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:23:47Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59874 https://bugzilla.redhat.com/show_bug.cgi?id=2498116 https://www.cve.org/CVERecord?id=CVE-2026-59874 https://nvd.nist.gov/vuln/detail/CVE-2026-59874 https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59874.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;A+Jv9uRM/keGEYgIGq4WhQ==&#34;: {&#xA;      &#34;id&#34;: &#34;A+Jv9uRM/keGEYgIGq4WhQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;A/L5cxR0pUN6sSD1UL7wlw==&#34;: {&#xA;      &#34;id&#34;: &#34;A/L5cxR0pUN6sSD1UL7wlw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-12084&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in cpython. This vulnerability allows impacted availability via a quadratic algorithm in `xml.dom.minidom` methods, such as `appendChild()`, when building excessively nested documents due to a dependency on `_clear_id_cache()`&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-03T18:55:32Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-12084 https://bugzilla.redhat.com/show_bug.cgi?id=2418655 https://www.cve.org/CVERecord?id=CVE-2025-12084 https://nvd.nist.gov/vuln/detail/CVE-2025-12084 https://github.com/python/cpython/issues/142145 https://github.com/python/cpython/pull/142146 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-12084.json https://access.redhat.com/errata/RHSA-2026:1478&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;A1ZQfTMMpQF7G100W1c/Rg==&#34;: {&#xA;      &#34;id&#34;: &#34;A1ZQfTMMpQF7G100W1c/Rg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48928 https://bugzilla.redhat.com/show_bug.cgi?id=2493333 https://www.cve.org/CVERecord?id=CVE-2026-48928 https://nvd.nist.gov/vuln/detail/CVE-2026-48928 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48928.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;A2s8gCjK3uaWI7+q7M5Aog==&#34;: {&#xA;      &#34;id&#34;: &#34;A2s8gCjK3uaWI7+q7M5Aog==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-2100&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-06T08:08:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-2100 https://bugzilla.redhat.com/show_bug.cgi?id=2437308 https://www.cve.org/CVERecord?id=CVE-2026-2100 https://nvd.nist.gov/vuln/detail/CVE-2026-2100 https://github.com/p11-glue/p11-kit/pull/740 https://github.com/p11-glue/p11-kit/releases/tag/0.26.2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2100.json https://access.redhat.com/errata/RHSA-2026:18599&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;p11-kit&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.26.2-1.el9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AF4l+pfrs0Si/0Bf3toHtA==&#34;: {&#xA;      &#34;id&#34;: &#34;AF4l+pfrs0Si/0Bf3toHtA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69419&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When processing a specially crafted PKCS#12 (Personal Information Exchange Syntax Standard) file, a remote attacker can exploit an out-of-bounds write vulnerability. This issue, occurring within the OPENSSL_uni2utf8() function, leads to memory corruption by writing data beyond its allocated buffer. Successful exploitation could result in a denial of service or potentially allow for arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69419 https://bugzilla.redhat.com/show_bug.cgi?id=2430386 https://www.cve.org/CVERecord?id=CVE-2025-69419 https://nvd.nist.gov/vuln/detail/CVE-2025-69419 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69419.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AGwkok3hPLMsQFqdif59+w==&#34;: {&#xA;      &#34;id&#34;: &#34;AGwkok3hPLMsQFqdif59+w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-7383&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-7383 https://bugzilla.redhat.com/show_bug.cgi?id=2481879 https://www.cve.org/CVERecord?id=CVE-2026-7383 https://nvd.nist.gov/vuln/detail/CVE-2026-7383 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7383.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AILk1bhdEUQriiNdRe9Buw==&#34;: {&#xA;      &#34;id&#34;: &#34;AILk1bhdEUQriiNdRe9Buw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-4598&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original&#39;s privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner&#39;s permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original&#39;s SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-4598 https://bugzilla.redhat.com/show_bug.cgi?id=2369242 https://www.cve.org/CVERecord?id=CVE-2025-4598 https://nvd.nist.gov/vuln/detail/CVE-2025-4598 https://www.openwall.com/lists/oss-security/2025/05/29/3 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4598.json https://access.redhat.com/errata/RHSA-2025:22660&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd-rpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-55.el9_7.7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AIlN8RmMOvhBveVuVAyHQQ==&#34;: {&#xA;      &#34;id&#34;: &#34;AIlN8RmMOvhBveVuVAyHQQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2874&#34;,&#xA;      &#34;description&#34;: &#34;A NULL pointer dereference vulnerability was found in Vim in the generate_loadvar function in the vim9compile.c file. This flaw allows an attacker who can trick a user into processing a specially crafted file to trigger the NULL pointer dereference, causing the application to crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2874 https://bugzilla.redhat.com/show_bug.cgi?id=2193207 https://www.cve.org/CVERecord?id=CVE-2022-2874 https://nvd.nist.gov/vuln/detail/CVE-2022-2874 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2874.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AKiLQ/xfYs8rccBZaw62bQ==&#34;: {&#xA;      &#34;id&#34;: &#34;AKiLQ/xfYs8rccBZaw62bQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-io-console&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.7.1-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ALEb7ClqbpU4flidf9/9Vg==&#34;: {&#xA;      &#34;id&#34;: &#34;ALEb7ClqbpU4flidf9/9Vg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bigdecimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.1.5-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AUiFITCnRjRxctzqqbDeeA==&#34;: {&#xA;      &#34;id&#34;: &#34;AUiFITCnRjRxctzqqbDeeA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3219&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in GnuPG. GnuPG can spin on a relatively small input by crafting a public key with thousands of signatures attached and compressed down to a few kilobytes. This issue can potentially cause a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-15T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3219 https://bugzilla.redhat.com/show_bug.cgi?id=2127010 https://www.cve.org/CVERecord?id=CVE-2022-3219 https://nvd.nist.gov/vuln/detail/CVE-2022-3219 https://dev.gnupg.org/D556 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3219.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnupg2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Ah03jmj/7fQOqUbg05PtZg==&#34;: {&#xA;      &#34;id&#34;: &#34;Ah03jmj/7fQOqUbg05PtZg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-0049&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim, which is vulnerable to an out-of-bounds read in the build_stl_str_hl function. This flaw allows a specially crafted file to cause information disclosure, data integrity corruption, or crash the software.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-01-04T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-0049 https://bugzilla.redhat.com/show_bug.cgi?id=2158269 https://www.cve.org/CVERecord?id=CVE-2023-0049 https://nvd.nist.gov/vuln/detail/CVE-2023-0049 https://huntr.dev/bounties/5e6f325c-ba54-4bf0-b050-dca048fd3fd9/ https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0049.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AvmIxq5EDqjW4mtnnlw9lA==&#34;: {&#xA;      &#34;id&#34;: &#34;AvmIxq5EDqjW4mtnnlw9lA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42012&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42012 https://bugzilla.redhat.com/show_bug.cgi?id=2467441 https://www.cve.org/CVERecord?id=CVE-2026-42012 https://nvd.nist.gov/vuln/detail/CVE-2026-42012 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-7 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42012.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AwUdH/KSEhHnx1nx0tagUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;AwUdH/KSEhHnx1nx0tagUQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2183&#34;,&#xA;      &#34;description&#34;: &#34;AV:L/AC:L/PR:N/UI:R/S:U/\nC:H   ==\u003e   C:N\nI:H   ==\u003e   I:N\nA:H   ==\u003e   A:L&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-23T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2183 https://bugzilla.redhat.com/show_bug.cgi?id=2102159 https://www.cve.org/CVERecord?id=CVE-2022-2183 https://nvd.nist.gov/vuln/detail/CVE-2022-2183 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2183.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AwiZctxQMpOexVhl+RZ/eQ==&#34;: {&#xA;      &#34;id&#34;: &#34;AwiZctxQMpOexVhl+RZ/eQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6100&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python&#39;s decompression modules, including `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile`. This vulnerability, a use-after-free, can occur if a program attempts to re-use a decompression object after a memory allocation error, especially when the system is experiencing high memory usage. Exploitation of this flaw could potentially allow an attacker to execute arbitrary code or access sensitive data. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-13T17:15:47Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6100 https://bugzilla.redhat.com/show_bug.cgi?id=2457932 https://www.cve.org/CVERecord?id=CVE-2026-6100 https://nvd.nist.gov/vuln/detail/CVE-2026-6100 https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2 https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20 https://github.com/python/cpython/issues/148395 https://github.com/python/cpython/pull/148396 https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json https://access.redhat.com/errata/RHSA-2026:19216&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AzESlP5N9z0ume0UnpGELg==&#34;: {&#xA;      &#34;id&#34;: &#34;AzESlP5N9z0ume0UnpGELg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41991&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the `gzexe` utility of GNU `gzip`. When the `mktemp` utility is not available, `gzexe` creates temporary files with predictable names based on the process ID. A local attacker can exploit this by pre-creating a symbolic link to an arbitrary file at the predicted temporary file path. This can lead to a Time-of-Check to Time-of-Use (TOCTOU) condition, allowing the attacker to overwrite arbitrary files on the system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-29T10:15:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41991 https://bugzilla.redhat.com/show_bug.cgi?id=2494158 https://www.cve.org/CVERecord?id=CVE-2026-41991 https://nvd.nist.gov/vuln/detail/CVE-2026-41991 https://cert.pl/en/posts/2026/04/CVE-2026-41991/ https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269 https://www.gnu.org/software/gzip/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41991.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gzip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;AzUHhCngmr5YuLLD/fQQEA==&#34;: {&#xA;      &#34;id&#34;: &#34;AzUHhCngmr5YuLLD/fQQEA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-13151&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libtasn1. A remote attacker could exploit a stack-based buffer overflow vulnerability in the `asn1_expend_octet_string` function. This occurs due to a failure in validating the size of input data. Successful exploitation can lead to a Denial of Service (DoS) condition, making the affected system or application unavailable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-07T21:14:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-13151 https://bugzilla.redhat.com/show_bug.cgi?id=2427698 https://www.cve.org/CVERecord?id=CVE-2025-13151 https://nvd.nist.gov/vuln/detail/CVE-2025-13151 https://gitlab.com/gnutls/libtasn1 https://gitlab.com/gnutls/libtasn1/-/merge_requests/121 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13151.json https://access.redhat.com/errata/RHSA-2026:28253&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtasn1&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:4.16.0-10.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;B+E5cjNC599y+nmprS3J2Q==&#34;: {&#xA;      &#34;id&#34;: &#34;B+E5cjNC599y+nmprS3J2Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15366&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the imaplib module in the Python standard library. The imaplib module does not reject control characters, such as newlines, in user-controlled input passed to IMAP commands. This issue allows an attacker to inject additional commands to be executed in the IMAP server.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:40:24Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15366 https://bugzilla.redhat.com/show_bug.cgi?id=2431368 https://www.cve.org/CVERecord?id=CVE-2025-15366 https://nvd.nist.gov/vuln/detail/CVE-2025-15366 https://github.com/python/cpython/issues/143921 https://github.com/python/cpython/pull/143922 https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15366.json https://access.redhat.com/errata/RHSA-2026:4168&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;B5DU5CG3Y0pIFFmMM3RU1A==&#34;: {&#xA;      &#34;id&#34;: &#34;B5DU5CG3Y0pIFFmMM3RU1A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42767&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. An attacker controlling a Certificate Management Protocol (CMP) server, or acting as a man-in-the-middle, could craft a malicious CMP response. This response, containing a Certificate Request Message Format (CRMF) CertRepMessage with a specific malformed EncryptedValue structure, would trigger a NULL pointer dereference in the OpenSSL CMP client. This vulnerability leads to a crash of the application, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42767 https://bugzilla.redhat.com/show_bug.cgi?id=2481891 https://www.cve.org/CVERecord?id=CVE-2026-42767 https://nvd.nist.gov/vuln/detail/CVE-2026-42767 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42767.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;BB1IXjQVr93It/qGF51Vqg==&#34;: {&#xA;      &#34;id&#34;: &#34;BB1IXjQVr93It/qGF51Vqg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21710&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request that includes a header named `__proto__`. When a Node.js application processes this request and attempts to access distinct headers, it encounters an unhandled error, leading to an application crash. This can result in a Denial of Service (DoS), making the affected service unavailable to users.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T19:07:28Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21710 https://bugzilla.redhat.com/show_bug.cgi?id=2453151 https://www.cve.org/CVERecord?id=CVE-2026-21710 https://nvd.nist.gov/vuln/detail/CVE-2026-21710 https://nodejs.org/en/blog/vulnerability/march-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21710.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;BBVHDYnqIwi0Vk9ZX1yGIw==&#34;: {&#xA;      &#34;id&#34;: &#34;BBVHDYnqIwi0Vk9ZX1yGIw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-23865&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Freetype. An integer overflow vulnerability exists when processing specially crafted OpenType variable fonts. A local attacker could exploit this by convincing a user to open a malicious font file, which may lead to an out-of-bounds read and potential information disclosure or denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-02T16:09:42Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-23865 https://bugzilla.redhat.com/show_bug.cgi?id=2443891 https://www.cve.org/CVERecord?id=CVE-2026-23865 https://nvd.nist.gov/vuln/detail/CVE-2026-23865 https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/ https://www.facebook.com/security/advisories/cve-2026-23865 https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixJAVA https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23865.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;freetype&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;BDC/Jijmwb4kfsAYqG7t2Q==&#34;: {&#xA;      &#34;id&#34;: &#34;BDC/Jijmwb4kfsAYqG7t2Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-64720&#34;,&#xA;      &#34;description&#34;: &#34;A buffer overflow flaw has been discovered in libpng. An out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled. The palette compositing code in png_init_read_transformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-24T23:45:38Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-64720 https://bugzilla.redhat.com/show_bug.cgi?id=2416904 https://www.cve.org/CVERecord?id=CVE-2025-64720 https://nvd.nist.gov/vuln/detail/CVE-2025-64720 https://github.com/pnggroup/libpng/commit/08da33b4c88cfcd36e5a706558a8d7e0e4773643 https://github.com/pnggroup/libpng/issues/686 https://github.com/pnggroup/libpng/pull/751 https://github.com/pnggroup/libpng/security/advisories/GHSA-hfc7-ph9c-wcww https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-64720.json https://access.redhat.com/errata/RHSA-2026:0238&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;BS5Qx6nN3HmM64VVoKmayw==&#34;: {&#xA;      &#34;id&#34;: &#34;BS5Qx6nN3HmM64VVoKmayw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3134&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free vulnerability was found in vim&#39;s do_tag() function of the src/tag.c file. The issue triggers when the &#39;tagfunc&#39; closes the window. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap use-after-free that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3134 https://bugzilla.redhat.com/show_bug.cgi?id=2126085 https://www.cve.org/CVERecord?id=CVE-2022-3134 https://nvd.nist.gov/vuln/detail/CVE-2022-3134 https://huntr.dev/bounties/6ec79e49-c7ab-4cd6-a517-e7934c2eb9dc https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3134.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;BTToHfvg0weSXCH9D0acFA==&#34;: {&#xA;      &#34;id&#34;: &#34;BTToHfvg0weSXCH9D0acFA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-28420&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. A remote attacker could exploit a heap-based buffer overflow and an out-of-bounds read vulnerability in Vim&#39;s terminal emulator. This occurs when processing specially crafted Unicode supplementary plane characters, potentially leading to information disclosure and denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-27T22:04:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-28420 https://bugzilla.redhat.com/show_bug.cgi?id=2443484 https://www.cve.org/CVERecord?id=CVE-2026-28420 https://nvd.nist.gov/vuln/detail/CVE-2026-28420 https://github.com/vim/vim/commit/bb6de2105b160e729c34063 https://github.com/vim/vim/releases/tag/v9.2.0076 https://github.com/vim/vim/security/advisories/GHSA-rvj2-jrf9-2phg https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28420.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;BXYBFOm74zXwzmdOdyNhzA==&#34;: {&#xA;      &#34;id&#34;: &#34;BXYBFOm74zXwzmdOdyNhzA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-7383&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-7383 https://bugzilla.redhat.com/show_bug.cgi?id=2481879 https://www.cve.org/CVERecord?id=CVE-2026-7383 https://nvd.nist.gov/vuln/detail/CVE-2026-7383 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7383.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;BaEDBo8YJd5pwSQNkGzAFg==&#34;: {&#xA;      &#34;id&#34;: &#34;BaEDBo8YJd5pwSQNkGzAFg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-56405&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. An integer overflow vulnerability exists within the `getAttributeId` function. This flaw could allow an attacker to potentially disclose sensitive information or execute arbitrary code, leading to a compromise of the system&#39;s integrity and confidentiality.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-21T15:47:13Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-56405 https://bugzilla.redhat.com/show_bug.cgi?id=2491188 https://www.cve.org/CVERecord?id=CVE-2026-56405 https://nvd.nist.gov/vuln/detail/CVE-2026-56405 https://github.com/libexpat/libexpat/pull/1251 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56405.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;BfDjqoaYrd0NKCGGxtokTg==&#34;: {&#xA;      &#34;id&#34;: &#34;BfDjqoaYrd0NKCGGxtokTg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-48231&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free flaw was found in the vim package. When executing a `:s` command for the first time and using a sub-replace-special atom inside the substitution, it is possible that the recursive `:s` call causes memory to be freed, which may later then be accessed by the initial `:s` command. This issue may result in Vim crashing.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-11-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-48231 https://bugzilla.redhat.com/show_bug.cgi?id=2250268 https://www.cve.org/CVERecord?id=CVE-2023-48231 https://nvd.nist.gov/vuln/detail/CVE-2023-48231 http://www.openwall.com/lists/oss-security/2023/11/16/1 https://github.com/vim/vim/commit/25aabc2b8ee1e19ced6f4da9d866cf9378fc4c5a https://github.com/vim/vim/security/advisories/GHSA-8g46-v9ff-c765 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-48231.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Bh96oSV9q0619slTJCaM0Q==&#34;: {&#xA;      &#34;id&#34;: &#34;Bh96oSV9q0619slTJCaM0Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-40403&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libxslt package. Processing web content may disclose sensitive information. This issue was addressed with improved memory handling.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-09-26T20:14:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-40403 https://bugzilla.redhat.com/show_bug.cgi?id=2349766 https://www.cve.org/CVERecord?id=CVE-2023-40403 https://nvd.nist.gov/vuln/detail/CVE-2023-40403 http://seclists.org/fulldisclosure/2023/Oct/10 http://seclists.org/fulldisclosure/2023/Oct/3 http://seclists.org/fulldisclosure/2023/Oct/4 http://seclists.org/fulldisclosure/2023/Oct/5 http://seclists.org/fulldisclosure/2023/Oct/6 http://seclists.org/fulldisclosure/2023/Oct/8 http://seclists.org/fulldisclosure/2023/Oct/9 https://bugs.chromium.org/p/chromium/issues/detail?id=1356211 https://bugzilla.gnome.org/show_bug.cgi?id=751621 https://gitlab.gnome.org/GNOME/libxslt/-/issues/94 https://support.apple.com/en-us/HT213927 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-40403.json https://access.redhat.com/errata/RHSA-2026:6266&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxslt-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.1.34-14.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Bl8VfXimE6raefu05cOS8w==&#34;: {&#xA;      &#34;id&#34;: &#34;Bl8VfXimE6raefu05cOS8w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48933&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48933 https://bugzilla.redhat.com/show_bug.cgi?id=2493331 https://www.cve.org/CVERecord?id=CVE-2026-48933 https://nvd.nist.gov/vuln/detail/CVE-2026-48933 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;BrupyHHgUisGe91mdtTkog==&#34;: {&#xA;      &#34;id&#34;: &#34;BrupyHHgUisGe91mdtTkog==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59871&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path processing. An attacker could exploit this to cause the application using node-tar to crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:25:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59871 https://bugzilla.redhat.com/show_bug.cgi?id=2498126 https://www.cve.org/CVERecord?id=CVE-2026-59871 https://nvd.nist.gov/vuln/detail/CVE-2026-59871 https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59871.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;BtU7U8JaAB8UA19RIrHuHQ==&#34;: {&#xA;      &#34;id&#34;: &#34;BtU7U8JaAB8UA19RIrHuHQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35387&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows the system to use unintended Elliptic Curve Digital Signature Algorithm (ECDSA) algorithms. This occurs because the configuration for accepted public key algorithms is misinterpreted, leading to the use of weaker cryptographic methods than intended. This could potentially allow an attacker to compromise the confidentiality of data.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:52:53Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35387 https://bugzilla.redhat.com/show_bug.cgi?id=2454494 https://www.cve.org/CVERecord?id=CVE-2026-35387 https://nvd.nist.gov/vuln/detail/CVE-2026-35387 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35387.json https://access.redhat.com/errata/RHSA-2026:19219&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Bu9dxnhmsLXDd3x0oRPHfA==&#34;: {&#xA;      &#34;id&#34;: &#34;Bu9dxnhmsLXDd3x0oRPHfA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11413&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted object file with the ld linker can trigger an out-of-bounds write in the bfd_putl64 function in the bfd/libbfd.c file due to an improper check, causing a crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-07T22:02:12Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11413 https://bugzilla.redhat.com/show_bug.cgi?id=2402423 https://www.cve.org/CVERecord?id=CVE-2025-11413 https://nvd.nist.gov/vuln/detail/CVE-2025-11413 https://sourceware.org/bugzilla/show_bug.cgi?id=33456 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=72efdf166aa0ed72ecc69fc2349af6591a7a19c0 https://vuldb.com/?id.327349 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11413.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;C5z0AxIvQN3JdMLvMYB+qg==&#34;: {&#xA;      &#34;id&#34;: &#34;C5z0AxIvQN3JdMLvMYB+qg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14087&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14087 https://bugzilla.redhat.com/show_bug.cgi?id=2419093 https://www.cve.org/CVERecord?id=CVE-2025-14087 https://nvd.nist.gov/vuln/detail/CVE-2025-14087 https://gitlab.gnome.org/GNOME/glib/-/issues/3834 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14087.json https://access.redhat.com/errata/RHSA-2026:15971&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-18.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;CKAla6xchD1gy0q9ML/2xg==&#34;: {&#xA;      &#34;id&#34;: &#34;CKAla6xchD1gy0q9ML/2xg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bundler&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.5.22-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;CO6FDlFyRSUjPhv7/gdAAA==&#34;: {&#xA;      &#34;id&#34;: &#34;CO6FDlFyRSUjPhv7/gdAAA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-default-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;CQNzMQJa1wEomWRr1m5WUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;CQNzMQJa1wEomWRr1m5WUQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34982&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. A modeline is used to set specific editor options directly from a text file. However, the `complete`, `guitabtooltip`, `printheader` options and the `mapset` function lack proper security checks, allowing an attacker to bypass restrictions and cause arbitrary OS command execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-06T15:16:48Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34982 https://bugzilla.redhat.com/show_bug.cgi?id=2455400 https://www.cve.org/CVERecord?id=CVE-2026-34982 https://nvd.nist.gov/vuln/detail/CVE-2026-34982 http://www.openwall.com/lists/oss-security/2026/04/01/1 https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615 https://github.com/vim/vim/releases/tag/v9.2.0276 https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.json https://access.redhat.com/errata/RHSA-2026:11510&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim-minimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:8.2.2637-23.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;CQPV/OxtJ+DwYc6C4gniNQ==&#34;: {&#xA;      &#34;id&#34;: &#34;CQPV/OxtJ+DwYc6C4gniNQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-47008&#34;,&#xA;      &#34;description&#34;: &#34;A memory leak was found in binutils in the make_tempdir and make_tempname functions. This flaw allows an attacker to use a set of steps to trigger a memory leak and perform a denial of service, resulting in a loss of the system&#39;s availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-47008 https://bugzilla.redhat.com/show_bug.cgi?id=2233984 https://www.cve.org/CVERecord?id=CVE-2022-47008 https://nvd.nist.gov/vuln/detail/CVE-2022-47008 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-47008.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;CfMK+8nnfjDlpiJ86nDqnQ==&#34;: {&#xA;      &#34;id&#34;: &#34;CfMK+8nnfjDlpiJ86nDqnQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48619&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. A malicious server can exploit the HTTP/2 client by sending an unlimited number of ORIGIN frames. This can lead to an Out of Memory error on the client, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48619 https://bugzilla.redhat.com/show_bug.cgi?id=2493325 https://www.cve.org/CVERecord?id=CVE-2026-48619 https://nvd.nist.gov/vuln/detail/CVE-2026-48619 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48619.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ChVC4WOnGJkEsPC5QHmS4Q==&#34;: {&#xA;      &#34;id&#34;: &#34;ChVC4WOnGJkEsPC5QHmS4Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-13757&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-23T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-13757 https://bugzilla.redhat.com/show_bug.cgi?id=2494556 https://www.cve.org/CVERecord?id=CVE-2026-13757 https://nvd.nist.gov/vuln/detail/CVE-2026-13757 https://github.com/advisories/GHSA-p2wm-69qx-x25w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13757.json https://access.redhat.com/errata/RHSA-2026:49667&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;p11-kit&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.26.4-1.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Cpn7PI6CgTg1FJ1Ijp4TIQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Cpn7PI6CgTg1FJ1Ijp4TIQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-8458&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcurl. A logical error in the connection pooling mechanism may cause libcurl to reuse an authenticated connection for an unintended service. This could allow an application to wrongfully reuse an existing connection to the same server that was authenticated for a different service, potentially leading to unauthorized access or information disclosure.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-03T06:14:42Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-8458 https://bugzilla.redhat.com/show_bug.cgi?id=2496764 https://www.cve.org/CVERecord?id=CVE-2026-8458 https://nvd.nist.gov/vuln/detail/CVE-2026-8458 https://curl.se/docs/CVE-2026-8458.html https://curl.se/docs/CVE-2026-8458.json https://hackerone.com/reports/3721183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8458.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;D/8pir/aXD8E2iIv4dA/Pg==&#34;: {&#xA;      &#34;id&#34;: &#34;D/8pir/aXD8E2iIv4dA/Pg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-56131&#34;,&#xA;      &#34;description&#34;: &#34;A use-after-free vulnerability in libexpat occurs because handler call depth isn&#39;t properly tracked when XML_ResumeParser is invoked during policy violations. This flaw can lead to information disclosure, data corruption, or denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-19T02:56:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-56131 https://bugzilla.redhat.com/show_bug.cgi?id=2490668 https://www.cve.org/CVERecord?id=CVE-2026-56131 https://nvd.nist.gov/vuln/detail/CVE-2026-56131 https://github.com/libexpat/libexpat/pull/1267 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56131.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;D17rv5OxhiqZrK+otc1Xcg==&#34;: {&#xA;      &#34;id&#34;: &#34;D17rv5OxhiqZrK+otc1Xcg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35386&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows a remote attacker to achieve arbitrary command execution by injecting shell metacharacters into a username provided on the command line. Exploitation requires an untrusted username and a non-default configuration of the &#39;%&#39; character in `ssh_config`.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:44:27Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35386 https://bugzilla.redhat.com/show_bug.cgi?id=2454506 https://www.cve.org/CVERecord?id=CVE-2026-35386 https://nvd.nist.gov/vuln/detail/CVE-2026-35386 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35386.json https://access.redhat.com/errata/RHSA-2026:13381&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-49.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;D4G1BWjcvupPxJokCdnHGA==&#34;: {&#xA;      &#34;id&#34;: &#34;D4G1BWjcvupPxJokCdnHGA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9076&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9076 https://bugzilla.redhat.com/show_bug.cgi?id=2481880 https://www.cve.org/CVERecord?id=CVE-2026-9076 https://nvd.nist.gov/vuln/detail/CVE-2026-9076 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9076.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;D7U85Qc3CYAscEzhSfT76A==&#34;: {&#xA;      &#34;id&#34;: &#34;D7U85Qc3CYAscEzhSfT76A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15467&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker can exploit a stack buffer overflow vulnerability by supplying a crafted Cryptographic Message Syntax (CMS) message with an oversized Initialization Vector (IV) when parsing AuthEnvelopedData structures that use Authenticated Encryption with Associated Data (AEAD) ciphers such as AES-GCM. This can lead to a crash, causing a Denial of Service (DoS), or potentially allow for remote code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T14:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15467 https://bugzilla.redhat.com/show_bug.cgi?id=2430376 https://www.cve.org/CVERecord?id=CVE-2025-15467 https://nvd.nist.gov/vuln/detail/CVE-2025-15467 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DAEgBJ6jpEvrKn3TAPAfVQ==&#34;: {&#xA;      &#34;id&#34;: &#34;DAEgBJ6jpEvrKn3TAPAfVQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42770&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A malicious peer can exploit this vulnerability by presenting a specially crafted DHX (X9.42) peer key. Due to improper validation of the peer key&#39;s subgroup membership, an attacker can recover the victim&#39;s private key after a small number of key exchange attempts. This information disclosure can lead to unauthorized access or further compromise of affected systems.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42770 https://bugzilla.redhat.com/show_bug.cgi?id=2481894 https://www.cve.org/CVERecord?id=CVE-2026-42770 https://nvd.nist.gov/vuln/detail/CVE-2026-42770 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42770.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DDxCHnX+kCqcRQj9b90/cg==&#34;: {&#xA;      &#34;id&#34;: &#34;DDxCHnX+kCqcRQj9b90/cg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-4156&#34;,&#xA;      &#34;description&#34;: &#34;A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-06-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-4156 https://bugzilla.redhat.com/show_bug.cgi?id=2215930 https://www.cve.org/CVERecord?id=CVE-2023-4156 https://nvd.nist.gov/vuln/detail/CVE-2023-4156 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4156.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gawk&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DNT7Ncyac0R7hltidKFOsA==&#34;: {&#xA;      &#34;id&#34;: &#34;DNT7Ncyac0R7hltidKFOsA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-65018&#34;,&#xA;      &#34;description&#34;: &#34;A buffer overflow flaw has been discovered in libpng. There is a heap buffer overflow vulnerability in the libpng simplified API function png_image_finish_read when processing 16-bit interlaced PNGs with 8-bit output format. Attacker-crafted interlaced PNG files cause heap writes beyond allocated buffer bounds.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-24T23:50:18Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-65018 https://bugzilla.redhat.com/show_bug.cgi?id=2416907 https://www.cve.org/CVERecord?id=CVE-2025-65018 https://nvd.nist.gov/vuln/detail/CVE-2025-65018 https://github.com/pnggroup/libpng/commit/16b5e3823918840aae65c0a6da57c78a5a496a4d https://github.com/pnggroup/libpng/commit/218612ddd6b17944e21eda56caf8b4bf7779d1ea https://github.com/pnggroup/libpng/issues/755 https://github.com/pnggroup/libpng/pull/757 https://github.com/pnggroup/libpng/security/advisories/GHSA-7wv6-48j4-hj3g https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-65018.json https://access.redhat.com/errata/RHSA-2026:0238&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DNd0sdbW83acQbIl3FDaPw==&#34;: {&#xA;      &#34;id&#34;: &#34;DNd0sdbW83acQbIl3FDaPw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-0054&#34;,&#xA;      &#34;description&#34;: &#34;An out-of-bounds write flaw was found in Vim, in the do_string_sub function in the eval.c file. The issue occurs because of an invalid memory access due to a missing check of the return value of the vim_regsub function when a specially crafted input is processed. This flaw allows an attacker who can trick a user into opening a specially crafted file to trigger the out-of-bounds write, causing the application to crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-01-03T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-0054 https://bugzilla.redhat.com/show_bug.cgi?id=2161349 https://www.cve.org/CVERecord?id=CVE-2023-0054 https://nvd.nist.gov/vuln/detail/CVE-2023-0054 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0054.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DSX8U+5pHixx0pf+XijnCw==&#34;: {&#xA;      &#34;id&#34;: &#34;DSX8U+5pHixx0pf+XijnCw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5435&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T11:58:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DTApvRZh1HJD5XbbpU3ahw==&#34;: {&#xA;      &#34;id&#34;: &#34;DTApvRZh1HJD5XbbpU3ahw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1757&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1757 https://bugzilla.redhat.com/show_bug.cgi?id=2435940 https://www.cve.org/CVERecord?id=CVE-2026-1757 https://nvd.nist.gov/vuln/detail/CVE-2026-1757 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1757.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DVhbZtpHlSM2ukk3QurV1w==&#34;: {&#xA;      &#34;id&#34;: &#34;DVhbZtpHlSM2ukk3QurV1w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-psych&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:5.1.2-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DW2DUdu8ljrldYoM7Mprtg==&#34;: {&#xA;      &#34;id&#34;: &#34;DW2DUdu8ljrldYoM7Mprtg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42769&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Certificate Management Protocol (CMP) implementation within OpenSSL. An attacker with existing Registration Authority (RA) level credentials could exploit an error in the certificate verification process during a Root Certificate Authority (CA) key update. This vulnerability allows the attacker to replace the root CA certificate for CMP clients with a fraudulent one. The primary consequence is an escalation of privileges, enabling the attacker to gain control equivalent to the root CA.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42769 https://bugzilla.redhat.com/show_bug.cgi?id=2481893 https://www.cve.org/CVERecord?id=CVE-2026-42769 https://nvd.nist.gov/vuln/detail/CVE-2026-42769 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42769.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DXoWfwXPN9ZCvCU/obObKQ==&#34;: {&#xA;      &#34;id&#34;: &#34;DXoWfwXPN9ZCvCU/obObKQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4878&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4878 https://bugzilla.redhat.com/show_bug.cgi?id=2451615 https://www.cve.org/CVERecord?id=CVE-2026-4878 https://nvd.nist.gov/vuln/detail/CVE-2026-4878 https://bugzilla.redhat.com/show_bug.cgi?id=2447554 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4878.json https://access.redhat.com/errata/RHSA-2026:12441&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libcap&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.48-10.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DcyOxGZU+Qt6lxShaMXeig==&#34;: {&#xA;      &#34;id&#34;: &#34;DcyOxGZU+Qt6lxShaMXeig==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-43617&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in rsync. When an rsync daemon is configured with \&#34;daemon chroot = /X\&#34; and uses hostname-based access control lists (ACLs), and the chrooted directory /X lacks necessary DNS resolution files, a remote attacker can bypass hostname-based deny rules. This occurs because the daemon performs reverse-DNS lookups after chrooting, causing the lookup to fail and the connecting hostname to be identified as \&#34;UNKNOWN\&#34;. An attacker can exploit this by controlling their pointer (PTR) record, enabling unauthorized connections from hostnames that should have been denied.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-20T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-43617 https://bugzilla.redhat.com/show_bug.cgi?id=2469060 https://www.cve.org/CVERecord?id=CVE-2026-43617 https://nvd.nist.gov/vuln/detail/CVE-2026-43617 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43617.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Di0hwt0owko/VaT8i7ICOw==&#34;: {&#xA;      &#34;id&#34;: &#34;Di0hwt0owko/VaT8i7ICOw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45409&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library&#39;s encoding function. This could cause the system to consume significant resources, leading to a Denial of Service (DoS), where the affected application becomes unavailable to legitimate users. This issue stems from an incomplete fix for a previously identified vulnerability.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-05T22:06:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45409 https://bugzilla.redhat.com/show_bug.cgi?id=2485616 https://www.cve.org/CVERecord?id=CVE-2026-45409 https://nvd.nist.gov/vuln/detail/CVE-2026-45409 https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45409.json https://access.redhat.com/errata/RHSA-2026:54484&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-idna&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.10-8.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Dif/+rLLCWjJt5Bzau2zsA==&#34;: {&#xA;      &#34;id&#34;: &#34;Dif/+rLLCWjJt5Bzau2zsA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4519&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python. The `webbrowser.open()` API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T15:08:32Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4519 https://bugzilla.redhat.com/show_bug.cgi?id=2449649 https://www.cve.org/CVERecord?id=CVE-2026-4519 https://nvd.nist.gov/vuln/detail/CVE-2026-4519 https://github.com/python/cpython/issues/143930 https://github.com/python/cpython/pull/143931 https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4519.json https://access.redhat.com/errata/RHSA-2026:19216&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DjqCxCryg8LYvAZ67mAiSQ==&#34;: {&#xA;      &#34;id&#34;: &#34;DjqCxCryg8LYvAZ67mAiSQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-29111&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-23T21:03:56Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-29111 https://bugzilla.redhat.com/show_bug.cgi?id=2450505 https://www.cve.org/CVERecord?id=CVE-2026-29111 https://nvd.nist.gov/vuln/detail/CVE-2026-29111 https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6 https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8 https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29111.json https://access.redhat.com/errata/RHSA-2026:13677&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd-pam&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-55.el9_7.9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Dl7D7r3bnERvJ1K3e9T3bQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Dl7D7r3bnERvJ1K3e9T3bQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rake&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:13.1.0-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DrIVK8+yvV91OzF2CS9o5A==&#34;: {&#xA;      &#34;id&#34;: &#34;DrIVK8+yvV91OzF2CS9o5A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-4598&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original&#39;s privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner&#39;s permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original&#39;s SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-4598 https://bugzilla.redhat.com/show_bug.cgi?id=2369242 https://www.cve.org/CVERecord?id=CVE-2025-4598 https://nvd.nist.gov/vuln/detail/CVE-2025-4598 https://www.openwall.com/lists/oss-security/2025/05/29/3 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4598.json https://access.redhat.com/errata/RHSA-2025:22660&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-55.el9_7.7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Ds5dBDqvRggZONNskvuAwg==&#34;: {&#xA;      &#34;id&#34;: &#34;Ds5dBDqvRggZONNskvuAwg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6019&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python&#39;s `http.cookies` module. The `Morsel.js_output()` function, responsible for generating JavaScript output for cookies, does not properly neutralize the `\u003c/script\u003e` HTML sequence. This oversight could allow a remote attacker to inject malicious script into a web page, potentially leading to Cross-Site Scripting (XSS) attacks. Such an attack could result in information disclosure or arbitrary code execution within the user&#39;s browser.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-22T19:28:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6019 https://bugzilla.redhat.com/show_bug.cgi?id=2460869 https://www.cve.org/CVERecord?id=CVE-2026-6019 https://nvd.nist.gov/vuln/detail/CVE-2026-6019 https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104 https://github.com/python/cpython/issues/90309 https://github.com/python/cpython/pull/148848 https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6019.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DsZp+BRVz/OTV0jFXHylmA==&#34;: {&#xA;      &#34;id&#34;: &#34;DsZp+BRVz/OTV0jFXHylmA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-28390&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T22:00:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-28390 https://bugzilla.redhat.com/show_bug.cgi?id=2456314 https://www.cve.org/CVERecord?id=CVE-2026-28390 https://nvd.nist.gov/vuln/detail/CVE-2026-28390 https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6 https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4 https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788 https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28390.json https://access.redhat.com/errata/RHSA-2026:22312&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-3.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DtkRUkQTzcJrj8ZsC36kqQ==&#34;: {&#xA;      &#34;id&#34;: &#34;DtkRUkQTzcJrj8ZsC36kqQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-50181&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration to manipulate request flows and disrupt service. This bypass occurs through improper handling of retry parameters during PoolManager instantiation. This issue can reult in a denial of service or unintended data exposure due to altered request destinations.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-06-19T01:08:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-50181 https://bugzilla.redhat.com/show_bug.cgi?id=2373799 https://www.cve.org/CVERecord?id=CVE-2025-50181 https://nvd.nist.gov/vuln/detail/CVE-2025-50181 https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857 https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-50181.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-pip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;DwTrtZS+niTc7qfIVCIZAQ==&#34;: {&#xA;      &#34;id&#34;: &#34;DwTrtZS+niTc7qfIVCIZAQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-59466&#34;,&#xA;      &#34;description&#34;: &#34;A stack overflow flaw has been discovered in Node.js error handling where \&#34;Maximum call stack size exceeded\&#34; errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on(&#39;uncaughtException&#39;)`, the process terminates, making the crash unrecoverable. Applications that rely on `AsyncLocalStorage` (v22, v20) or `async_hooks.createHook()` (v24, v22, v20) become vulnerable to denial-of-service crashes triggered by deep recursion under specific conditions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-59466 https://bugzilla.redhat.com/show_bug.cgi?id=2431343 https://www.cve.org/CVERecord?id=CVE-2025-59466 https://nvd.nist.gov/vuln/detail/CVE-2025-59466 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59466.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;E69qsmSRl4PzNiueJkPUDw==&#34;: {&#xA;      &#34;id&#34;: &#34;E69qsmSRl4PzNiueJkPUDw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55130&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55130 https://bugzilla.redhat.com/show_bug.cgi?id=2431352 https://www.cve.org/CVERecord?id=CVE-2025-55130 https://nvd.nist.gov/vuln/detail/CVE-2025-55130 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55130.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;E9ztZ/MyJW/b90Qruzzb/A==&#34;: {&#xA;      &#34;id&#34;: &#34;E9ztZ/MyJW/b90Qruzzb/A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59875&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a library for manipulating tar archives in Node.js. A remote attacker could craft a malicious archive containing null characters (NUL bytes) in its metadata. When this archive is processed, the unstripped null characters can cause the application to terminate unexpectedly, leading to a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:20:29Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59875 https://bugzilla.redhat.com/show_bug.cgi?id=2498115 https://www.cve.org/CVERecord?id=CVE-2026-59875 https://nvd.nist.gov/vuln/detail/CVE-2026-59875 https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3 https://github.com/isaacs/node-tar/releases/tag/v7.5.17 https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59875.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;EFXoHkta9v8NXWXURLTCBw==&#34;: {&#xA;      &#34;id&#34;: &#34;EFXoHkta9v8NXWXURLTCBw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-2297&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in CPython. This vulnerability allows a local user with low privileges to bypass security auditing mechanisms. The issue occurs because the SourcelessFileLoader component, responsible for handling older Python compiled files (.pyc), does not properly trigger system audit events. This oversight could enable malicious activities to go undetected, compromising the integrity of the system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-04T22:10:43Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-2297 https://bugzilla.redhat.com/show_bug.cgi?id=2444691 https://www.cve.org/CVERecord?id=CVE-2026-2297 https://nvd.nist.gov/vuln/detail/CVE-2026-2297 https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86 https://github.com/python/cpython/issues/145506 https://github.com/python/cpython/pull/145507 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2297.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;EGiW9TUcKA6dU0wY//GJ7w==&#34;: {&#xA;      &#34;id&#34;: &#34;EGiW9TUcKA6dU0wY//GJ7w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-68160&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This vulnerability involves an out-of-bounds write in the line-buffering BIO filter, which can lead to memory corruption. While exploitation is unlikely to be under direct attacker control, a successful attack could cause an application to crash, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-68160 https://bugzilla.redhat.com/show_bug.cgi?id=2430380 https://www.cve.org/CVERecord?id=CVE-2025-68160 https://nvd.nist.gov/vuln/detail/CVE-2025-68160 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68160.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;EJqYggmJ1CPHdE/+zAY7WA==&#34;: {&#xA;      &#34;id&#34;: &#34;EJqYggmJ1CPHdE/+zAY7WA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33846&#34;,&#xA;      &#34;description&#34;: &#34;A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-04T08:53:59Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33846 https://bugzilla.redhat.com/show_bug.cgi?id=2450625 https://www.cve.org/CVERecord?id=CVE-2026-33846 https://nvd.nist.gov/vuln/detail/CVE-2026-33846 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33846.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ENmG+VyULoyY7sa0jIk/uw==&#34;: {&#xA;      &#34;id&#34;: &#34;ENmG+VyULoyY7sa0jIk/uw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-2229&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the undici WebSocket client. A remote malicious server can exploit this vulnerability by sending a WebSocket frame with an invalid `server_max_window_bits` parameter within the permessage-deflate extension. This improper validation causes the client&#39;s Node.js process to terminate, leading to a denial-of-service (DoS) condition for the client.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:27:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-2229 https://bugzilla.redhat.com/show_bug.cgi?id=2447143 https://www.cve.org/CVERecord?id=CVE-2026-2229 https://nvd.nist.gov/vuln/detail/CVE-2026-2229 https://cna.openjsf.org/security-advisories.html https://datatracker.ietf.org/doc/html/rfc7692 https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8 https://hackerone.com/reports/3487486 https://nodejs.org/api/zlib.html#class-zlibinflateraw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2229.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;EOFhzMVjLzNyQsRKP/y6ag==&#34;: {&#xA;      &#34;id&#34;: &#34;EOFhzMVjLzNyQsRKP/y6ag==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59998&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. The sshd component has an undocumented security-relevant behavior where GSSAPIStrictAcceptorCheck has no value when the server is in a Windows Active Directory environment. This could lead to unintended information disclosure and impact data integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T00:11:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59998 https://bugzilla.redhat.com/show_bug.cgi?id=2497935 https://www.cve.org/CVERecord?id=CVE-2026-59998 https://nvd.nist.gov/vuln/detail/CVE-2026-59998 https://marc.info/?l=openssh-unix-dev\u0026m=178333966933090\u0026w=2 https://www.openssh.org/releasenotes.html#10.4p1 https://www.openwall.com/lists/oss-security/2026/07/06/5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59998.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;EOZFP6ki76xUja7Br+mpEw==&#34;: {&#xA;      &#34;id&#34;: &#34;EOZFP6ki76xUja7Br+mpEw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9678&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Undici. The cache interceptor in shared-cache mode incorrectly classifies certain responses as cacheable due to improper handling of whitespace-padded Cache-Control header field names. This vulnerability allows an unauthenticated attacker to access authenticated user data from the cache, leading to information disclosure. This occurs when both authenticated and unauthenticated requests resolve to the same cache key.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:04:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9678 https://bugzilla.redhat.com/show_bug.cgi?id=2490000 https://www.cve.org/CVERecord?id=CVE-2026-9678 https://nvd.nist.gov/vuln/detail/CVE-2026-9678 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9678.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;EUdYVqG8WVFrguzTJcoB9w==&#34;: {&#xA;      &#34;id&#34;: &#34;EUdYVqG8WVFrguzTJcoB9w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6238&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T16:43:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-minimal-langpack&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Eh3WlvVSpgyvj1kaA5So7g==&#34;: {&#xA;      &#34;id&#34;: &#34;Eh3WlvVSpgyvj1kaA5So7g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-13601&#34;,&#xA;      &#34;description&#34;: &#34;A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-24T13:00:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-13601 https://bugzilla.redhat.com/show_bug.cgi?id=2416741 https://www.cve.org/CVERecord?id=CVE-2025-13601 https://nvd.nist.gov/vuln/detail/CVE-2025-13601 https://gitlab.gnome.org/GNOME/glib/-/issues/3827 https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4914 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13601.json https://access.redhat.com/errata/RHSA-2026:0936&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-18.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ElE6r7xQZAfd5MScs95BXQ==&#34;: {&#xA;      &#34;id&#34;: &#34;ElE6r7xQZAfd5MScs95BXQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-3198&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GNU Binutils. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-04-04T01:31:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-3198 https://bugzilla.redhat.com/show_bug.cgi?id=2357358 https://www.cve.org/CVERecord?id=CVE-2025-3198 https://nvd.nist.gov/vuln/detail/CVE-2025-3198 https://sourceware.org/bugzilla/show_bug.cgi?id=32716 https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d https://vuldb.com/?ctiid.303151 https://vuldb.com/?id.303151 https://vuldb.com/?submit.545773 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-3198.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;EmYlXCkWzU0dM5AZphsDzw==&#34;: {&#xA;      &#34;id&#34;: &#34;EmYlXCkWzU0dM5AZphsDzw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42768&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL&#39;s CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim&#39;s private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application&#39;s error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42768 https://bugzilla.redhat.com/show_bug.cgi?id=2481892 https://www.cve.org/CVERecord?id=CVE-2026-42768 https://nvd.nist.gov/vuln/detail/CVE-2026-42768 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42768.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Ep1W9j+OJARAHSERuL7J7Q==&#34;: {&#xA;      &#34;id&#34;: &#34;Ep1W9j+OJARAHSERuL7J7Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34182&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL&#39;s Cryptographic Message Services (CMS) AuthEnvelopedData processing. An on-path attacker can exploit insufficient input validation on cipher and tag length fields by sending specially crafted CMS messages. This can lead to the forging of messages or bypassing integrity validation. Consequently, an attacker may achieve key-equivalent functionality for a given CMS recipient.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34182 https://bugzilla.redhat.com/show_bug.cgi?id=2481884 https://www.cve.org/CVERecord?id=CVE-2026-34182 https://nvd.nist.gov/vuln/detail/CVE-2026-34182 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34182.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ExqOQ5ldBNUvCH4EdaOK5w==&#34;: {&#xA;      &#34;id&#34;: &#34;ExqOQ5ldBNUvCH4EdaOK5w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-6170&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-06-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-6170 https://bugzilla.redhat.com/show_bug.cgi?id=2372952 https://www.cve.org/CVERecord?id=CVE-2025-6170 https://nvd.nist.gov/vuln/detail/CVE-2025-6170 https://gitlab.gnome.org/GNOME/libxml2/-/issues/941 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6170.json https://access.redhat.com/errata/RHSA-2026:39317&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.9.13-14.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Ez8lHT2uV9Tf9vJC/T4WXg==&#34;: {&#xA;      &#34;id&#34;: &#34;Ez8lHT2uV9Tf9vJC/T4WXg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4426&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4426 https://bugzilla.redhat.com/show_bug.cgi?id=2449010 https://www.cve.org/CVERecord?id=CVE-2026-4426 https://nvd.nist.gov/vuln/detail/CVE-2026-4426 https://github.com/libarchive/libarchive/pull/2897 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4426.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;F2zbkAiOFT3iZ5Dx0+MHfA==&#34;: {&#xA;      &#34;id&#34;: &#34;F2zbkAiOFT3iZ5Dx0+MHfA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-25547&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the brace-expansion component. This denial of service (DoS) vulnerability allows a remote attacker to provide specially crafted input containing repeated numeric brace ranges. This input causes the library to attempt an unbounded expansion, consuming excessive CPU and memory resources. This can lead to a system crash, impacting the availability of the service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-04T21:51:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-25547 https://bugzilla.redhat.com/show_bug.cgi?id=2436942 https://www.cve.org/CVERecord?id=CVE-2026-25547 https://nvd.nist.gov/vuln/detail/CVE-2026-25547 https://github.com/isaacs/brace-expansion/security/advisories/GHSA-7h2j-956f-4vf2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25547.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;F8lGQFeTGfg63gSPRvjBBA==&#34;: {&#xA;      &#34;id&#34;: &#34;F8lGQFeTGfg63gSPRvjBBA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48935&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. The Permission API allows a local user to modify file metadata on paths that have been explicitly set as read-only. This can lead to unauthorized changes in file properties, impacting the integrity of the file system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48935 https://bugzilla.redhat.com/show_bug.cgi?id=2493329 https://www.cve.org/CVERecord?id=CVE-2026-48935 https://nvd.nist.gov/vuln/detail/CVE-2026-48935 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48935.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;FAhn0w8CyRA5pQLzx0KOLg==&#34;: {&#xA;      &#34;id&#34;: &#34;FAhn0w8CyRA5pQLzx0KOLg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;FFVNPAck6QPQFhxf4KhO3g==&#34;: {&#xA;      &#34;id&#34;: &#34;FFVNPAck6QPQFhxf4KhO3g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;FInGJTEa3gToUzpaoDNNQw==&#34;: {&#xA;      &#34;id&#34;: &#34;FInGJTEa3gToUzpaoDNNQw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35388&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows for a low integrity impact due to the omission of connection multiplexing confirmation for proxy-mode multiplexing sessions. A local user, under specific and complex conditions requiring user interaction, could potentially establish a multiplexed session without explicit confirmation, leading to unintended data handling.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:57:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35388 https://bugzilla.redhat.com/show_bug.cgi?id=2454500 https://www.cve.org/CVERecord?id=CVE-2026-35388 https://nvd.nist.gov/vuln/detail/CVE-2026-35388 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35388.json https://access.redhat.com/errata/RHSA-2026:13381&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-49.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;FMWVyBjC/IhzfdU57RFV5A==&#34;: {&#xA;      &#34;id&#34;: &#34;FMWVyBjC/IhzfdU57RFV5A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.22-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;FQwXyPZ+oHyxQZ9RBQXbpw==&#34;: {&#xA;      &#34;id&#34;: &#34;FQwXyPZ+oHyxQZ9RBQXbpw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-13034&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. When configured to use public key pinning with QUIC connections and GnuTLS, and with standard certificate verification explicitly disabled, curl could bypass the intended public key check. This oversight allows a malicious server to impersonate a legitimate one, potentially leading to unauthorized access or information disclosure due to a failure in verifying the server&#39;s identity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-13034 https://bugzilla.redhat.com/show_bug.cgi?id=2426406 https://www.cve.org/CVERecord?id=CVE-2025-13034 https://nvd.nist.gov/vuln/detail/CVE-2025-13034 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13034.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;FW+E40XkknH5Jv24oip5Ow==&#34;: {&#xA;      &#34;id&#34;: &#34;FW+E40XkknH5Jv24oip5Ow==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4360&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Python `Tarfile.extract()` function. This vulnerability occurs when processing untrusted tar files containing hardlinks, as the `filter` parameter is not correctly enforced. An attacker could exploit this to write files with unintended user or group ownership, potentially leading to unauthorized modifications or privilege issues on the system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-30T14:45:35Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4360 https://bugzilla.redhat.com/show_bug.cgi?id=2494987 https://www.cve.org/CVERecord?id=CVE-2026-4360 https://nvd.nist.gov/vuln/detail/CVE-2026-4360 https://github.com/python/cpython/issues/151987 https://github.com/python/cpython/pull/151988 https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4360.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;FeNPPUXNvPHMFZ28E13Mog==&#34;: {&#xA;      &#34;id&#34;: &#34;FeNPPUXNvPHMFZ28E13Mog==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48934&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48934 https://bugzilla.redhat.com/show_bug.cgi?id=2493332 https://www.cve.org/CVERecord?id=CVE-2026-48934 https://nvd.nist.gov/vuln/detail/CVE-2026-48934 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48934.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;FroZeKbNhNx69+bj8o0OqQ==&#34;: {&#xA;      &#34;id&#34;: &#34;FroZeKbNhNx69+bj8o0OqQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11082&#34;,&#xA;      &#34;description&#34;: &#34;A head based buffer overflow flaw has been discovered in GNU bin utilities. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-27T22:32:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11082 https://bugzilla.redhat.com/show_bug.cgi?id=2399943 https://www.cve.org/CVERecord?id=CVE-2025-11082 https://nvd.nist.gov/vuln/detail/CVE-2025-11082 https://sourceware.org/bugzilla/attachment.cgi?id=16358 https://sourceware.org/bugzilla/show_bug.cgi?id=33464 https://sourceware.org/bugzilla/show_bug.cgi?id=33464#c2 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea1a0737c7692737a644af0486b71e4a392cbca8 https://vuldb.com/?ctiid.326123 https://vuldb.com/?id.326123 https://vuldb.com/?submit.661276 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11082.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Fw+ArhlgBhD30C7D93vYhg==&#34;: {&#xA;      &#34;id&#34;: &#34;Fw+ArhlgBhD30C7D93vYhg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-6069&#34;,&#xA;      &#34;description&#34;: &#34;A denial-of-service (DoS) vulnerability has been discovered in Python&#39;s html.parser.HTMLParser class. When processing specially malformed HTML input, the parsing runtime can become quadratic with respect to the input size. This significantly increased processing time can lead to excessive resource consumption, ultimately causing a denial-of-service condition in applications that rely on this parser.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-06-17T13:39:46Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-6069 https://bugzilla.redhat.com/show_bug.cgi?id=2373234 https://www.cve.org/CVERecord?id=CVE-2025-6069 https://nvd.nist.gov/vuln/detail/CVE-2025-6069 https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949 https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41 https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b https://github.com/python/cpython/issues/135462 https://github.com/python/cpython/pull/135464 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6069.json https://access.redhat.com/errata/RHSA-2025:23342&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-2.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;FzTxCzGYtLmJVoQ1syBiUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;FzTxCzGYtLmJVoQ1syBiUQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4111&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-11T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4111 https://bugzilla.redhat.com/show_bug.cgi?id=2446453 https://www.cve.org/CVERecord?id=CVE-2026-4111 https://nvd.nist.gov/vuln/detail/CVE-2026-4111 https://github.com/libarchive/libarchive/pull/2877 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4111.json https://access.redhat.com/errata/RHSA-2026:5080&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;bsdtar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.3-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;G/nM9FqgWuICAFy4kMmJlA==&#34;: {&#xA;      &#34;id&#34;: &#34;G/nM9FqgWuICAFy4kMmJlA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59995&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. The `sftp` client, when used to download files from a malicious server with the &#39;sftp server:/path .&#39; command, does not properly restrict where those files are saved. This allows an attacker to control the download location, potentially overwriting existing files or placing malicious files in sensitive directories on the client system, which could compromise system integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T00:04:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59995 https://bugzilla.redhat.com/show_bug.cgi?id=2497927 https://www.cve.org/CVERecord?id=CVE-2026-59995 https://nvd.nist.gov/vuln/detail/CVE-2026-59995 https://marc.info/?l=openssh-unix-dev\u0026m=178333966933090\u0026w=2 https://www.openssh.org/releasenotes.html#10.4p1 https://www.openwall.com/lists/oss-security/2026/07/06/5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59995.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;G1BYG6YufGP4p88wdWeAgg==&#34;: {&#xA;      &#34;id&#34;: &#34;G1BYG6YufGP4p88wdWeAgg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42011&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42011 https://bugzilla.redhat.com/show_bug.cgi?id=2467437 https://www.cve.org/CVERecord?id=CVE-2026-42011 https://nvd.nist.gov/vuln/detail/CVE-2026-42011 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42011.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;GAn7gWUe2pFr7PbwechqxA==&#34;: {&#xA;      &#34;id&#34;: &#34;GAn7gWUe2pFr7PbwechqxA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-30258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GnuPG. In affected versions, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, leading to a verification denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-03-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-30258 https://bugzilla.redhat.com/show_bug.cgi?id=2353427 https://www.cve.org/CVERecord?id=CVE-2025-30258 https://nvd.nist.gov/vuln/detail/CVE-2025-30258 https://dev.gnupg.org/T7527 https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158 https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-30258.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnupg2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;GKtRNrhu6jQDTa3SPO81Kg==&#34;: {&#xA;      &#34;id&#34;: &#34;GKtRNrhu6jQDTa3SPO81Kg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4046&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T17:16:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-headers&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;GMnASWjZHihDlhJdlv57Iw==&#34;: {&#xA;      &#34;id&#34;: &#34;GMnASWjZHihDlhJdlv57Iw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-64505&#34;,&#xA;      &#34;description&#34;: &#34;A heap buffer over-read vulnerability exists in libpng&#39;s png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-24T23:38:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-64505 https://bugzilla.redhat.com/show_bug.cgi?id=2416905 https://www.cve.org/CVERecord?id=CVE-2025-64505 https://nvd.nist.gov/vuln/detail/CVE-2025-64505 https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37 https://github.com/pnggroup/libpng/pull/748 https://github.com/pnggroup/libpng/security/advisories/GHSA-4952-h5wq-4m42 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-64505.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;GW37uYQxwwgJBIDtA/dT2g==&#34;: {&#xA;      &#34;id&#34;: &#34;GW37uYQxwwgJBIDtA/dT2g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-1795&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python. When a separating comma ends up on a folded line during an address list folding of email headers, the comma is unintentionally unicode encoded. The expected behavior is that the separating comma remains unencoded. This can result in the address header being misinterpreted by some mail servers.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-28T18:59:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-1795 https://bugzilla.redhat.com/show_bug.cgi?id=2349061 https://www.cve.org/CVERecord?id=CVE-2025-1795 https://nvd.nist.gov/vuln/detail/CVE-2025-1795 https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48 https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593 https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74 https://github.com/python/cpython/issues/100884 https://github.com/python/cpython/pull/100885 https://github.com/python/cpython/pull/119099 https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1795.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;GWKQvGJTKzyU9GiQECoFhg==&#34;: {&#xA;      &#34;id&#34;: &#34;GWKQvGJTKzyU9GiQECoFhg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69420&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A type confusion vulnerability exists in the TimeStamp Response verification code, where an ASN1_TYPE union member is accessed without proper type validation. A remote attacker can exploit this by providing a malformed TimeStamp Response to an application that verifies timestamp responses. This can lead to an invalid or NULL pointer dereference, resulting in a Denial of Service (DoS) due to an application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69420 https://bugzilla.redhat.com/show_bug.cgi?id=2430388 https://www.cve.org/CVERecord?id=CVE-2025-69420 https://nvd.nist.gov/vuln/detail/CVE-2025-69420 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69420.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;GXMpRf2go/wGEbwpp9BPPQ==&#34;: {&#xA;      &#34;id&#34;: &#34;GXMpRf2go/wGEbwpp9BPPQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-1175&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. There is an incorrect calculation of buffer size issue found in Vim&#39;s yank_copy_line() function of the register.c file. This flaw allows illegal memory access when using virtual editing as \&#34;startspaces\&#34; goes negative. An attacker can trick a user into opening a specially crafted file, triggering an issue that causes an application to crash leading to a denial of service, corrupting memory, and possibly executing code.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-03-04T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-1175 https://bugzilla.redhat.com/show_bug.cgi?id=2176457 https://www.cve.org/CVERecord?id=CVE-2023-1175 https://nvd.nist.gov/vuln/detail/CVE-2023-1175 https://huntr.dev/bounties/7e93fc17-92eb-4ae7-b01a-93bb460b643e https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1175.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;GdB2cJ8S1OqnHKM7G6grQA==&#34;: {&#xA;      &#34;id&#34;: &#34;GdB2cJ8S1OqnHKM7G6grQA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55131&#34;,&#xA;      &#34;description&#34;: &#34;A memory exposure flaw has been discovered in Node.js. A flaw in Node.js&#39;s buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain leftover data from previous operations, allowing in-process secrets like tokens or passwords to leak or causing data corruption.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55131 https://bugzilla.redhat.com/show_bug.cgi?id=2431350 https://www.cve.org/CVERecord?id=CVE-2025-55131 https://nvd.nist.gov/vuln/detail/CVE-2025-55131 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55131.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;GfPY5zBbHJQI4ZGaDcJj2A==&#34;: {&#xA;      &#34;id&#34;: &#34;GfPY5zBbHJQI4ZGaDcJj2A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3278&#34;,&#xA;      &#34;description&#34;: &#34;A NULL pointer dereference vulnerability was found in Vim&#39;s eval_next_non_blank() function of the src/eval.c file. The flaw occurs when using NUL in buffer uses :source. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a NULL pointer dereference that causes a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-24T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3278 https://bugzilla.redhat.com/show_bug.cgi?id=2129831 https://www.cve.org/CVERecord?id=CVE-2022-3278 https://nvd.nist.gov/vuln/detail/CVE-2022-3278 https://huntr.dev/bounties/a9fad77e-f245-4ce9-ba15-c7d4c86c4612 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3278.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;GnBCRP9H+R6do428z3nOkQ==&#34;: {&#xA;      &#34;id&#34;: &#34;GnBCRP9H+R6do428z3nOkQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-4173&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. A possible use after free vulnerability could allow an attacker to input a specially crafted file leading to a crash or code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-12-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-4173 https://bugzilla.redhat.com/show_bug.cgi?id=2035930 https://www.cve.org/CVERecord?id=CVE-2021-4173 https://nvd.nist.gov/vuln/detail/CVE-2021-4173 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-4173.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Go9bB5Mq4W4FHPvmZKBhCg==&#34;: {&#xA;      &#34;id&#34;: &#34;Go9bB5Mq4W4FHPvmZKBhCg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42010&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42010 https://bugzilla.redhat.com/show_bug.cgi?id=2467289 https://www.cve.org/CVERecord?id=CVE-2026-42010 https://nvd.nist.gov/vuln/detail/CVE-2026-42010 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42010.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;GoTAJ6nke0a3zoxJ8lkaAg==&#34;: {&#xA;      &#34;id&#34;: &#34;GoTAJ6nke0a3zoxJ8lkaAg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45446&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. The implementations of AES-SIV (Advanced Encryption Standard - SIV) and AES-GCM-SIV (Advanced Encryption Standard - Galois/Counter Mode - SIV) incorrectly process authentication tags for empty messages. This vulnerability allows a remote attacker to forge empty messages with arbitrary Additional Authenticated Data (AAD) in applications that utilize these specific cipher modes within custom protocols and do not properly handle zero-length ciphertexts. This could lead to unauthorized data manipulation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45446 https://bugzilla.redhat.com/show_bug.cgi?id=2481897 https://www.cve.org/CVERecord?id=CVE-2026-45446 https://nvd.nist.gov/vuln/detail/CVE-2026-45446 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45446.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Gv9SmnUKqHUi+G3vQah9BA==&#34;: {&#xA;      &#34;id&#34;: &#34;Gv9SmnUKqHUi+G3vQah9BA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55130&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55130 https://bugzilla.redhat.com/show_bug.cgi?id=2431352 https://www.cve.org/CVERecord?id=CVE-2025-55130 https://nvd.nist.gov/vuln/detail/CVE-2025-55130 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55130.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;H1wshPoazj8pmzsnWAztZA==&#34;: {&#xA;      &#34;id&#34;: &#34;H1wshPoazj8pmzsnWAztZA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6276&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intended for the first host to the second host, resulting in a cookie leak. This issue is categorized as an Origin Validation Error (CWE-346). Exploitation typically requires specific debugging configurations.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6276 https://bugzilla.redhat.com/show_bug.cgi?id=2461203 https://www.cve.org/CVERecord?id=CVE-2026-6276 https://nvd.nist.gov/vuln/detail/CVE-2026-6276 https://curl.se/docs/CVE-2026-6276.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6276.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;H6ZekKRHFt5pG1Ua5PfWzw==&#34;: {&#xA;      &#34;id&#34;: &#34;H6ZekKRHFt5pG1Ua5PfWzw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6100&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python&#39;s decompression modules, including `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile`. This vulnerability, a use-after-free, can occur if a program attempts to re-use a decompression object after a memory allocation error, especially when the system is experiencing high memory usage. Exploitation of this flaw could potentially allow an attacker to execute arbitrary code or access sensitive data. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-13T17:15:47Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6100 https://bugzilla.redhat.com/show_bug.cgi?id=2457932 https://www.cve.org/CVERecord?id=CVE-2026-6100 https://nvd.nist.gov/vuln/detail/CVE-2026-6100 https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2 https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20 https://github.com/python/cpython/issues/148395 https://github.com/python/cpython/pull/148396 https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json https://access.redhat.com/errata/RHSA-2026:10949&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;HHBOKYlzeD2Busv7btyBAA==&#34;: {&#xA;      &#34;id&#34;: &#34;HHBOKYlzeD2Busv7btyBAA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-48232&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines when smooth scrolling is enabled and the cpo-settings include the &#39;n&#39; flag. This issue may occur when a window border is present and when the wrapped line continues on the next physical line directly in the window border because the &#39;cpo&#39; setting includes the &#39;n&#39; flag. Only users with non-default settings are affected and the exception should only result in a crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-11-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-48232 https://bugzilla.redhat.com/show_bug.cgi?id=2250269 https://www.cve.org/CVERecord?id=CVE-2023-48232 https://nvd.nist.gov/vuln/detail/CVE-2023-48232 http://www.openwall.com/lists/oss-security/2023/11/16/1 https://github.com/vim/vim/commit/cb0b99f0672d8446585d26e998343dceca17d1ce https://github.com/vim/vim/security/advisories/GHSA-f6cx-x634-hqpw https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-48232.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;HSaKorahiaNwGqqE2DJSaw==&#34;: {&#xA;      &#34;id&#34;: &#34;HSaKorahiaNwGqqE2DJSaw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3235&#34;,&#xA;      &#34;description&#34;: &#34;A use after free vulnerability has been found in the vim package of the linux kernals such that Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-18T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3235 https://bugzilla.redhat.com/show_bug.cgi?id=2129371 https://www.cve.org/CVERecord?id=CVE-2022-3235 https://nvd.nist.gov/vuln/detail/CVE-2022-3235 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3235.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;HVxGZgwvlrVpgAxKx4gRlA==&#34;: {&#xA;      &#34;id&#34;: &#34;HVxGZgwvlrVpgAxKx4gRlA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-13149&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-30T08:30:34Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-13149 https://bugzilla.redhat.com/show_bug.cgi?id=2494813 https://www.cve.org/CVERecord?id=CVE-2026-13149 https://nvd.nist.gov/vuln/detail/CVE-2026-13149 https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754 https://www.npmjs.com/package/brace-expansion https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;HZ0OAEgNf1utcoh9whd4EA==&#34;: {&#xA;      &#34;id&#34;: &#34;HZ0OAEgNf1utcoh9whd4EA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14512&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib&#39;s GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-11T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14512 https://bugzilla.redhat.com/show_bug.cgi?id=2421339 https://www.cve.org/CVERecord?id=CVE-2025-14512 https://nvd.nist.gov/vuln/detail/CVE-2025-14512 https://gitlab.gnome.org/GNOME/glib/-/issues/3845 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14512.json https://access.redhat.com/errata/RHSA-2026:19361&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-19.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Hd38sct1pK5WIzmx83J/eA==&#34;: {&#xA;      &#34;id&#34;: &#34;Hd38sct1pK5WIzmx83J/eA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27135&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 frame, leading to an assertion failure and a denial of service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-18T17:59:02Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27135 https://bugzilla.redhat.com/show_bug.cgi?id=2448754 https://www.cve.org/CVERecord?id=CVE-2026-27135 https://nvd.nist.gov/vuln/detail/CVE-2026-27135 https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1 https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Hg9hK3dp3A/kFUiUwl8AoQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Hg9hK3dp3A/kFUiUwl8AoQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-56406&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. An integer overflow vulnerability exists in the `XML_ParseBuffer` function due to a missing check. This flaw could allow an attacker to cause memory corruption, potentially leading to arbitrary code execution, information disclosure, or a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-21T15:48:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-56406 https://bugzilla.redhat.com/show_bug.cgi?id=2491187 https://www.cve.org/CVERecord?id=CVE-2026-56406 https://nvd.nist.gov/vuln/detail/CVE-2026-56406 https://github.com/libexpat/libexpat/pull/1255 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56406.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Hk8k4qPIhaJI1mipqA9iiw==&#34;: {&#xA;      &#34;id&#34;: &#34;Hk8k4qPIhaJI1mipqA9iiw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41080&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing a specially crafted XML document that leverages insufficient entropy in the hash function. This can lead to hash flooding, a type of Denial of Service (DoS) attack, where the system becomes unresponsive or crashes due to excessive resource consumption.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-16T16:52:01Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41080 https://bugzilla.redhat.com/show_bug.cgi?id=2458967 https://www.cve.org/CVERecord?id=CVE-2026-41080 https://nvd.nist.gov/vuln/detail/CVE-2026-41080 https://github.com/libexpat/libexpat/issues/47 https://github.com/libexpat/libexpat/pull/1183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41080.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;HlOu0EmTxHkjzmJeJEuJmw==&#34;: {&#xA;      &#34;id&#34;: &#34;HlOu0EmTxHkjzmJeJEuJmw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-4735&#34;,&#xA;      &#34;description&#34;: &#34;Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-09-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-4735 https://bugzilla.redhat.com/show_bug.cgi?id=2237165 https://www.cve.org/CVERecord?id=CVE-2023-4735 https://nvd.nist.gov/vuln/detail/CVE-2023-4735 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4735.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Hoba3nMTEuYEZMkGsuPdgg==&#34;: {&#xA;      &#34;id&#34;: &#34;Hoba3nMTEuYEZMkGsuPdgg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-50219&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. This vulnerability occurs because the library, in versions before 2.8.2, does not properly track handler call depth when certain XML parsing functions are invoked from within handlers during a policy violation. This oversight can lead to a use-after-free condition, which may result in information disclosure, integrity loss, or denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-04T04:20:32Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-50219 https://bugzilla.redhat.com/show_bug.cgi?id=2484620 https://www.cve.org/CVERecord?id=CVE-2026-50219 https://nvd.nist.gov/vuln/detail/CVE-2026-50219 https://github.com/libexpat/libexpat/pull/1246 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50219.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;HveCNT+j0lknlUOFTaqgtg==&#34;: {&#xA;      &#34;id&#34;: &#34;HveCNT+j0lknlUOFTaqgtg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22693&#34;,&#xA;      &#34;description&#34;: &#34;A null pointer dereference vector has been discovered in the harfbuzz package. A null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh:1672-1673. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-10T05:53:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22693 https://bugzilla.redhat.com/show_bug.cgi?id=2428439 https://www.cve.org/CVERecord?id=CVE-2026-22693 https://nvd.nist.gov/vuln/detail/CVE-2026-22693 https://github.com/harfbuzz/harfbuzz/commit/1265ff8d990284f04d8768f35b0e20ae5f60daae https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-xvjr-f2r9-c7ww https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22693.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;harfbuzz&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;HwrQV7Eq97lmWod0H+Mywg==&#34;: {&#xA;      &#34;id&#34;: &#34;HwrQV7Eq97lmWod0H+Mywg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42769&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Certificate Management Protocol (CMP) implementation within OpenSSL. An attacker with existing Registration Authority (RA) level credentials could exploit an error in the certificate verification process during a Root Certificate Authority (CA) key update. This vulnerability allows the attacker to replace the root CA certificate for CMP clients with a fraudulent one. The primary consequence is an escalation of privileges, enabling the attacker to gain control equivalent to the root CA.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42769 https://bugzilla.redhat.com/show_bug.cgi?id=2481893 https://www.cve.org/CVERecord?id=CVE-2026-42769 https://nvd.nist.gov/vuln/detail/CVE-2026-42769 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42769.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;HxI42iSjURjRki+uV6q/9w==&#34;: {&#xA;      &#34;id&#34;: &#34;HxI42iSjURjRki+uV6q/9w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-0232&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-10-12T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-0232 https://bugzilla.redhat.com/show_bug.cgi?id=2243754 https://www.cve.org/CVERecord?id=CVE-2024-0232 https://nvd.nist.gov/vuln/detail/CVE-2024-0232 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0232.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;sqlite&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;I3+uP7bb+nPtzRYHH2UUgw==&#34;: {&#xA;      &#34;id&#34;: &#34;I3+uP7bb+nPtzRYHH2UUgw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-3826&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in Libiberty. A heap and stack buffer overflow found in the dlang_lname function in d-demangle.c leads to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-09-22T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-3826 https://bugzilla.redhat.com/show_bug.cgi?id=2122627 https://www.cve.org/CVERecord?id=CVE-2021-3826 https://nvd.nist.gov/vuln/detail/CVE-2021-3826 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-3826.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;I3vwwgMxzxWo15otCOgvAw==&#34;: {&#xA;      &#34;id&#34;: &#34;I3vwwgMxzxWo15otCOgvAw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-3928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. A possible stack-based buffer overflow could allow an attacker to input a specially crafted file leading to a crash or code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-10-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-3928 https://bugzilla.redhat.com/show_bug.cgi?id=2021292 https://www.cve.org/CVERecord?id=CVE-2021-3928 https://nvd.nist.gov/vuln/detail/CVE-2021-3928 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-3928.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;IDIT7Gfu8E9A+NfUxEcAbQ==&#34;: {&#xA;      &#34;id&#34;: &#34;IDIT7Gfu8E9A+NfUxEcAbQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42768&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL&#39;s CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim&#39;s private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application&#39;s error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42768 https://bugzilla.redhat.com/show_bug.cgi?id=2481892 https://www.cve.org/CVERecord?id=CVE-2026-42768 https://nvd.nist.gov/vuln/detail/CVE-2026-42768 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42768.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;IF/pusRwq2cM2AL083HZhw==&#34;: {&#xA;      &#34;id&#34;: &#34;IF/pusRwq2cM2AL083HZhw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42338&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user&#39;s browser.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-12T19:43:16Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42338 https://bugzilla.redhat.com/show_bug.cgi?id=2476810 https://www.cve.org/CVERecord?id=CVE-2026-42338 https://nvd.nist.gov/vuln/detail/CVE-2026-42338 https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;IFUwSX5dX69QHRHfvOeQDg==&#34;: {&#xA;      &#34;id&#34;: &#34;IFUwSX5dX69QHRHfvOeQDg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6429&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6429 https://bugzilla.redhat.com/show_bug.cgi?id=2461205 https://www.cve.org/CVERecord?id=CVE-2026-6429 https://nvd.nist.gov/vuln/detail/CVE-2026-6429 https://curl.se/docs/CVE-2026-6429.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6429.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;IGF/2G1+7Y+pT7nmmFHvPw==&#34;: {&#xA;      &#34;id&#34;: &#34;IGF/2G1+7Y+pT7nmmFHvPw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-40355&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit a NULL pointer dereference vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the termination of the process, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-40355 https://bugzilla.redhat.com/show_bug.cgi?id=2463370 https://www.cve.org/CVERecord?id=CVE-2026-40355 https://nvd.nist.gov/vuln/detail/CVE-2026-40355 https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f https://web.mit.edu/kerberos/advisories/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40355.json https://access.redhat.com/errata/RHSA-2026:19357&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;krb5-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.21.1-10.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;IPiVFeI45MBrWEz4KZcdQQ==&#34;: {&#xA;      &#34;id&#34;: &#34;IPiVFeI45MBrWEz4KZcdQQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42308&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceeding large amount, an integer overflow can occur when Pillow tracks the current position. This could lead to a denial of service (DoS) condition, making the application unavailable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T04:09:01Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42308 https://bugzilla.redhat.com/show_bug.cgi?id=2468457 https://www.cve.org/CVERecord?id=CVE-2026-42308 https://nvd.nist.gov/vuln/detail/CVE-2026-42308 https://github.com/python-pillow/Pillow/releases/tag/12.2.0 https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42308.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;IeTK1HBLKpS1+gfVSPrpvg==&#34;: {&#xA;      &#34;id&#34;: &#34;IeTK1HBLKpS1+gfVSPrpvg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-47007&#34;,&#xA;      &#34;description&#34;: &#34;A memory leak was found in function  stab_demangle_v3_arg in stabs.c in Binutils, allows local attacker to exploit the vulnerability using specially crafted file to cause Denial of Service.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-47007 https://bugzilla.redhat.com/show_bug.cgi?id=2233980 https://www.cve.org/CVERecord?id=CVE-2022-47007 https://nvd.nist.gov/vuln/detail/CVE-2022-47007 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-47007.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;IrRjtVOpf04EO7iAKFAznQ==&#34;: {&#xA;      &#34;id&#34;: &#34;IrRjtVOpf04EO7iAKFAznQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0915&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. When an application calls the `getnetbyaddr` or `getnetbyaddr_r` functions to resolve a network address, and the system&#39;s `nsswitch.conf` file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-15T22:08:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0915 https://bugzilla.redhat.com/show_bug.cgi?id=2430201 https://www.cve.org/CVERecord?id=CVE-2026-0915 https://nvd.nist.gov/vuln/detail/CVE-2026-0915 https://sourceware.org/bugzilla/show_bug.cgi?id=33802 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0915.json https://access.redhat.com/errata/RHSA-2026:2786&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-231.el9_7.10&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Iv6wxIYqSLEjaMJTKmJ+Pw==&#34;: {&#xA;      &#34;id&#34;: &#34;Iv6wxIYqSLEjaMJTKmJ+Pw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4437&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4437 https://bugzilla.redhat.com/show_bug.cgi?id=2449777 https://www.cve.org/CVERecord?id=CVE-2026-4437 https://nvd.nist.gov/vuln/detail/CVE-2026-4437 https://sourceware.org/bugzilla/show_bug.cgi?id=34014 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4437.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;J/9bEF16NjSRIAmmzZMBkQ==&#34;: {&#xA;      &#34;id&#34;: &#34;J/9bEF16NjSRIAmmzZMBkQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:37:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-gconv-extra&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;J/M93jueASHywmph2g+HMg==&#34;: {&#xA;      &#34;id&#34;: &#34;J/M93jueASHywmph2g+HMg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48619&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. A malicious server can exploit the HTTP/2 client by sending an unlimited number of ORIGIN frames. This can lead to an Out of Memory error on the client, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48619 https://bugzilla.redhat.com/show_bug.cgi?id=2493325 https://www.cve.org/CVERecord?id=CVE-2026-48619 https://nvd.nist.gov/vuln/detail/CVE-2026-48619 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48619.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;J1e16b0P6Tp2x5sVgsqutQ==&#34;: {&#xA;      &#34;id&#34;: &#34;J1e16b0P6Tp2x5sVgsqutQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48615&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48615 https://bugzilla.redhat.com/show_bug.cgi?id=2493335 https://www.cve.org/CVERecord?id=CVE-2026-48615 https://nvd.nist.gov/vuln/detail/CVE-2026-48615 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48615.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;J7eLc/Mh7BobYrDH+tpguA==&#34;: {&#xA;      &#34;id&#34;: &#34;J7eLc/Mh7BobYrDH+tpguA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-10911&#34;,&#xA;      &#34;description&#34;: &#34;A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-08-04T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-10911 https://bugzilla.redhat.com/show_bug.cgi?id=2397838 https://www.cve.org/CVERecord?id=CVE-2025-10911 https://nvd.nist.gov/vuln/detail/CVE-2025-10911 https://gitlab.gnome.org/GNOME/libxslt/-/issues/144 https://gitlab.gnome.org/GNOME/libxslt/-/merge_requests/77 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-10911.json https://access.redhat.com/errata/RHSA-2026:28243&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxslt-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.1.34-14.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;J9gq9t3ASg6Sp5n2QRemEA==&#34;: {&#xA;      &#34;id&#34;: &#34;J9gq9t3ASg6Sp5n2QRemEA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-6075&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability in Python’s os.path.expandvars() function that can cause performance degradation. When processing specially crafted, user-controlled input with nested environment variable patterns, the function exhibits quadratic time complexity, potentially leading to excessive CPU usage and denial of service (DoS) conditions. No code execution or data exposure occurs, so the impact is limited to performance slowdown.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-31T16:41:34Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-6075 https://bugzilla.redhat.com/show_bug.cgi?id=2408891 https://www.cve.org/CVERecord?id=CVE-2025-6075 https://nvd.nist.gov/vuln/detail/CVE-2025-6075 https://github.com/python/cpython/issues/136065 https://mail.python.org/archives/list/security-announce@python.org/thread/IUP5QJ6D4KK6ULHOMPC7DPNKRYQTQNLA/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6075.json https://access.redhat.com/errata/RHSA-2025:23342&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-2.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;JAlZO0sgdy1FBW5F7Zj+Pg==&#34;: {&#xA;      &#34;id&#34;: &#34;JAlZO0sgdy1FBW5F7Zj+Pg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35388&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows for a low integrity impact due to the omission of connection multiplexing confirmation for proxy-mode multiplexing sessions. A local user, under specific and complex conditions requiring user interaction, could potentially establish a multiplexed session without explicit confirmation, leading to unintended data handling.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:57:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35388 https://bugzilla.redhat.com/show_bug.cgi?id=2454500 https://www.cve.org/CVERecord?id=CVE-2026-35388 https://nvd.nist.gov/vuln/detail/CVE-2026-35388 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35388.json https://access.redhat.com/errata/RHSA-2026:13381&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-49.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;JD0llI0bGUOG/VBz+9LeVQ==&#34;: {&#xA;      &#34;id&#34;: &#34;JD0llI0bGUOG/VBz+9LeVQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-48235&#34;,&#xA;      &#34;description&#34;: &#34;A flaw as found in Vim, an open source command line text editor. When parsing relative ex addresses, one may unintentionally cause an overflow. Ironically, this happens in the existing overflow check because the line number becomes negative and LONG_MAX - lnum will cause the overflow. The impact is low because user interaction is required and a crash may not happen in all situations.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-11-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-48235 https://bugzilla.redhat.com/show_bug.cgi?id=2250272 https://www.cve.org/CVERecord?id=CVE-2023-48235 https://nvd.nist.gov/vuln/detail/CVE-2023-48235 http://www.openwall.com/lists/oss-security/2023/11/16/1 https://github.com/vim/vim/commit/060623e4a3bc72b011e7cd92bedb3bfb64e06200 https://github.com/vim/vim/security/advisories/GHSA-6g74-hr6q-pr8g https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-48235.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;JLoYxSe6sUCueA3LPfbTLA==&#34;: {&#xA;      &#34;id&#34;: &#34;JLoYxSe6sUCueA3LPfbTLA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-default-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;JPakAMrmBlullQ47gJ/fkw==&#34;: {&#xA;      &#34;id&#34;: &#34;JPakAMrmBlullQ47gJ/fkw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33416&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng, a library used for processing PNG (Portable Network Graphics) image files. This vulnerability arises from improper memory management where a heap-allocated buffer is aliased between internal data structures. When specific functions are called, a freed memory region can still be referenced, leading to a use-after-free condition. An attacker could potentially exploit this to achieve arbitrary code execution or cause a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-26T16:48:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33416 https://bugzilla.redhat.com/show_bug.cgi?id=2451805 https://www.cve.org/CVERecord?id=CVE-2026-33416 https://nvd.nist.gov/vuln/detail/CVE-2026-33416 https://github.com/pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb https://github.com/pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667 https://github.com/pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25 https://github.com/pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1 https://github.com/pnggroup/libpng/pull/824 https://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33416.json https://access.redhat.com/errata/RHSA-2026:28255&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-15.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;JYnbFl5uln18531ZOk6t8g==&#34;: {&#xA;      &#34;id&#34;: &#34;JYnbFl5uln18531ZOk6t8g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45446&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. The implementations of AES-SIV (Advanced Encryption Standard - SIV) and AES-GCM-SIV (Advanced Encryption Standard - Galois/Counter Mode - SIV) incorrectly process authentication tags for empty messages. This vulnerability allows a remote attacker to forge empty messages with arbitrary Additional Authenticated Data (AAD) in applications that utilize these specific cipher modes within custom protocols and do not properly handle zero-length ciphertexts. This could lead to unauthorized data manipulation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45446 https://bugzilla.redhat.com/show_bug.cgi?id=2481897 https://www.cve.org/CVERecord?id=CVE-2026-45446 https://nvd.nist.gov/vuln/detail/CVE-2026-45446 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45446.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;JknhMYFxtGMAisBMILMboQ==&#34;: {&#xA;      &#34;id&#34;: &#34;JknhMYFxtGMAisBMILMboQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-6176&#34;,&#xA;      &#34;description&#34;: &#34;Scrapy are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-31T00:00:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-6176 https://bugzilla.redhat.com/show_bug.cgi?id=2408762 https://www.cve.org/CVERecord?id=CVE-2025-6176 https://nvd.nist.gov/vuln/detail/CVE-2025-6176 https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6176.json https://access.redhat.com/errata/RHSA-2026:2042&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;brotli&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.0.9-9.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;JmKf//IQj2eMVJFTB1Feyw==&#34;: {&#xA;      &#34;id&#34;: &#34;JmKf//IQj2eMVJFTB1Feyw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-48234&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open source command line text editor. When getting the count for a normal mode z command, it may overflow if large counts are given. The impact is low because user interaction is required and a crash may not happen in all situations.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-11-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-48234 https://bugzilla.redhat.com/show_bug.cgi?id=2250271 https://www.cve.org/CVERecord?id=CVE-2023-48234 https://nvd.nist.gov/vuln/detail/CVE-2023-48234 http://www.openwall.com/lists/oss-security/2023/11/16/1 https://github.com/vim/vim/commit/58f9befca1fa172068effad7f2ea5a9d6a7b0cca https://github.com/vim/vim/security/advisories/GHSA-59gw-c949-6phq https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-48234.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;JpVSLeyNGU9aXWuvL1lvmw==&#34;: {&#xA;      &#34;id&#34;: &#34;JpVSLeyNGU9aXWuvL1lvmw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-irb&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.13.1-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Jrkns8qeStFRPhcitcuZ4w==&#34;: {&#xA;      &#34;id&#34;: &#34;Jrkns8qeStFRPhcitcuZ4w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22796&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a denial of service (DoS) by providing specially crafted PKCS#7 data to an application that performs signature verification. The vulnerability occurs because the application accesses an ASN1_TYPE union member without proper type validation, leading to an invalid or NULL pointer dereference and a crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22796 https://bugzilla.redhat.com/show_bug.cgi?id=2430390 https://www.cve.org/CVERecord?id=CVE-2026-22796 https://nvd.nist.gov/vuln/detail/CVE-2026-22796 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22796.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;JtGggrfMckWn0xvfWBMJJQ==&#34;: {&#xA;      &#34;id&#34;: &#34;JtGggrfMckWn0xvfWBMJJQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2210&#34;,&#xA;      &#34;description&#34;: &#34;Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2210 https://bugzilla.redhat.com/show_bug.cgi?id=2102177 https://www.cve.org/CVERecord?id=CVE-2022-2210 https://nvd.nist.gov/vuln/detail/CVE-2022-2210 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2210.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;K2GE6n8fwvl9qlLu7U38Fg==&#34;: {&#xA;      &#34;id&#34;: &#34;K2GE6n8fwvl9qlLu7U38Fg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55131&#34;,&#xA;      &#34;description&#34;: &#34;A memory exposure flaw has been discovered in Node.js. A flaw in Node.js&#39;s buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain leftover data from previous operations, allowing in-process secrets like tokens or passwords to leak or causing data corruption.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55131 https://bugzilla.redhat.com/show_bug.cgi?id=2431350 https://www.cve.org/CVERecord?id=CVE-2025-55131 https://nvd.nist.gov/vuln/detail/CVE-2025-55131 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55131.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.4-1.22.22.0.1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;K3SBN066vVckR2wFFfybNw==&#34;: {&#xA;      &#34;id&#34;: &#34;K3SBN066vVckR2wFFfybNw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41035&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in rsync. When rsync is configured to handle extended attributes (using the -X or --xattrs option), a remote attacker can exploit a use-after-free vulnerability. This occurs because the receive_xattr function incorrectly processes an untrusted length value during a sorting operation, leading to memory corruption. Successful exploitation can result in a denial of service, causing the rsync process to crash, and may potentially allow for arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-16T06:53:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41035 https://bugzilla.redhat.com/show_bug.cgi?id=2458898 https://www.cve.org/CVERecord?id=CVE-2026-41035 https://nvd.nist.gov/vuln/detail/CVE-2026-41035 https://github.com/RsyncProject/rsync/issues/871 https://github.com/RsyncProject/rsync/releases https://www.openwall.com/lists/oss-security/2026/04/16/2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41035.json https://access.redhat.com/errata/RHSA-2026:19368&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.2.5-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;KB8w2g8b8sP5A8+iqhqw8A==&#34;: {&#xA;      &#34;id&#34;: &#34;KB8w2g8b8sP5A8+iqhqw8A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-28418&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. When processing a specially crafted Emacs-style tags file, a heap-based buffer overflow out-of-bounds read vulnerability allows an attacker to trick Vim into reading up to 7 bytes beyond its allocated memory boundary. This could lead to information disclosure or potentially affect the integrity of the application.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-27T21:58:37Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-28418 https://bugzilla.redhat.com/show_bug.cgi?id=2443481 https://www.cve.org/CVERecord?id=CVE-2026-28418 https://nvd.nist.gov/vuln/detail/CVE-2026-28418 https://github.com/vim/vim/commit/f6a7f469a9c0d09e84cd6cb https://github.com/vim/vim/releases/tag/v9.2.0074 https://github.com/vim/vim/security/advisories/GHSA-h4mf-vg97-hj8j https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28418.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;KFwkHKkJGVyJAn2RsW13sw==&#34;: {&#xA;      &#34;id&#34;: &#34;KFwkHKkJGVyJAn2RsW13sw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66199&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker can exploit this vulnerability by sending a specially crafted CompressedCertificate message during the TLS 1.3 handshake. This can cause excessive per-connection memory allocations, leading to resource exhaustion and a Denial of Service (DoS) for affected clients and servers. This issue occurs when TLS 1.3 certificate compression is enabled and negotiated.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66199 https://bugzilla.redhat.com/show_bug.cgi?id=2430379 https://www.cve.org/CVERecord?id=CVE-2025-66199 https://nvd.nist.gov/vuln/detail/CVE-2025-66199 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66199.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;KHHIjt6Egtc7csaIbQ3mbw==&#34;: {&#xA;      &#34;id&#34;: &#34;KHHIjt6Egtc7csaIbQ3mbw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-32778&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. This vulnerability allows an attacker to trigger a NULL pointer dereference in the `setContext` function. This occurs when the system attempts to retry an operation after an out-of-memory condition, which can lead to a Denial of Service (DoS) for the affected application.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-16T07:02:34Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-32778 https://bugzilla.redhat.com/show_bug.cgi?id=2447885 https://www.cve.org/CVERecord?id=CVE-2026-32778 https://nvd.nist.gov/vuln/detail/CVE-2026-32778 https://github.com/libexpat/libexpat/pull/1159 https://github.com/libexpat/libexpat/pull/1163 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32778.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;KMGV9rbVZ/vVUNSX6f+JqA==&#34;: {&#xA;      &#34;id&#34;: &#34;KMGV9rbVZ/vVUNSX6f+JqA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4111&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-11T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4111 https://bugzilla.redhat.com/show_bug.cgi?id=2446453 https://www.cve.org/CVERecord?id=CVE-2026-4111 https://nvd.nist.gov/vuln/detail/CVE-2026-4111 https://github.com/libarchive/libarchive/pull/2877 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4111.json https://access.redhat.com/errata/RHSA-2026:5080&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.3-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;KRZBmtp/oO0gwwF8PmGh2g==&#34;: {&#xA;      &#34;id&#34;: &#34;KRZBmtp/oO0gwwF8PmGh2g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1528&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a specially crafted WebSocket frame with an extremely large 64-bit length. This causes undici&#39;s ByteParser to overflow its internal calculations, leading to an invalid state and a fatal TypeError. The primary consequence is a Denial of Service (DoS), which terminates the process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:21:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1528 https://bugzilla.redhat.com/show_bug.cgi?id=2447145 https://www.cve.org/CVERecord?id=CVE-2026-1528 https://nvd.nist.gov/vuln/detail/CVE-2026-1528 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj https://hackerone.com/reports/3537648 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1528.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;KWRSi8vxblrZIdlqIEG3zA==&#34;: {&#xA;      &#34;id&#34;: &#34;KWRSi8vxblrZIdlqIEG3zA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59873&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:22:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59873 https://bugzilla.redhat.com/show_bug.cgi?id=2498120 https://www.cve.org/CVERecord?id=CVE-2026-59873 https://nvd.nist.gov/vuln/detail/CVE-2026-59873 https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3 https://github.com/isaacs/node-tar/releases/tag/v7.5.19 https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59873.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;KYv6PwzjV6/5I33cZ9LUmQ==&#34;: {&#xA;      &#34;id&#34;: &#34;KYv6PwzjV6/5I33cZ9LUmQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2817&#34;,&#xA;      &#34;description&#34;: &#34;A use-after-free vulnerability was found in Vim in the string_quote function in the strings.c file. This issue occurs because an already freed memory is used when a specially crafted input is processed. This flaw allows an attacker who can trick a user into opening a specially crafted file into triggering the use-after-free, causing the application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-12T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2817 https://bugzilla.redhat.com/show_bug.cgi?id=2119043 https://www.cve.org/CVERecord?id=CVE-2022-2817 https://nvd.nist.gov/vuln/detail/CVE-2022-2817 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2817.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Kpg8AKRn9eUVlQlRye20Tg==&#34;: {&#xA;      &#34;id&#34;: &#34;Kpg8AKRn9eUVlQlRye20Tg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-psych&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:5.1.2-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Kqq2xlybjD/tOLmQWu2xPw==&#34;: {&#xA;      &#34;id&#34;: &#34;Kqq2xlybjD/tOLmQWu2xPw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-5918&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-20T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-5918 https://bugzilla.redhat.com/show_bug.cgi?id=2370877 https://www.cve.org/CVERecord?id=CVE-2025-5918 https://nvd.nist.gov/vuln/detail/CVE-2025-5918 https://github.com/libarchive/libarchive/pull/2584 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5918.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;KqyZJW2L6JQ2vf0yVMm6jg==&#34;: {&#xA;      &#34;id&#34;: &#34;KqyZJW2L6JQ2vf0yVMm6jg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33416&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng, a library used for processing PNG (Portable Network Graphics) image files. This vulnerability arises from improper memory management where a heap-allocated buffer is aliased between internal data structures. When specific functions are called, a freed memory region can still be referenced, leading to a use-after-free condition. An attacker could potentially exploit this to achieve arbitrary code execution or cause a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-26T16:48:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33416 https://bugzilla.redhat.com/show_bug.cgi?id=2451805 https://www.cve.org/CVERecord?id=CVE-2026-33416 https://nvd.nist.gov/vuln/detail/CVE-2026-33416 https://github.com/pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb https://github.com/pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667 https://github.com/pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25 https://github.com/pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1 https://github.com/pnggroup/libpng/pull/824 https://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33416.json https://access.redhat.com/errata/RHSA-2026:28255&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-15.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Kr2KcyJfYQ8J1RDorzTofQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Kr2KcyJfYQ8J1RDorzTofQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69651&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. An attacker could exploit this vulnerability by providing a crafted Executable and Linkable Format (ELF) binary with malformed relocation or symbol data. Processing this malicious binary leads to an invalid pointer free, which triggers memory corruption checks and causes the program to terminate.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69651 https://bugzilla.redhat.com/show_bug.cgi?id=2445299 https://www.cve.org/CVERecord?id=CVE-2025-69651 https://nvd.nist.gov/vuln/detail/CVE-2025-69651 https://sourceware.org/bugzilla/show_bug.cgi?id=33700 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69651.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;KsboTEAsiwsdLEKIDivkyA==&#34;: {&#xA;      &#34;id&#34;: &#34;KsboTEAsiwsdLEKIDivkyA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2175&#34;,&#xA;      &#34;description&#34;: &#34;A heap buffer over-read vulnerability was found in Vim&#39;s put_on_cmdline() function of the src/ex_getln.c file. This issue occurs due to invalid memory access when using an expression on the command line. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap buffer overflow that causes an application to crash and corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-23T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2175 https://bugzilla.redhat.com/show_bug.cgi?id=2101293 https://www.cve.org/CVERecord?id=CVE-2022-2175 https://nvd.nist.gov/vuln/detail/CVE-2022-2175 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2175.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Kso3mzUHoYi+5+CqbHmG2w==&#34;: {&#xA;      &#34;id&#34;: &#34;Kso3mzUHoYi+5+CqbHmG2w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11940&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the `tarfile.extractall()` function within Python. A remote attacker could exploit this vulnerability by providing a specially crafted archive. This archive could bypass security filters by using a hardlink that references a symlink, allowing the symlink to be recreated outside the intended destination directory. This could lead to out-of-destination file reads or writes, potentially resulting in information disclosure or arbitrary file modification.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-23T16:04:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11940 https://bugzilla.redhat.com/show_bug.cgi?id=2491848 https://www.cve.org/CVERecord?id=CVE-2026-11940 https://nvd.nist.gov/vuln/detail/CVE-2026-11940 https://github.com/python/cpython/issues/151558 https://github.com/python/cpython/pull/151559 https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11940.json https://access.redhat.com/errata/RHSA-2026:54268&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-7.el9_8.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;L1NHjBKVcGa4hqzsfSCCQg==&#34;: {&#xA;      &#34;id&#34;: &#34;L1NHjBKVcGa4hqzsfSCCQg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34180&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34180 https://bugzilla.redhat.com/show_bug.cgi?id=2481881 https://www.cve.org/CVERecord?id=CVE-2026-34180 https://nvd.nist.gov/vuln/detail/CVE-2026-34180 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34180.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;LI6QdIyga6/I93JFZfZG6g==&#34;: {&#xA;      &#34;id&#34;: &#34;LI6QdIyga6/I93JFZfZG6g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5435&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T11:58:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-locale-source&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;LIhAM4tPNTZzvy57RdTFgQ==&#34;: {&#xA;      &#34;id&#34;: &#34;LIhAM4tPNTZzvy57RdTFgQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6733&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici&#39;s HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:14:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6733 https://bugzilla.redhat.com/show_bug.cgi?id=2490006 https://www.cve.org/CVERecord?id=CVE-2026-6733 https://nvd.nist.gov/vuln/detail/CVE-2026-6733 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 https://hackerone.com/reports/3582376 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6733.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;LUQxjpYcQwxSDC7CX78VUw==&#34;: {&#xA;      &#34;id&#34;: &#34;LUQxjpYcQwxSDC7CX78VUw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-60000&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH&#39;s Secure Shell Daemon (sshd). This vulnerability allows a remote attacker to cause a denial of service by initiating an excessive number of authentication attempts. The issue arises from the mishandling of the MaxAuthTries setting specifically when using GSSAPIAuthentication, leading to resource exhaustion.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T00:14:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-60000 https://bugzilla.redhat.com/show_bug.cgi?id=2497946 https://www.cve.org/CVERecord?id=CVE-2026-60000 https://nvd.nist.gov/vuln/detail/CVE-2026-60000 https://marc.info/?l=openssh-unix-dev\u0026m=178333966933090\u0026w=2 https://www.openssh.org/releasenotes.html#10.4p1 https://www.openwall.com/lists/oss-security/2026/07/06/5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-60000.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;LXM9CbBE9eK3grkTD73h+g==&#34;: {&#xA;      &#34;id&#34;: &#34;LXM9CbBE9eK3grkTD73h+g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-3832&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-30T17:29:25Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-3832 https://bugzilla.redhat.com/show_bug.cgi?id=2445762 https://www.cve.org/CVERecord?id=CVE-2026-3832 https://nvd.nist.gov/vuln/detail/CVE-2026-3832 https://gitlab.com/gnutls/gnutls/-/issues/1801 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3832.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;LdeUngez6mnzZ7ugJzuAmQ==&#34;: {&#xA;      &#34;id&#34;: &#34;LdeUngez6mnzZ7ugJzuAmQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-59466&#34;,&#xA;      &#34;description&#34;: &#34;A stack overflow flaw has been discovered in Node.js error handling where \&#34;Maximum call stack size exceeded\&#34; errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on(&#39;uncaughtException&#39;)`, the process terminates, making the crash unrecoverable. Applications that rely on `AsyncLocalStorage` (v22, v20) or `async_hooks.createHook()` (v24, v22, v20) become vulnerable to denial-of-service crashes triggered by deep recursion under specific conditions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-59466 https://bugzilla.redhat.com/show_bug.cgi?id=2431343 https://www.cve.org/CVERecord?id=CVE-2025-59466 https://nvd.nist.gov/vuln/detail/CVE-2025-59466 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59466.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Lhc4n2a9ma6eRDB/RCRmLQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Lhc4n2a9ma6eRDB/RCRmLQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-9086&#34;,&#xA;      &#34;description&#34;: &#34;An out of bounds read flaw has been discovered in the curl project. Under specific conditions the path comparison logic makes curl read outside a heap buffer boundary. This bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-12T05:10:03Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-9086 https://bugzilla.redhat.com/show_bug.cgi?id=2394750 https://www.cve.org/CVERecord?id=CVE-2025-9086 https://nvd.nist.gov/vuln/detail/CVE-2025-9086 https://curl.se/docs/CVE-2025-9086.html https://curl.se/docs/CVE-2025-9086.json https://github.com/curl/curl/commit/c6ae07c6a541e0e96d0040afb6 https://hackerone.com/reports/3294999 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9086.json https://access.redhat.com/errata/RHSA-2026:1350&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl-minimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:7.76.1-35.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;LiIvRwi7+1nAVErMH0hoaQ==&#34;: {&#xA;      &#34;id&#34;: &#34;LiIvRwi7+1nAVErMH0hoaQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-5278&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GNU Coreutils. The sort utility&#39;s begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-5278 https://bugzilla.redhat.com/show_bug.cgi?id=2368764 https://www.cve.org/CVERecord?id=CVE-2025-5278 https://nvd.nist.gov/vuln/detail/CVE-2025-5278 https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633 https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5278.json https://access.redhat.com/errata/RHSA-2026:28911&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;coreutils-single&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.32-41.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;LkJjju2s50oKpBRyBT8s0A==&#34;: {&#xA;      &#34;id&#34;: &#34;LkJjju2s50oKpBRyBT8s0A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-41965&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in Vim versions before 9.1.0648 that can cause the program to crash. This issue happens when a user abandons a modified file, and Vim tries to save it as an Untitled file. Due to a mistake in handling this process, Vim accidentally tries to free up memory twice, which can lead to problems, causing the program to crash. This issue can be exploited by someone with local access to the system.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-08-01T22:21:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-41965 https://bugzilla.redhat.com/show_bug.cgi?id=2302419 https://www.cve.org/CVERecord?id=CVE-2024-41965 https://nvd.nist.gov/vuln/detail/CVE-2024-41965 https://github.com/vim/vim/commit/b29f4abcd4b3382fa746edd1d0562b7b48c https://github.com/vim/vim/security/advisories/GHSA-46pw-v7qw-xc2f https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-41965.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Lr5d+BjmGHyC+AWnFQJRTA==&#34;: {&#xA;      &#34;id&#34;: &#34;Lr5d+BjmGHyC+AWnFQJRTA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-8291&#34;,&#xA;      &#34;description&#34;: &#34;A zip file handling flaw has been discovered in the python standard library `zipfile` module. The &#39;zipfile&#39; module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the &#39;zipfile&#39; module compared to other ZIP implementations.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-07T18:10:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-8291 https://bugzilla.redhat.com/show_bug.cgi?id=2402342 https://www.cve.org/CVERecord?id=CVE-2025-8291 https://nvd.nist.gov/vuln/detail/CVE-2025-8291 https://github.com/python/cpython/commit/162997bb70e067668c039700141770687bc8f267 https://github.com/python/cpython/commit/333d4a6f4967d3ace91492a39ededbcf3faa76a6 https://github.com/python/cpython/issues/139700 https://github.com/python/cpython/pull/139702 https://mail.python.org/archives/list/security-announce@python.org/thread/QECOPWMTH4VPPJAXAH2BGTA4XADOP62G/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-8291.json https://access.redhat.com/errata/RHSA-2025:23342&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-2.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;LxYgcRll4fEnbCHHZWt4BA==&#34;: {&#xA;      &#34;id&#34;: &#34;LxYgcRll4fEnbCHHZWt4BA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5121&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T07:44:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5121 https://bugzilla.redhat.com/show_bug.cgi?id=2452945 https://www.cve.org/CVERecord?id=CVE-2026-5121 https://nvd.nist.gov/vuln/detail/CVE-2026-5121 https://github.com/advisories/GHSA-2vwv-vqpv-v8vc https://github.com/libarchive/libarchive/pull/2934 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5121.json https://access.redhat.com/errata/RHSA-2026:8510&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.3-9.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Ly8YGlWm8+S4CYtF8Y/Htw==&#34;: {&#xA;      &#34;id&#34;: &#34;Ly8YGlWm8+S4CYtF8Y/Htw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bigdecimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.1.5-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;M293c+QguJ/aaYP3cMwfyQ==&#34;: {&#xA;      &#34;id&#34;: &#34;M293c+QguJ/aaYP3cMwfyQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-28388&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-28388 https://bugzilla.redhat.com/show_bug.cgi?id=2451097 https://www.cve.org/CVERecord?id=CVE-2026-28388 https://nvd.nist.gov/vuln/detail/CVE-2026-28388 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28388.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;M29Ot9TqS/JJH7ICJCbCog==&#34;: {&#xA;      &#34;id&#34;: &#34;M29Ot9TqS/JJH7ICJCbCog==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22801&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng, a reference library for PNG (Portable Network Graphics) raster image files. An integer truncation vulnerability exists in the png_write_image_16bit and png_write_image_8bit simplified write API functions. A local attacker could exploit this flaw by providing a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes, leading to a heap buffer over-read. This can result in information disclosure or a denial of service (DoS) to the system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-12T22:57:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22801 https://bugzilla.redhat.com/show_bug.cgi?id=2428824 https://www.cve.org/CVERecord?id=CVE-2026-22801 https://nvd.nist.gov/vuln/detail/CVE-2026-22801 https://github.com/pnggroup/libpng/security/advisories/GHSA-vgjq-8cw5-ggw8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22801.json https://access.redhat.com/errata/RHSA-2026:3405&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MDVosfib/bnNAm4m647vLA==&#34;: {&#xA;      &#34;id&#34;: &#34;MDVosfib/bnNAm4m647vLA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48934&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48934 https://bugzilla.redhat.com/show_bug.cgi?id=2493332 https://www.cve.org/CVERecord?id=CVE-2026-48934 https://nvd.nist.gov/vuln/detail/CVE-2026-48934 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48934.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MEeKHFVdv0EwpaMPKCy3Sw==&#34;: {&#xA;      &#34;id&#34;: &#34;MEeKHFVdv0EwpaMPKCy3Sw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48619&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. A malicious server can exploit the HTTP/2 client by sending an unlimited number of ORIGIN frames. This can lead to an Out of Memory error on the client, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48619 https://bugzilla.redhat.com/show_bug.cgi?id=2493325 https://www.cve.org/CVERecord?id=CVE-2026-48619 https://nvd.nist.gov/vuln/detail/CVE-2026-48619 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48619.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MIaYLvbJRWXm7UR3+CJ1PA==&#34;: {&#xA;      &#34;id&#34;: &#34;MIaYLvbJRWXm7UR3+CJ1PA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66864&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted PE file with cxxfilt can trigger a NULL pointer dereference in the d_print_comp_inner function in the cp-demangle.c file, causing a crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66864 https://bugzilla.redhat.com/show_bug.cgi?id=2425827 https://www.cve.org/CVERecord?id=CVE-2025-66864 https://nvd.nist.gov/vuln/detail/CVE-2025-66864 https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66864.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MLyBE3p9/9+LMOMl2JBi6w==&#34;: {&#xA;      &#34;id&#34;: &#34;MLyBE3p9/9+LMOMl2JBi6w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2343&#34;,&#xA;      &#34;description&#34;: &#34;A heap-based buffer overflow was found in Vim in the ins_compl_add function in the insexpand.c file. This issue occurs due to a read past the end of a buffer when a specially crafted input is processed. This flaw allows an attacker who can trick a user into opening a specially crafted file into triggering the heap-based buffer overflow, causing the application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-07-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2343 https://bugzilla.redhat.com/show_bug.cgi?id=2106779 https://www.cve.org/CVERecord?id=CVE-2022-2343 https://nvd.nist.gov/vuln/detail/CVE-2022-2343 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2343.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MMLwOzBcCET4jaa3dPuTwQ==&#34;: {&#xA;      &#34;id&#34;: &#34;MMLwOzBcCET4jaa3dPuTwQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-38533&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in the strip utility of binutils. An attacker able to convince a victim to process a specially crafted COFF file by the strip utility can lead to a heap-based buffer overflow, causing the utility to crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-13T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-38533 https://bugzilla.redhat.com/show_bug.cgi?id=2124569 https://www.cve.org/CVERecord?id=CVE-2022-38533 https://nvd.nist.gov/vuln/detail/CVE-2022-38533 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-38533.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MS/0MdicPKEzcrADakYBYA==&#34;: {&#xA;      &#34;id&#34;: &#34;MS/0MdicPKEzcrADakYBYA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4437&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4437 https://bugzilla.redhat.com/show_bug.cgi?id=2449777 https://www.cve.org/CVERecord?id=CVE-2026-4437 https://nvd.nist.gov/vuln/detail/CVE-2026-4437 https://sourceware.org/bugzilla/show_bug.cgi?id=34014 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4437.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MZUC9kv5PI1Xlt1QOYz1SQ==&#34;: {&#xA;      &#34;id&#34;: &#34;MZUC9kv5PI1Xlt1QOYz1SQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34180&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34180 https://bugzilla.redhat.com/show_bug.cgi?id=2481881 https://www.cve.org/CVERecord?id=CVE-2026-34180 https://nvd.nist.gov/vuln/detail/CVE-2026-34180 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34180.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MciappbjqbiRE2dg7PbMSg==&#34;: {&#xA;      &#34;id&#34;: &#34;MciappbjqbiRE2dg7PbMSg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48933&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48933 https://bugzilla.redhat.com/show_bug.cgi?id=2493331 https://www.cve.org/CVERecord?id=CVE-2026-48933 https://nvd.nist.gov/vuln/detail/CVE-2026-48933 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MdEybCUhVKCoyI/dXRvNlA==&#34;: {&#xA;      &#34;id&#34;: &#34;MdEybCUhVKCoyI/dXRvNlA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14104&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1913&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libfdisk&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.37.4-21.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MqEiWiJF+vNoM9tbeG6KSw==&#34;: {&#xA;      &#34;id&#34;: &#34;MqEiWiJF+vNoM9tbeG6KSw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MrkZWekwMOpCZnSllV83tw==&#34;: {&#xA;      &#34;id&#34;: &#34;MrkZWekwMOpCZnSllV83tw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:37:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;MtOwgWyogkVoNGuQavHN8g==&#34;: {&#xA;      &#34;id&#34;: &#34;MtOwgWyogkVoNGuQavHN8g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22801&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng, a reference library for PNG (Portable Network Graphics) raster image files. An integer truncation vulnerability exists in the png_write_image_16bit and png_write_image_8bit simplified write API functions. A local attacker could exploit this flaw by providing a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes, leading to a heap buffer over-read. This can result in information disclosure or a denial of service (DoS) to the system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-12T22:57:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22801 https://bugzilla.redhat.com/show_bug.cgi?id=2428824 https://www.cve.org/CVERecord?id=CVE-2026-22801 https://nvd.nist.gov/vuln/detail/CVE-2026-22801 https://github.com/pnggroup/libpng/security/advisories/GHSA-vgjq-8cw5-ggw8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22801.json https://access.redhat.com/errata/RHSA-2026:3405&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;N5EbMRV7FNySo/Sn3CmU+w==&#34;: {&#xA;      &#34;id&#34;: &#34;N5EbMRV7FNySo/Sn3CmU+w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11525&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. When undici processes Set-Cookie headers, it incorrectly interprets the SameSite attribute, accepting partial matches instead of exact ones. This allows a malicious server to downgrade a cookie&#39;s SameSite policy to a less secure setting, potentially leading to unintended information disclosure or a weakening of security protections for the user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:31:03Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11525 https://bugzilla.redhat.com/show_bug.cgi?id=2490008 https://www.cve.org/CVERecord?id=CVE-2026-11525 https://nvd.nist.gov/vuln/detail/CVE-2026-11525 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11525.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;N6nQdxnBzns6IrsJM+Xsuw==&#34;: {&#xA;      &#34;id&#34;: &#34;N6nQdxnBzns6IrsJM+Xsuw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-json&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.7.2-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;N6zpVUumTTQTvmCVOXvHPQ==&#34;: {&#xA;      &#34;id&#34;: &#34;N6zpVUumTTQTvmCVOXvHPQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21710&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request that includes a header named `__proto__`. When a Node.js application processes this request and attempts to access distinct headers, it encounters an unhandled error, leading to an application crash. This can result in a Denial of Service (DoS), making the affected service unavailable to users.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T19:07:28Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21710 https://bugzilla.redhat.com/show_bug.cgi?id=2453151 https://www.cve.org/CVERecord?id=CVE-2026-21710 https://nvd.nist.gov/vuln/detail/CVE-2026-21710 https://nodejs.org/en/blog/vulnerability/march-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21710.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;N9dwh+Df2etJCiT3zY4CJw==&#34;: {&#xA;      &#34;id&#34;: &#34;N9dwh+Df2etJCiT3zY4CJw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-10911&#34;,&#xA;      &#34;description&#34;: &#34;A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-08-04T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-10911 https://bugzilla.redhat.com/show_bug.cgi?id=2397838 https://www.cve.org/CVERecord?id=CVE-2025-10911 https://nvd.nist.gov/vuln/detail/CVE-2025-10911 https://gitlab.gnome.org/GNOME/libxslt/-/issues/144 https://gitlab.gnome.org/GNOME/libxslt/-/merge_requests/77 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-10911.json https://access.redhat.com/errata/RHSA-2026:28243&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxslt&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.1.34-14.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;NF/ewEROjeKYjnb1lHH2iw==&#34;: {&#xA;      &#34;id&#34;: &#34;NF/ewEROjeKYjnb1lHH2iw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34183&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL&#39;s QUIC PATH_CHALLENGE handler. A remote attacker can exploit this vulnerability by flooding a QUIC client or server with specially crafted PATH_CHALLENGE frames. This leads to unbounded memory allocation within the local QUIC stack, as the system continuously allocates PATH_RESPONSE frames without them being acknowledged. The primary consequence is a Denial of Service (DoS), causing the affected application to terminate abnormally due to memory exhaustion.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34183 https://bugzilla.redhat.com/show_bug.cgi?id=2481885 https://www.cve.org/CVERecord?id=CVE-2026-34183 https://nvd.nist.gov/vuln/detail/CVE-2026-34183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34183.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;NHJdq5G883S5W8foR85U2A==&#34;: {&#xA;      &#34;id&#34;: &#34;NHJdq5G883S5W8foR85U2A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-61726&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the net/url package in the Go standard library. The package does not enforce a limit on the number of unique query parameters it parses. A Go application using the net/http.Request.ParseForm method will try to process all parameters provided in the request. A specially crafted HTTP request containing a massive number of query parameters will cause the application to consume an excessive amount of memory, eventually causing the application to crash or become unresponsive, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-28T19:30:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-61726 https://bugzilla.redhat.com/show_bug.cgi?id=2434432 https://www.cve.org/CVERecord?id=CVE-2025-61726 https://nvd.nist.gov/vuln/detail/CVE-2025-61726 https://go.dev/cl/736712 https://go.dev/issue/77101 https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc https://pkg.go.dev/vuln/GO-2026-4341 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json https://access.redhat.com/errata/RHSA-2026:3668&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;go-srpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.6.0-13.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;NKSXZUie8BGH5nwjKc1B6A==&#34;: {&#xA;      &#34;id&#34;: &#34;NKSXZUie8BGH5nwjKc1B6A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55132&#34;,&#xA;      &#34;description&#34;: &#34;A file access flaw has been discovered in NodeJS. A file&#39;s access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55132 https://bugzilla.redhat.com/show_bug.cgi?id=2431338 https://www.cve.org/CVERecord?id=CVE-2025-55132 https://nvd.nist.gov/vuln/detail/CVE-2025-55132 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55132.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.4-1.22.22.0.1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;NXO5f9Vv38zu/sOzuqBB9Q==&#34;: {&#xA;      &#34;id&#34;: &#34;NXO5f9Vv38zu/sOzuqBB9Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1525&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici, a Node.js HTTP/1.1 client. A remote attacker could exploit this vulnerability by sending HTTP/1.1 requests that include duplicate Content-Length headers with different casing (e.g., \&#34;Content-Length\&#34; and \&#34;content-length\&#34;). This can lead to HTTP Request Smuggling, a technique where an attacker sends an ambiguous request that is interpreted differently by a proxy and a backend server. Successful exploitation could result in unauthorized access, cache poisoning, or credential hijacking. It may also cause a Denial of Service (DoS) if strict HTTP parsers reject the malformed requests.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T19:56:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1525 https://bugzilla.redhat.com/show_bug.cgi?id=2447144 https://www.cve.org/CVERecord?id=CVE-2026-1525 https://nvd.nist.gov/vuln/detail/CVE-2026-1525 https://cna.openjsf.org/security-advisories.html https://cwe.mitre.org/data/definitions/444.html https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm https://hackerone.com/reports/3556037 https://www.rfc-editor.org/rfc/rfc9110.html#section-8.6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1525.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;NeZAaBfGrzLvaMKrJL7WlA==&#34;: {&#xA;      &#34;id&#34;: &#34;NeZAaBfGrzLvaMKrJL7WlA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-45306&#34;,&#xA;      &#34;description&#34;: &#34;A heap-buffer overflow was found in Vim. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that the cursor position always points inside a line and does not become invalid by pointing beyond the end of a line. It was assumed that this loop was unnecessary. However, this change made it possible for the cursor position to stay invalid and point beyond the end of a line, which would eventually cause a heap-buffer-overflow when trying to access the line pointer at the specified cursor position.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-09-02T18:15:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-45306 https://bugzilla.redhat.com/show_bug.cgi?id=2309275 https://www.cve.org/CVERecord?id=CVE-2024-45306 https://nvd.nist.gov/vuln/detail/CVE-2024-45306 https://github.com/vim/vim/commit/396fd1ec2956307755392a1 https://github.com/vim/vim/releases/tag/v9.1.0038 https://github.com/vim/vim/security/advisories/GHSA-wxf9-c5gx-qrwr https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-45306.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;NfiEOtFyxMslIq3QwoTtjQ==&#34;: {&#xA;      &#34;id&#34;: &#34;NfiEOtFyxMslIq3QwoTtjQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59874&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:23:47Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59874 https://bugzilla.redhat.com/show_bug.cgi?id=2498116 https://www.cve.org/CVERecord?id=CVE-2026-59874 https://nvd.nist.gov/vuln/detail/CVE-2026-59874 https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59874.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Nh6DgKTo1EEcTUg+VgZK9Q==&#34;: {&#xA;      &#34;id&#34;: &#34;Nh6DgKTo1EEcTUg+VgZK9Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48934&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48934 https://bugzilla.redhat.com/show_bug.cgi?id=2493332 https://www.cve.org/CVERecord?id=CVE-2026-48934 https://nvd.nist.gov/vuln/detail/CVE-2026-48934 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48934.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;NrATYvL+2i2gY4ol+szT+g==&#34;: {&#xA;      &#34;id&#34;: &#34;NrATYvL+2i2gY4ol+szT+g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48934&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48934 https://bugzilla.redhat.com/show_bug.cgi?id=2493332 https://www.cve.org/CVERecord?id=CVE-2026-48934 https://nvd.nist.gov/vuln/detail/CVE-2026-48934 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48934.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;NrNei+pIM0R36v4Js8XxAg==&#34;: {&#xA;      &#34;id&#34;: &#34;NrNei+pIM0R36v4Js8XxAg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35387&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows the system to use unintended Elliptic Curve Digital Signature Algorithm (ECDSA) algorithms. This occurs because the configuration for accepted public key algorithms is misinterpreted, leading to the use of weaker cryptographic methods than intended. This could potentially allow an attacker to compromise the confidentiality of data.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:52:53Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35387 https://bugzilla.redhat.com/show_bug.cgi?id=2454494 https://www.cve.org/CVERecord?id=CVE-2026-35387 https://nvd.nist.gov/vuln/detail/CVE-2026-35387 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35387.json https://access.redhat.com/errata/RHSA-2026:13381&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-49.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;NrTzMmbWyM5UeSvnQVNLOg==&#34;: {&#xA;      &#34;id&#34;: &#34;NrTzMmbWyM5UeSvnQVNLOg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0988&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-15T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0988 https://bugzilla.redhat.com/show_bug.cgi?id=2429886 https://www.cve.org/CVERecord?id=CVE-2026-0988 https://nvd.nist.gov/vuln/detail/CVE-2026-0988 https://gitlab.gnome.org/GNOME/glib/-/issues/3851 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0988.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;NxJdA8sdmOpi2KE8EaPazA==&#34;: {&#xA;      &#34;id&#34;: &#34;NxJdA8sdmOpi2KE8EaPazA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-default-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;O+92Gg/bs8C9EjretuiP8A==&#34;: {&#xA;      &#34;id&#34;: &#34;O+92Gg/bs8C9EjretuiP8A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-55653&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-22T23:17:43Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-55653 https://bugzilla.redhat.com/show_bug.cgi?id=2462351 https://www.cve.org/CVERecord?id=CVE-2026-55653 https://nvd.nist.gov/vuln/detail/CVE-2026-55653 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55653.json https://access.redhat.com/errata/RHSA-2026:47756&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-9.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;O3XylFvGObsPmzTrCuhV8A==&#34;: {&#xA;      &#34;id&#34;: &#34;O3XylFvGObsPmzTrCuhV8A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-14164&#34;,&#xA;      &#34;description&#34;: &#34;A double free issue has been identified in libarchive&#39;s RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-24T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-14164 https://bugzilla.redhat.com/show_bug.cgi?id=2493411 https://www.cve.org/CVERecord?id=CVE-2026-14164 https://nvd.nist.gov/vuln/detail/CVE-2026-14164 https://github.com/libarchive/libarchive/issues/3069 https://github.com/libarchive/libarchive/pull/3071 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14164.json https://access.redhat.com/errata/RHSA-2026:52674&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.3-11.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;O912x64ev1faikrIaaOp6w==&#34;: {&#xA;      &#34;id&#34;: &#34;O912x64ev1faikrIaaOp6w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9678&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Undici. The cache interceptor in shared-cache mode incorrectly classifies certain responses as cacheable due to improper handling of whitespace-padded Cache-Control header field names. This vulnerability allows an unauthenticated attacker to access authenticated user data from the cache, leading to information disclosure. This occurs when both authenticated and unauthenticated requests resolve to the same cache key.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:04:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9678 https://bugzilla.redhat.com/show_bug.cgi?id=2490000 https://www.cve.org/CVERecord?id=CVE-2026-9678 https://nvd.nist.gov/vuln/detail/CVE-2026-9678 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9678.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;OB+gdUis8HhIN+YuJZ0d3w==&#34;: {&#xA;      &#34;id&#34;: &#34;OB+gdUis8HhIN+YuJZ0d3w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6733&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici&#39;s HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:14:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6733 https://bugzilla.redhat.com/show_bug.cgi?id=2490006 https://www.cve.org/CVERecord?id=CVE-2026-6733 https://nvd.nist.gov/vuln/detail/CVE-2026-6733 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 https://hackerone.com/reports/3582376 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6733.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;OXJFeTFLsi8lSYgzBz58BA==&#34;: {&#xA;      &#34;id&#34;: &#34;OXJFeTFLsi8lSYgzBz58BA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-12151&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T16:05:38Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-12151 https://bugzilla.redhat.com/show_bug.cgi?id=2489980 https://www.cve.org/CVERecord?id=CVE-2026-12151 https://nvd.nist.gov/vuln/detail/CVE-2026-12151 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;OXr+UvfSDAQbLGP4xOBSMw==&#34;: {&#xA;      &#34;id&#34;: &#34;OXr+UvfSDAQbLGP4xOBSMw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-1127&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. A division by zero in the scrolldown function may lead to a denial of service, modified memory, and possibly remote execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-03-01T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-1127 https://bugzilla.redhat.com/show_bug.cgi?id=2174662 https://www.cve.org/CVERecord?id=CVE-2023-1127 https://nvd.nist.gov/vuln/detail/CVE-2023-1127 https://huntr.dev/bounties/2d4d309e-4c96-415f-9070-36d0815f1beb https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1127.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;OZs5l4RWFkhsw7PWdRXzZg==&#34;: {&#xA;      &#34;id&#34;: &#34;OZs5l4RWFkhsw7PWdRXzZg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:37:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-locale-source&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;OaLF1hM9BwMPMfYWn9kNEA==&#34;: {&#xA;      &#34;id&#34;: &#34;OaLF1hM9BwMPMfYWn9kNEA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-3479&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python&#39;s `pkgutil.get_data()` function, which is used to retrieve data from packages. This function did not properly validate the `resource` argument, allowing a local attacker to perform path traversal attacks. Path traversal enables an attacker to access files and directories stored outside the intended root directory, potentially leading to information disclosure or unintended file access.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-18T18:13:42Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-3479 https://bugzilla.redhat.com/show_bug.cgi?id=2448746 https://www.cve.org/CVERecord?id=CVE-2026-3479 https://nvd.nist.gov/vuln/detail/CVE-2026-3479 https://github.com/python/cpython/issues/146121 https://github.com/python/cpython/pull/146122 https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3479.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Ob+LJ5zYHnbjt14Yf8W7UA==&#34;: {&#xA;      &#34;id&#34;: &#34;Ob+LJ5zYHnbjt14Yf8W7UA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3016&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free vulnerability was found in vim&#39;s get_next_valid_entry() function of the src/quickfix.c file. The issue occurs because vim is using freed memory when the location list is changed in autocmd. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap use-after-free that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-28T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3016 https://bugzilla.redhat.com/show_bug.cgi?id=2124208 https://www.cve.org/CVERecord?id=CVE-2022-3016 https://nvd.nist.gov/vuln/detail/CVE-2022-3016 https://huntr.dev/bounties/260516c2-5c4a-4b7f-a01c-04b1aeeea371 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3016.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;OwBRDeukhCJw3hE9ZsCdCg==&#34;: {&#xA;      &#34;id&#34;: &#34;OwBRDeukhCJw3hE9ZsCdCg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35386&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows a remote attacker to achieve arbitrary command execution by injecting shell metacharacters into a username provided on the command line. Exploitation requires an untrusted username and a non-default configuration of the &#39;%&#39; character in `ssh_config`.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:44:27Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35386 https://bugzilla.redhat.com/show_bug.cgi?id=2454506 https://www.cve.org/CVERecord?id=CVE-2026-35386 https://nvd.nist.gov/vuln/detail/CVE-2026-35386 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35386.json https://access.redhat.com/errata/RHSA-2026:19219&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;P0gqeMXeqGecgv5yzB/trQ==&#34;: {&#xA;      &#34;id&#34;: &#34;P0gqeMXeqGecgv5yzB/trQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27904&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in minimatch. A remote attacker could exploit this vulnerability by providing a specially crafted glob expression with nested unbounded quantifiers. This could lead to catastrophic backtracking in the V8 JavaScript engine, causing the application to become unresponsive and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-26T01:07:42Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27904 https://bugzilla.redhat.com/show_bug.cgi?id=2442922 https://www.cve.org/CVERecord?id=CVE-2026-27904 https://nvd.nist.gov/vuln/detail/CVE-2026-27904 https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27904.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;P8nRZINGxkoETGXvn0vWdQ==&#34;: {&#xA;      &#34;id&#34;: &#34;P8nRZINGxkoETGXvn0vWdQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1528&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a specially crafted WebSocket frame with an extremely large 64-bit length. This causes undici&#39;s ByteParser to overflow its internal calculations, leading to an invalid state and a fatal TypeError. The primary consequence is a Denial of Service (DoS), which terminates the process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:21:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1528 https://bugzilla.redhat.com/show_bug.cgi?id=2447145 https://www.cve.org/CVERecord?id=CVE-2026-1528 https://nvd.nist.gov/vuln/detail/CVE-2026-1528 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj https://hackerone.com/reports/3537648 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1528.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;PAKBAYCAtIg8PKEYWQkTzQ==&#34;: {&#xA;      &#34;id&#34;: &#34;PAKBAYCAtIg8PKEYWQkTzQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-59465&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in NodeJS. A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-59465 https://bugzilla.redhat.com/show_bug.cgi?id=2431349 https://www.cve.org/CVERecord?id=CVE-2025-59465 https://nvd.nist.gov/vuln/detail/CVE-2025-59465 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59465.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.4-1.22.22.0.1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;PAegHDN7lb4f5q+9sjv8sQ==&#34;: {&#xA;      &#34;id&#34;: &#34;PAegHDN7lb4f5q+9sjv8sQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-12610&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T12:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-12610 https://bugzilla.redhat.com/show_bug.cgi?id=2490288 https://www.cve.org/CVERecord?id=CVE-2026-12610 https://nvd.nist.gov/vuln/detail/CVE-2026-12610 https://github.com/SSSD/sssd/issues/8796 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12610.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pam&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;PD08BQc1tUldC8QSScd1aA==&#34;: {&#xA;      &#34;id&#34;: &#34;PD08BQc1tUldC8QSScd1aA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-60002&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. A remote attacker could exploit a use-after-free vulnerability on the client side when a server changes its host key during a key re-exchange. This could lead to high impact on confidentiality and integrity, and low impact on availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T00:17:33Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-60002 https://bugzilla.redhat.com/show_bug.cgi?id=2497936 https://www.cve.org/CVERecord?id=CVE-2026-60002 https://nvd.nist.gov/vuln/detail/CVE-2026-60002 https://marc.info/?l=openssh-unix-dev\u0026m=178333966933090\u0026w=2 https://www.openssh.org/releasenotes.html#10.4p1 https://www.openwall.com/lists/oss-security/2026/07/06/5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-60002.json https://access.redhat.com/errata/RHSA-2026:47756&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-9.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;PInmzCd2elAZed8XII2H3A==&#34;: {&#xA;      &#34;id&#34;: &#34;PInmzCd2elAZed8XII2H3A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48619&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. A malicious server can exploit the HTTP/2 client by sending an unlimited number of ORIGIN frames. This can lead to an Out of Memory error on the client, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48619 https://bugzilla.redhat.com/show_bug.cgi?id=2493325 https://www.cve.org/CVERecord?id=CVE-2026-48619 https://nvd.nist.gov/vuln/detail/CVE-2026-48619 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48619.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;PX5l1wv6H6/jl5nGaxFp+w==&#34;: {&#xA;      &#34;id&#34;: &#34;PX5l1wv6H6/jl5nGaxFp+w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bigdecimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.1.5-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Pi9su0FguY3j1GBpXhwKIA==&#34;: {&#xA;      &#34;id&#34;: &#34;Pi9su0FguY3j1GBpXhwKIA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9678&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Undici. The cache interceptor in shared-cache mode incorrectly classifies certain responses as cacheable due to improper handling of whitespace-padded Cache-Control header field names. This vulnerability allows an unauthenticated attacker to access authenticated user data from the cache, leading to information disclosure. This occurs when both authenticated and unauthenticated requests resolve to the same cache key.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:04:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9678 https://bugzilla.redhat.com/show_bug.cgi?id=2490000 https://www.cve.org/CVERecord?id=CVE-2026-9678 https://nvd.nist.gov/vuln/detail/CVE-2026-9678 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9678.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Pml3cIw2PYIOjBurBs3LFQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Pml3cIw2PYIOjBurBs3LFQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;PqOWZHQu7W9hh0UlnMkHAQ==&#34;: {&#xA;      &#34;id&#34;: &#34;PqOWZHQu7W9hh0UlnMkHAQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69646&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. A local attacker can exploit this vulnerability by supplying a malicious input file containing malformed DWARF debug_rnglists data. This can cause the objdump tool to enter an unbounded logging loop, leading to excessive CPU and I/O usage and preventing analysis completion. This issue results in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69646 https://bugzilla.redhat.com/show_bug.cgi?id=2445264 https://www.cve.org/CVERecord?id=CVE-2025-69646 https://nvd.nist.gov/vuln/detail/CVE-2025-69646 https://sourceware.org/bugzilla/show_bug.cgi?id=33638 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69646.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;PvgbBaq86gnOp8hffKEHhQ==&#34;: {&#xA;      &#34;id&#34;: &#34;PvgbBaq86gnOp8hffKEHhQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35385&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. When the `scp` command is used by a root user to download a file with the legacy protocol option (`-O`) and without preserving original file permissions (`-p`), the downloaded file can be installed with elevated privileges (setuid or setgid). This unexpected behavior could allow a malicious file to execute with higher permissions than intended, posing a security risk through potential privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:30:59Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35385 https://bugzilla.redhat.com/show_bug.cgi?id=2454469 https://www.cve.org/CVERecord?id=CVE-2026-35385 https://nvd.nist.gov/vuln/detail/CVE-2026-35385 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35385.json https://access.redhat.com/errata/RHSA-2026:13381&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-49.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Py++HyN8+aNZZa9dPe2rDQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Py++HyN8+aNZZa9dPe2rDQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69420&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A type confusion vulnerability exists in the TimeStamp Response verification code, where an ASN1_TYPE union member is accessed without proper type validation. A remote attacker can exploit this by providing a malformed TimeStamp Response to an application that verifies timestamp responses. This can lead to an invalid or NULL pointer dereference, resulting in a Denial of Service (DoS) due to an application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69420 https://bugzilla.redhat.com/show_bug.cgi?id=2430388 https://www.cve.org/CVERecord?id=CVE-2025-69420 https://nvd.nist.gov/vuln/detail/CVE-2025-69420 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69420.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Pza9Y2xtH9MChVMkZwgw2A==&#34;: {&#xA;      &#34;id&#34;: &#34;Pza9Y2xtH9MChVMkZwgw2A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-7264&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcurl, where libcurl&#39;s ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the length of the *time fraction*, leading to a `strlen()` performed on a pointer to a heap buffer area that is not purposely NULL terminated.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-07-31T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-7264 https://bugzilla.redhat.com/show_bug.cgi?id=2301888 https://www.cve.org/CVERecord?id=CVE-2024-7264 https://nvd.nist.gov/vuln/detail/CVE-2024-7264 https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-7264.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Q0D37bmhhLGtYILIAMgFXg==&#34;: {&#xA;      &#34;id&#34;: &#34;Q0D37bmhhLGtYILIAMgFXg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2207&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2207 https://bugzilla.redhat.com/show_bug.cgi?id=2102185 https://www.cve.org/CVERecord?id=CVE-2022-2207 https://nvd.nist.gov/vuln/detail/CVE-2022-2207 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2207.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Q2616MMrHflQbREkbaxMFg==&#34;: {&#xA;      &#34;id&#34;: &#34;Q2616MMrHflQbREkbaxMFg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-44656&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open-source command-line text editor. An attacker who controls the contents of a file can exploit an OS command injection vulnerability in Vim&#39;s `:find` command-line completion. This occurs when the `path` option, which can be set from a modeline, contains backtick-enclosed shell commands. These commands are then executed when a user opens the malicious file and triggers `:find` completion, leading to arbitrary command execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-08T22:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-44656 https://bugzilla.redhat.com/show_bug.cgi?id=2468420 https://www.cve.org/CVERecord?id=CVE-2026-44656 https://nvd.nist.gov/vuln/detail/CVE-2026-44656 https://github.com/vim/vim/commit/190cb3c2b9c769a3972bcfd991a7b5b6cb771ef0 https://github.com/vim/vim/releases/tag/v9.2.0435 https://github.com/vim/vim/security/advisories/GHSA-hwg5-3cxw-wvvg https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44656.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Q2JaEcNprQzczHwEGMbXgA==&#34;: {&#xA;      &#34;id&#34;: &#34;Q2JaEcNprQzczHwEGMbXgA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-12151&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T16:05:38Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-12151 https://bugzilla.redhat.com/show_bug.cgi?id=2489980 https://www.cve.org/CVERecord?id=CVE-2026-12151 https://nvd.nist.gov/vuln/detail/CVE-2026-12151 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Q6H4f5u2pbj98wlSQQLoGg==&#34;: {&#xA;      &#34;id&#34;: &#34;Q6H4f5u2pbj98wlSQQLoGg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-57451&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Vim allows an attacker to cause a Denial of Service (DoS) via an application crash. If a user opens a maliciously crafted undo file, an out-of-bounds read is triggered in the get_text_props() function due to missing length validation on property counts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-25T15:28:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-57451 https://bugzilla.redhat.com/show_bug.cgi?id=2492978 https://www.cve.org/CVERecord?id=CVE-2026-57451 https://nvd.nist.gov/vuln/detail/CVE-2026-57451 https://github.com/vim/vim/commit/b2338ca90643e2f01ecb6547c1172716aaec4f79 https://github.com/vim/vim/releases/tag/v9.2.0670 https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57451.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QG/MLFKQxQOk84kYcs5X4A==&#34;: {&#xA;      &#34;id&#34;: &#34;QG/MLFKQxQOk84kYcs5X4A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22695&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng, a reference library for processing PNG (Portable Network Graphics) image files. A local attacker could exploit a heap buffer over-read vulnerability in the `png_image_finish_read` function by tricking a user into processing a specially crafted interlaced 16-bit PNG file with an 8-bit output format and non-minimal row stride. This could lead to a denial of service (DoS) and potentially information disclosure.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-12T22:55:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22695 https://bugzilla.redhat.com/show_bug.cgi?id=2428825 https://www.cve.org/CVERecord?id=CVE-2026-22695 https://nvd.nist.gov/vuln/detail/CVE-2026-22695 https://github.com/pnggroup/libpng/commit/218612ddd6b17944e21eda56caf8b4bf7779d1ea https://github.com/pnggroup/libpng/commit/e4f7ad4ea2 https://github.com/pnggroup/libpng/issues/778 https://github.com/pnggroup/libpng/security/advisories/GHSA-mmq5-27w3-rxpp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22695.json https://access.redhat.com/errata/RHSA-2026:3405&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QNrS4atSfp1tFVuWE/Cnqg==&#34;: {&#xA;      &#34;id&#34;: &#34;QNrS4atSfp1tFVuWE/Cnqg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4775&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-24T14:33:35Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4775 https://bugzilla.redhat.com/show_bug.cgi?id=2450768 https://www.cve.org/CVERecord?id=CVE-2026-4775 https://nvd.nist.gov/vuln/detail/CVE-2026-4775 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4775.json https://access.redhat.com/errata/RHSA-2026:12271&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtiff&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:4.4.0-15.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QOF3F7DIkILMx0gIrkLxgw==&#34;: {&#xA;      &#34;id&#34;: &#34;QOF3F7DIkILMx0gIrkLxgw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21710&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request that includes a header named `__proto__`. When a Node.js application processes this request and attempts to access distinct headers, it encounters an unhandled error, leading to an application crash. This can result in a Denial of Service (DoS), making the affected service unavailable to users.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T19:07:28Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21710 https://bugzilla.redhat.com/show_bug.cgi?id=2453151 https://www.cve.org/CVERecord?id=CVE-2026-21710 https://nvd.nist.gov/vuln/detail/CVE-2026-21710 https://nodejs.org/en/blog/vulnerability/march-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21710.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QX9gQ7esz1e73iQHmwojXA==&#34;: {&#xA;      &#34;id&#34;: &#34;QX9gQ7esz1e73iQHmwojXA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-3973&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. A possible heap-based buffer overflow could allow an attacker to input a specially crafted file leading to a crash or code execution. The highest threat from this vulnerability is to system availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-11-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-3973 https://bugzilla.redhat.com/show_bug.cgi?id=2025059 https://www.cve.org/CVERecord?id=CVE-2021-3973 https://nvd.nist.gov/vuln/detail/CVE-2021-3973 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-3973.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QZ+YDQI7XEpbDFIIv4hUIw==&#34;: {&#xA;      &#34;id&#34;: &#34;QZ+YDQI7XEpbDFIIv4hUIw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-29111&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-23T21:03:56Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-29111 https://bugzilla.redhat.com/show_bug.cgi?id=2450505 https://www.cve.org/CVERecord?id=CVE-2026-29111 https://nvd.nist.gov/vuln/detail/CVE-2026-29111 https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6 https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8 https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29111.json https://access.redhat.com/errata/RHSA-2026:19213&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-67.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QZ8ts+eZBnwTfp8wZbfpwg==&#34;: {&#xA;      &#34;id&#34;: &#34;QZ8ts+eZBnwTfp8wZbfpwg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42014&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42014 https://bugzilla.redhat.com/show_bug.cgi?id=2467451 https://www.cve.org/CVERecord?id=CVE-2026-42014 https://nvd.nist.gov/vuln/detail/CVE-2026-42014 https://gitlab.com/gnutls/gnutls/-/issues/1766 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-9 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42014.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QaKFgrY/cUPl6Ls/xAwlFQ==&#34;: {&#xA;      &#34;id&#34;: &#34;QaKFgrY/cUPl6Ls/xAwlFQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11495&#34;,&#xA;      &#34;description&#34;: &#34;A heap based buffer overflow flaw has been discovered in the GNU Binutils package. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-08T20:02:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11495 https://bugzilla.redhat.com/show_bug.cgi?id=2402584 https://www.cve.org/CVERecord?id=CVE-2025-11495 https://nvd.nist.gov/vuln/detail/CVE-2025-11495 https://sourceware.org/bugzilla/attachment.cgi?id=16393 https://sourceware.org/bugzilla/show_bug.cgi?id=33502 https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0 https://vuldb.com/?ctiid.327620 https://vuldb.com/?id.327620 https://vuldb.com/?submit.668290 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11495.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QbgvVzhz2dr5BDvAUM6wFQ==&#34;: {&#xA;      &#34;id&#34;: &#34;QbgvVzhz2dr5BDvAUM6wFQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2304&#34;,&#xA;      &#34;description&#34;: &#34;A stack-based buffer overflow vulnerability was found in Vim&#39;s spell_dump_compl() function of the src/spell.c file. This issue occurs because the spell dump goes beyond the end of an array when crafted input is processed. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering an out-of-bounds write that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-07-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2304 https://bugzilla.redhat.com/show_bug.cgi?id=2104416 https://www.cve.org/CVERecord?id=CVE-2022-2304 https://nvd.nist.gov/vuln/detail/CVE-2022-2304 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2304.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Qe1reyLPtQVZ5wKqKa9jQA==&#34;: {&#xA;      &#34;id&#34;: &#34;Qe1reyLPtQVZ5wKqKa9jQA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-0213&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim.  The vulnerability occurs due to not checking the length for the NameBuff function, which can lead to a heap buffer overflow. This flaw allows an attacker to input a specially crafted file, leading to a crash or code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-01-12T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-0213 https://bugzilla.redhat.com/show_bug.cgi?id=2043779 https://www.cve.org/CVERecord?id=CVE-2022-0213 https://nvd.nist.gov/vuln/detail/CVE-2022-0213 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-0213.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QgRg8usqYLpC2SzTmhUKsQ==&#34;: {&#xA;      &#34;id&#34;: &#34;QgRg8usqYLpC2SzTmhUKsQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-22134&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. Due to Vim not properly terminating visual mode, a heap buffer overflow condition may be triggered when a user switches buffers using the `:all` command. This issue may lead to unexpected behavior, such as an application crash or memory corruption.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-01-13T20:41:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-22134 https://bugzilla.redhat.com/show_bug.cgi?id=2337437 https://www.cve.org/CVERecord?id=CVE-2025-22134 https://nvd.nist.gov/vuln/detail/CVE-2025-22134 https://github.com/vim/vim/commit/c9a1e257f1630a0866447e53a564f7ff96a80ead https://github.com/vim/vim/security/advisories/GHSA-5rgf-26wj-48v8 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22134.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Qi/s8gqjz2kgI+pAtQ5t9w==&#34;: {&#xA;      &#34;id&#34;: &#34;Qi/s8gqjz2kgI+pAtQ5t9w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6733&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici&#39;s HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:14:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6733 https://bugzilla.redhat.com/show_bug.cgi?id=2490006 https://www.cve.org/CVERecord?id=CVE-2026-6733 https://nvd.nist.gov/vuln/detail/CVE-2026-6733 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 https://hackerone.com/reports/3582376 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6733.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QmXO38HGjUD9lc3XwducGg==&#34;: {&#xA;      &#34;id&#34;: &#34;QmXO38HGjUD9lc3XwducGg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42338&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user&#39;s browser.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-12T19:43:16Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42338 https://bugzilla.redhat.com/show_bug.cgi?id=2476810 https://www.cve.org/CVERecord?id=CVE-2026-42338 https://nvd.nist.gov/vuln/detail/CVE-2026-42338 https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Qmv/HFfBCKuu6eMPjatnfw==&#34;: {&#xA;      &#34;id&#34;: &#34;Qmv/HFfBCKuu6eMPjatnfw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14104&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1913&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux-core&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.37.4-21.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QpRZEOKvwJh9R+ZiKkkeqQ==&#34;: {&#xA;      &#34;id&#34;: &#34;QpRZEOKvwJh9R+ZiKkkeqQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66293&#34;,&#xA;      &#34;description&#34;: &#34;An out of bounds read vulnerability has been discovered in libpng. This vulnerability is in libpng&#39;s simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng&#39;s internal state management.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-03T20:33:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66293 https://bugzilla.redhat.com/show_bug.cgi?id=2418711 https://www.cve.org/CVERecord?id=CVE-2025-66293 https://nvd.nist.gov/vuln/detail/CVE-2025-66293 https://github.com/pnggroup/libpng/commit/788a624d7387a758ffd5c7ab010f1870dea753a1 https://github.com/pnggroup/libpng/commit/a05a48b756de63e3234ea6b3b938b8f5f862484a https://github.com/pnggroup/libpng/issues/764 https://github.com/pnggroup/libpng/security/advisories/GHSA-9mpm-9pxh-mg4f https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66293.json https://access.redhat.com/errata/RHSA-2026:0238&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;QskDoDnTSvrQeDXklM4YOw==&#34;: {&#xA;      &#34;id&#34;: &#34;QskDoDnTSvrQeDXklM4YOw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4105&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-13T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4105 https://bugzilla.redhat.com/show_bug.cgi?id=2447262 https://www.cve.org/CVERecord?id=CVE-2026-4105 https://nvd.nist.gov/vuln/detail/CVE-2026-4105 https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4105.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Qvh4esOhPMDkhhNZaEzAtg==&#34;: {&#xA;      &#34;id&#34;: &#34;Qvh4esOhPMDkhhNZaEzAtg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1526&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A remote attacker can exploit this vulnerability by sending a specially crafted compressed frame, known as a \&#34;decompression bomb,\&#34; during permessage-deflate decompression. The undici WebSocket client does not properly limit the size of decompressed data, leading to unbounded memory consumption. This can cause the Node.js process to exhaust available memory, resulting in a denial of service (DoS) where the process crashes or becomes unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:08:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1526 https://bugzilla.redhat.com/show_bug.cgi?id=2447142 https://www.cve.org/CVERecord?id=CVE-2026-1526 https://nvd.nist.gov/vuln/detail/CVE-2026-1526 https://cna.openjsf.org/security-advisories.html https://datatracker.ietf.org/doc/html/rfc7692 https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q https://hackerone.com/reports/3481206 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1526.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Qvw0/zOlMy3n6XUCrN6SmQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Qvw0/zOlMy3n6XUCrN6SmQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42338&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user&#39;s browser.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-12T19:43:16Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42338 https://bugzilla.redhat.com/show_bug.cgi?id=2476810 https://www.cve.org/CVERecord?id=CVE-2026-42338 https://nvd.nist.gov/vuln/detail/CVE-2026-42338 https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;R1x4adkbkgVhxc9hzgUZcA==&#34;: {&#xA;      &#34;id&#34;: &#34;R1x4adkbkgVhxc9hzgUZcA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-25260&#34;,&#xA;      &#34;description&#34;: &#34;A NULL pointer dereference vulnerability in the elfutils library has been discovered. This vulnerability occurs within the handle_verdef() function in the readelf.c source file. A NULL pointer dereference typically happens when a program attempts to access memory using a pointer that is not pointing anywhere (i.e., it&#39;s NULL), leading to a crash or potentially exploitable behavior.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-02-20T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-25260 https://bugzilla.redhat.com/show_bug.cgi?id=2265194 https://www.cve.org/CVERecord?id=CVE-2024-25260 https://nvd.nist.gov/vuln/detail/CVE-2024-25260 https://github.com/schsiung/fuzzer_issues/issues/1 https://sourceware.org/bugzilla/show_bug.cgi?id=31058 https://sourceware.org/elfutils/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-25260.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;elfutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;R5XnexvMFgBiw/v8sY0BOA==&#34;: {&#xA;      &#34;id&#34;: &#34;R5XnexvMFgBiw/v8sY0BOA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-40553&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gawk. A buffer overflow vulnerability exists in the `ftype()` routine, located in the `extension/readdir.c` program file. This vulnerability could allow an attacker to crash the program, resulting in a denial of service. It may also potentially lead to arbitrary code execution, though this has not been definitively confirmed.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-13T12:07:56Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-40553 https://bugzilla.redhat.com/show_bug.cgi?id=2499657 https://www.cve.org/CVERecord?id=CVE-2026-40553 https://nvd.nist.gov/vuln/detail/CVE-2026-40553 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40553.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gawk&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;R7olSy1x/HelcHgr9AjG7A==&#34;: {&#xA;      &#34;id&#34;: &#34;R7olSy1x/HelcHgr9AjG7A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-26996&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in minimatch. A remote attacker could exploit this Regular Expression Denial of Service (ReDoS) vulnerability by providing a specially crafted glob pattern. This pattern, containing numerous consecutive wildcard characters, causes excessive processing and exponential backtracking in the regular expression engine. Successful exploitation leads to a Denial of Service (DoS), making the application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-20T03:05:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-26996 https://bugzilla.redhat.com/show_bug.cgi?id=2441268 https://www.cve.org/CVERecord?id=CVE-2026-26996 https://nvd.nist.gov/vuln/detail/CVE-2026-26996 https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5 https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26996.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RARCK1i4HMZsevzlwavFtw==&#34;: {&#xA;      &#34;id&#34;: &#34;RARCK1i4HMZsevzlwavFtw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42015&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42015 https://bugzilla.redhat.com/show_bug.cgi?id=2467678 https://www.cve.org/CVERecord?id=CVE-2026-42015 https://nvd.nist.gov/vuln/detail/CVE-2026-42015 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-11 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42015.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RATpPhLUqjEbe+XxyYxOOw==&#34;: {&#xA;      &#34;id&#34;: &#34;RATpPhLUqjEbe+XxyYxOOw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2257&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim, which is vulnerable to an out-of-bounds read in the msg_outtrans_special function. This flaw allows a specially crafted file to crash software or execute code when opened in vim.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-30T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2257 https://bugzilla.redhat.com/show_bug.cgi?id=2103133 https://www.cve.org/CVERecord?id=CVE-2022-2257 https://nvd.nist.gov/vuln/detail/CVE-2022-2257 https://huntr.dev/bounties/ca581f80-03ba-472a-b820-78f7fd05fe89/ https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2257.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RBuf8b62KyhEUrkIKRG/3A==&#34;: {&#xA;      &#34;id&#34;: &#34;RBuf8b62KyhEUrkIKRG/3A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RCLRHWzoL8kWcamW6v1E6w==&#34;: {&#xA;      &#34;id&#34;: &#34;RCLRHWzoL8kWcamW6v1E6w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-57452&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open source command-line text editor. When opening a specially crafted encrypted file using the VimCrypt~04! or VimCrypt~05! methods, an attacker could trigger an unsigned length calculation error. This issue leads to an out-of-bounds read, causing Vim to crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-25T15:27:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-57452 https://bugzilla.redhat.com/show_bug.cgi?id=2492979 https://www.cve.org/CVERecord?id=CVE-2026-57452 https://nvd.nist.gov/vuln/detail/CVE-2026-57452 https://github.com/vim/vim/commit/c8777cec25dcfae89c42e9aff51af61f71c5745f https://github.com/vim/vim/releases/tag/v9.2.0671 https://github.com/vim/vim/security/advisories/GHSA-c4j9-wr9j-4486 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57452.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RHShqbO2hqcBNPYbKDg/3A==&#34;: {&#xA;      &#34;id&#34;: &#34;RHShqbO2hqcBNPYbKDg/3A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6732&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6732 https://bugzilla.redhat.com/show_bug.cgi?id=2461300 https://www.cve.org/CVERecord?id=CVE-2026-6732 https://nvd.nist.gov/vuln/detail/CVE-2026-6732 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097 https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6732.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RI2wKrfD1EyE3/UfHBEmcA==&#34;: {&#xA;      &#34;id&#34;: &#34;RI2wKrfD1EyE3/UfHBEmcA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42338&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user&#39;s browser.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-12T19:43:16Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42338 https://bugzilla.redhat.com/show_bug.cgi?id=2476810 https://www.cve.org/CVERecord?id=CVE-2026-42338 https://nvd.nist.gov/vuln/detail/CVE-2026-42338 https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RNhf6Q4lLrEWcaxYFUvj7A==&#34;: {&#xA;      &#34;id&#34;: &#34;RNhf6Q4lLrEWcaxYFUvj7A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-43618&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in rsync. An authenticated daemon peer can exploit an integer overflow vulnerability in the compressed-token decoder. By carefully manipulating the compressed-token, a malicious sender can trigger an overflow, leading to remote memory disclosure. This allows an attacker to leak sensitive process memory contents, including environment variables, passwords, and memory pointers, which significantly weakens Address Space Layout Randomization (ASLR) and can facilitate further exploitation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-20T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-43618 https://bugzilla.redhat.com/show_bug.cgi?id=2469054 https://www.cve.org/CVERecord?id=CVE-2026-43618 https://nvd.nist.gov/vuln/detail/CVE-2026-43618 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43618.json https://access.redhat.com/errata/RHSA-2026:26410&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.2.5-7.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RPAl+kgiy/xyZ/LXXbemyw==&#34;: {&#xA;      &#34;id&#34;: &#34;RPAl+kgiy/xyZ/LXXbemyw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4438&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4438 https://bugzilla.redhat.com/show_bug.cgi?id=2449783 https://www.cve.org/CVERecord?id=CVE-2026-4438 https://nvd.nist.gov/vuln/detail/CVE-2026-4438 https://sourceware.org/bugzilla/show_bug.cgi?id=34015 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4438.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-locale-source&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RRtBD+EuTLmzasgAaBJyZw==&#34;: {&#xA;      &#34;id&#34;: &#34;RRtBD+EuTLmzasgAaBJyZw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11081&#34;,&#xA;      &#34;description&#34;: &#34;An out of bounds read flaw has been discovered in GNU bin utilities. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-27T22:02:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11081 https://bugzilla.redhat.com/show_bug.cgi?id=2399944 https://www.cve.org/CVERecord?id=CVE-2025-11081 https://nvd.nist.gov/vuln/detail/CVE-2025-11081 https://github.com/user-attachments/files/20623354/hdf5_crash_3.txt https://sourceware.org/bugzilla/show_bug.cgi?id=33406 https://sourceware.org/bugzilla/show_bug.cgi?id=33406#c2 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f87a66db645caf8cc0e6fc87b0c28c78a38af59b https://vuldb.com/?ctiid.326122 https://vuldb.com/?id.326122 https://vuldb.com/?submit.661275 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11081.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RbYTnX5KpMQtsQJE/xjcFA==&#34;: {&#xA;      &#34;id&#34;: &#34;RbYTnX5KpMQtsQJE/xjcFA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Rd2hVVbUws+mcvoC7DaoiQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Rd2hVVbUws+mcvoC7DaoiQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-4292&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free flaw was found in Vim&#39;s did_set_spelllang() function of the spell.c file. This issue occurs because vim uses freed memory after SpellFileMissing autocmd uses bwipe. This could allows an attacker to trick a user into opening a specially crafted file, triggering a heap use-after-free issue that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-12-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-4292 https://bugzilla.redhat.com/show_bug.cgi?id=2151558 https://www.cve.org/CVERecord?id=CVE-2022-4292 https://nvd.nist.gov/vuln/detail/CVE-2022-4292 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-4292.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Rd6dUUcujScJTEeiIRkyqw==&#34;: {&#xA;      &#34;id&#34;: &#34;Rd6dUUcujScJTEeiIRkyqw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4519&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python. The `webbrowser.open()` API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T15:08:32Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4519 https://bugzilla.redhat.com/show_bug.cgi?id=2449649 https://www.cve.org/CVERecord?id=CVE-2026-4519 https://nvd.nist.gov/vuln/detail/CVE-2026-4519 https://github.com/python/cpython/issues/143930 https://github.com/python/cpython/pull/143931 https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4519.json https://access.redhat.com/errata/RHSA-2026:6766&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RiAwHTFYpWhzZETb+CSE0Q==&#34;: {&#xA;      &#34;id&#34;: &#34;RiAwHTFYpWhzZETb+CSE0Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21710&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request that includes a header named `__proto__`. When a Node.js application processes this request and attempts to access distinct headers, it encounters an unhandled error, leading to an application crash. This can result in a Denial of Service (DoS), making the affected service unavailable to users.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T19:07:28Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21710 https://bugzilla.redhat.com/show_bug.cgi?id=2453151 https://www.cve.org/CVERecord?id=CVE-2026-21710 https://nvd.nist.gov/vuln/detail/CVE-2026-21710 https://nodejs.org/en/blog/vulnerability/march-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21710.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Rk5ia3x816rxtSUtbpOMnw==&#34;: {&#xA;      &#34;id&#34;: &#34;Rk5ia3x816rxtSUtbpOMnw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-18839&#34;,&#xA;      &#34;description&#34;: &#34;An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-08-05T18:56:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-18839 https://bugzilla.redhat.com/show_bug.cgi?id=2511010 https://www.cve.org/CVERecord?id=CVE-2026-18839 https://nvd.nist.gov/vuln/detail/CVE-2026-18839 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18839.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;popt&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RoQvxPrgcpXyTej834bT2Q==&#34;: {&#xA;      &#34;id&#34;: &#34;RoQvxPrgcpXyTej834bT2Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-57360&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the nm utility of binutils. A local user who specifies the `--without-symbol-versions` option on a specially crafted ELF file can trigger a segmentation fault condition. This may lead to an application crash or other undefined behavior.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-01-21T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-57360 https://bugzilla.redhat.com/show_bug.cgi?id=2339263 https://www.cve.org/CVERecord?id=CVE-2024-57360 https://nvd.nist.gov/vuln/detail/CVE-2024-57360 https://sourceware.org/bugzilla/show_bug.cgi?id=32467 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-57360.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Rrms4yDDctk9MqbL4wHXYA==&#34;: {&#xA;      &#34;id&#34;: &#34;Rrms4yDDctk9MqbL4wHXYA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11972&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Python `tarfile` module. When processing a specially crafted tar archive opened in &#39;streaming mode&#39; (mode=&#39;r|&#39;), the module does not properly handle the end-of-file (EOF) condition. This can cause the `tarfile` module to enter an infinite loop, leading to a Denial of Service (DoS) for applications processing such archives.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-23T22:02:45Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11972 https://bugzilla.redhat.com/show_bug.cgi?id=2492050 https://www.cve.org/CVERecord?id=CVE-2026-11972 https://nvd.nist.gov/vuln/detail/CVE-2026-11972 https://github.com/python/cpython/issues/151981 https://github.com/python/cpython/pull/151982 https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11972.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RxiYxX3H5lL8cc7k0ac/mQ==&#34;: {&#xA;      &#34;id&#34;: &#34;RxiYxX3H5lL8cc7k0ac/mQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-4516&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability has been identified in CPython&#39;s bytes.decode() function when used with the \&#34;unicode_escape\&#34; encoding and the \&#34;ignore\&#34; or \&#34;replace\&#34; error handling modes. This flaw can result in the incorrect decoding of byte strings. While this may not directly lead to traditional security breaches like data exfiltration, the resulting unexpected program behavior could introduce instability, logic errors, or unintended side effects within applications that rely on this specific decoding functionality.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-15T13:29:20Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-4516 https://bugzilla.redhat.com/show_bug.cgi?id=2366509 https://www.cve.org/CVERecord?id=CVE-2025-4516 https://nvd.nist.gov/vuln/detail/CVE-2025-4516 https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142 https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e https://github.com/python/cpython/issues/133767 https://github.com/python/cpython/pull/129648 https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4516.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;RzrQmVvfhyaExSlpoLqDzg==&#34;: {&#xA;      &#34;id&#34;: &#34;RzrQmVvfhyaExSlpoLqDzg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55130&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55130 https://bugzilla.redhat.com/show_bug.cgi?id=2431352 https://www.cve.org/CVERecord?id=CVE-2025-55130 https://nvd.nist.gov/vuln/detail/CVE-2025-55130 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55130.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;S0PFhlHzk3DOoPuq+7jmPA==&#34;: {&#xA;      &#34;id&#34;: &#34;S0PFhlHzk3DOoPuq+7jmPA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-8932&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. The libcurl library, used for transferring data with URLs, could improperly reuse existing network connections. This occurred even when changes to mutual Transport Layer Security (mTLS) settings, particularly those for client certificates, should have prevented such reuse. This issue could lead to a security feature bypass, where a client might use a connection with an unintended or weaker security configuration, potentially compromising the integrity or confidentiality of data.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-03T06:16:30Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-8932 https://bugzilla.redhat.com/show_bug.cgi?id=2496759 https://www.cve.org/CVERecord?id=CVE-2026-8932 https://nvd.nist.gov/vuln/detail/CVE-2026-8932 https://curl.se/docs/CVE-2026-8932.html https://curl.se/docs/CVE-2026-8932.json https://hackerone.com/reports/3733910 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8932.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;S1vpC2/S8eBK717462wBrQ==&#34;: {&#xA;      &#34;id&#34;: &#34;S1vpC2/S8eBK717462wBrQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bundler&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.5.22-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;S5Dzz9cigoJDCj8s5UcT0g==&#34;: {&#xA;      &#34;id&#34;: &#34;S5Dzz9cigoJDCj8s5UcT0g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-41409&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-07-18T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-41409 https://bugzilla.redhat.com/show_bug.cgi?id=2260814 https://www.cve.org/CVERecord?id=CVE-2022-41409 https://nvd.nist.gov/vuln/detail/CVE-2022-41409 https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35 https://github.com/PCRE2Project/pcre2/issues/141 https://github.com/advisories/GHSA-4qfx-v7wh-3q4j https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-41409.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pcre2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;SC1Dy3taETcbAxJ5m5vXqQ==&#34;: {&#xA;      &#34;id&#34;: &#34;SC1Dy3taETcbAxJ5m5vXqQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27904&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in minimatch. A remote attacker could exploit this vulnerability by providing a specially crafted glob expression with nested unbounded quantifiers. This could lead to catastrophic backtracking in the V8 JavaScript engine, causing the application to become unresponsive and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-26T01:07:42Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27904 https://bugzilla.redhat.com/show_bug.cgi?id=2442922 https://www.cve.org/CVERecord?id=CVE-2026-27904 https://nvd.nist.gov/vuln/detail/CVE-2026-27904 https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27904.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;SGI/AkdUGrhS5bQBrDpzJg==&#34;: {&#xA;      &#34;id&#34;: &#34;SGI/AkdUGrhS5bQBrDpzJg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42307&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim’s netrw plugin. Improper sanitization of specially crafted filenames or URLs could allow shell metacharacters to be included in temporary filenames passed to external commands. A local attacker could exploit this issue to trigger unintended shell command execution when a user opens malicious content using affected netrw functionality.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-08T22:38:53Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42307 https://bugzilla.redhat.com/show_bug.cgi?id=2468403 https://www.cve.org/CVERecord?id=CVE-2026-42307 https://nvd.nist.gov/vuln/detail/CVE-2026-42307 https://github.com/vim/vim/commit/405e2fb6d54d5653523809e2853d99d1c000a5fc https://github.com/vim/vim/releases/tag/v9.2.0383 https://github.com/vim/vim/security/advisories/GHSA-85ch-p2qr-m5gx https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42307.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;SGRK/IsCkjX097oRuDhiEQ==&#34;: {&#xA;      &#34;id&#34;: &#34;SGRK/IsCkjX097oRuDhiEQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-6170&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-06-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-6170 https://bugzilla.redhat.com/show_bug.cgi?id=2372952 https://www.cve.org/CVERecord?id=CVE-2025-6170 https://nvd.nist.gov/vuln/detail/CVE-2025-6170 https://gitlab.gnome.org/GNOME/libxml2/-/issues/941 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6170.json https://access.redhat.com/errata/RHSA-2026:39317&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.9.13-14.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;SH2AP7i0ZzGmFbD1kuJsew==&#34;: {&#xA;      &#34;id&#34;: &#34;SH2AP7i0ZzGmFbD1kuJsew==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-73281&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH&#39;s `ssh-agent` component. A misinteraction between agent locking and the `session-bind@openssh.com` extension allows operations intended for local execution to be performed remotely. This could enable a remote attacker to add PKCS#11 tokens or utilize keys with destination restrictions, bypassing intended security controls.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-08-11T19:10:33Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-73281 https://bugzilla.redhat.com/show_bug.cgi?id=2514327 https://www.cve.org/CVERecord?id=CVE-2026-73281 https://nvd.nist.gov/vuln/detail/CVE-2026-73281 https://www.openssh.org/releasenotes.html#10.5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73281.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;SIuaHC7QSLhT9Coo7Xm2hA==&#34;: {&#xA;      &#34;id&#34;: &#34;SIuaHC7QSLhT9Coo7Xm2hA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48928 https://bugzilla.redhat.com/show_bug.cgi?id=2493333 https://www.cve.org/CVERecord?id=CVE-2026-48928 https://nvd.nist.gov/vuln/detail/CVE-2026-48928 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48928.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;SJA+1v6mehbGh4JXJ2n5jA==&#34;: {&#xA;      &#34;id&#34;: &#34;SJA+1v6mehbGh4JXJ2n5jA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22695&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng, a reference library for processing PNG (Portable Network Graphics) image files. A local attacker could exploit a heap buffer over-read vulnerability in the `png_image_finish_read` function by tricking a user into processing a specially crafted interlaced 16-bit PNG file with an 8-bit output format and non-minimal row stride. This could lead to a denial of service (DoS) and potentially information disclosure.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-12T22:55:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22695 https://bugzilla.redhat.com/show_bug.cgi?id=2428825 https://www.cve.org/CVERecord?id=CVE-2026-22695 https://nvd.nist.gov/vuln/detail/CVE-2026-22695 https://github.com/pnggroup/libpng/commit/218612ddd6b17944e21eda56caf8b4bf7779d1ea https://github.com/pnggroup/libpng/commit/e4f7ad4ea2 https://github.com/pnggroup/libpng/issues/778 https://github.com/pnggroup/libpng/security/advisories/GHSA-mmq5-27w3-rxpp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22695.json https://access.redhat.com/errata/RHSA-2026:3405&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;SQcVquEPU3fE4fDQPb3bLQ==&#34;: {&#xA;      &#34;id&#34;: &#34;SQcVquEPU3fE4fDQPb3bLQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-24515&#34;,&#xA;      &#34;description&#34;: &#34;A null pointer dereference flaw has been discovered in libexpat. The function `XML_ExternalEntityParserCreate` failed to copy the encoding handler data passed to XML_SetUnknownEncodingHandler from the parent to the new subparser. This can cause a NULL dereference from external entities that declare use of an unknown encoding. The expected impact is denial of service. It takes use of both functions `XML_ExternalEntityParserCreate` and `XML_SetUnknownEncodingHandler` for an application to be vulnerable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-23T07:46:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-24515 https://bugzilla.redhat.com/show_bug.cgi?id=2432312 https://www.cve.org/CVERecord?id=CVE-2026-24515 https://nvd.nist.gov/vuln/detail/CVE-2026-24515 https://github.com/libexpat/libexpat/pull/1131 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24515.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ST+HmAso4vf4Hnu6TuBXXQ==&#34;: {&#xA;      &#34;id&#34;: &#34;ST+HmAso4vf4Hnu6TuBXXQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-12818&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability has been identified in PostgreSQL’s libpq client library, where integer wraparound in several allocation-size calculations allows a peer or input provider to cause an undersized buffer and then write out-of-bounds by hundreds of megabytes. This can lead to a client application segmentation fault or crash when using libpq to connect to a PostgreSQL server.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-13T13:00:12Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-12818 https://bugzilla.redhat.com/show_bug.cgi?id=2414826 https://www.cve.org/CVERecord?id=CVE-2025-12818 https://nvd.nist.gov/vuln/detail/CVE-2025-12818 https://www.postgresql.org/support/security/CVE-2025-12818/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-12818.json https://access.redhat.com/errata/RHSA-2026:0458&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpq&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:13.23-1.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ScOp6HuJxBp54FxFpTVDnA==&#34;: {&#xA;      &#34;id&#34;: &#34;ScOp6HuJxBp54FxFpTVDnA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-25645&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the `requests` HTTP library, specifically in the `requests.utils.extract_zipped_paths()` function, which is used to load Certificate Authority (CA) bundles. A local attacker can exploit this vulnerability by pre-creating a malicious CA bundle file in the system&#39;s temporary directory. When a vulnerable application initializes the `requests` library, it may load this malicious file instead of the legitimate CA bundle, leading to a bypass of security controls and potential integrity compromise.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-25T17:02:48Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-25645 https://bugzilla.redhat.com/show_bug.cgi?id=2451408 https://www.cve.org/CVERecord?id=CVE-2026-25645 https://nvd.nist.gov/vuln/detail/CVE-2026-25645 https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7 https://github.com/psf/requests/releases/tag/v2.33.0 https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25645.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-pip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;SdlHZBjfHlAbNa/I1YXwQA==&#34;: {&#xA;      &#34;id&#34;: &#34;SdlHZBjfHlAbNa/I1YXwQA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-10158&#34;,&#xA;      &#34;description&#34;: &#34;An out of bounds read flaw has been discovered in rsync. A malicious client acting as the receiver of an rsync file transfer can trigger an OOB read via a negative array index. The rsync client requires at least read access to the remote rsync module to trigger the issue.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-18T14:24:19Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-10158 https://bugzilla.redhat.com/show_bug.cgi?id=2415637 https://www.cve.org/CVERecord?id=CVE-2025-10158 https://nvd.nist.gov/vuln/detail/CVE-2025-10158 https://attackerkb.com/assessments/fbacb2a6-d1cd-4011-bb3a-f06b1c8306b1 https://github.com/RsyncProject/rsync/commit/797e17fc4a6f15e3b1756538a9f812b63942686f https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-10158.json https://access.redhat.com/errata/RHSA-2026:6390&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.2.5-3.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;SfJy5i/9nh3s5fpZxZDQCg==&#34;: {&#xA;      &#34;id&#34;: &#34;SfJy5i/9nh3s5fpZxZDQCg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4786&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Python webbrowser.open() API. If a specially crafted URL containing \&#34;%action\&#34; is processed, an attacker could bypass a previous mitigation for CVE-2026-4519. This bypass allows for command injection into the underlying shell, potentially leading to arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-13T21:52:19Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4786 https://bugzilla.redhat.com/show_bug.cgi?id=2458049 https://www.cve.org/CVERecord?id=CVE-2026-4786 https://nvd.nist.gov/vuln/detail/CVE-2026-4786 https://github.com/python/cpython/issues/148169 https://github.com/python/cpython/pull/148170 https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4786.json https://access.redhat.com/errata/RHSA-2026:10949&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;SvhQ7tNvl6ANrVnaJ4cBNw==&#34;: {&#xA;      &#34;id&#34;: &#34;SvhQ7tNvl6ANrVnaJ4cBNw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3099&#34;,&#xA;      &#34;description&#34;: &#34;A use-after-free vulnerability was found in vim&#39;s do_cmdline() function of the src/ex_docmd.c file. The issue triggers when an invalid line number on :for is ignored. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering use-after-free that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-03T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3099 https://bugzilla.redhat.com/show_bug.cgi?id=2124157 https://www.cve.org/CVERecord?id=CVE-2022-3099 https://nvd.nist.gov/vuln/detail/CVE-2022-3099 https://huntr.dev/bounties/403210c7-6cc7-4874-8934-b57f88bd4f5e https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3099.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Sygyk9+T2DbXETLWiB21dA==&#34;: {&#xA;      &#34;id&#34;: &#34;Sygyk9+T2DbXETLWiB21dA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rdoc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:6.6.3.1-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;T+jfDhqJcXwVQ38oWEz/6g==&#34;: {&#xA;      &#34;id&#34;: &#34;T+jfDhqJcXwVQ38oWEz/6g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14104&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1913&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libsmartcols&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.37.4-21.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;T1g7X8ESyY5xnqSayytC4w==&#34;: {&#xA;      &#34;id&#34;: &#34;T1g7X8ESyY5xnqSayytC4w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-56391&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GNU coreutils uniq. When processing specially crafted multibyte input with the --check-chars option, an attacker can trigger an out-of-bounds read. This vulnerability can lead to a denial of service (DoS) due to an application crash and potentially expose sensitive information from adjacent memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-24T07:44:45Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-56391 https://bugzilla.redhat.com/show_bug.cgi?id=2506691 https://www.cve.org/CVERecord?id=CVE-2026-56391 https://nvd.nist.gov/vuln/detail/CVE-2026-56391 https://cert.pl/en/posts/2026/07/CVE-2026-56391 https://git.savannah.gnu.org/cgit/coreutils.git/ https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56391.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;coreutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;T5Nghm4crNWWnUrYvZZItg==&#34;: {&#xA;      &#34;id&#34;: &#34;T5Nghm4crNWWnUrYvZZItg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2124&#34;,&#xA;      &#34;description&#34;: &#34;Buffer Over-read in GitHub repository vim/vim prior to 8.2.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2124 https://bugzilla.redhat.com/show_bug.cgi?id=2099558 https://www.cve.org/CVERecord?id=CVE-2022-2124 https://nvd.nist.gov/vuln/detail/CVE-2022-2124 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2124.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;T76LK9MUa3lwsxSAw540ZA==&#34;: {&#xA;      &#34;id&#34;: &#34;T76LK9MUa3lwsxSAw540ZA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9678&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Undici. The cache interceptor in shared-cache mode incorrectly classifies certain responses as cacheable due to improper handling of whitespace-padded Cache-Control header field names. This vulnerability allows an unauthenticated attacker to access authenticated user data from the cache, leading to information disclosure. This occurs when both authenticated and unauthenticated requests resolve to the same cache key.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:04:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9678 https://bugzilla.redhat.com/show_bug.cgi?id=2490000 https://www.cve.org/CVERecord?id=CVE-2026-9678 https://nvd.nist.gov/vuln/detail/CVE-2026-9678 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9678.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;T7eVCD5Gwe0DXPZP59mQUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;T7eVCD5Gwe0DXPZP59mQUQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48928 https://bugzilla.redhat.com/show_bug.cgi?id=2493333 https://www.cve.org/CVERecord?id=CVE-2026-48928 https://nvd.nist.gov/vuln/detail/CVE-2026-48928 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48928.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TFhgbPsd17URo8rNJh9SWQ==&#34;: {&#xA;      &#34;id&#34;: &#34;TFhgbPsd17URo8rNJh9SWQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42767&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. An attacker controlling a Certificate Management Protocol (CMP) server, or acting as a man-in-the-middle, could craft a malicious CMP response. This response, containing a Certificate Request Message Format (CRMF) CertRepMessage with a specific malformed EncryptedValue structure, would trigger a NULL pointer dereference in the OpenSSL CMP client. This vulnerability leads to a crash of the application, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42767 https://bugzilla.redhat.com/show_bug.cgi?id=2481891 https://www.cve.org/CVERecord?id=CVE-2026-42767 https://nvd.nist.gov/vuln/detail/CVE-2026-42767 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42767.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TIcWaTRsDD52irGN4xUQyA==&#34;: {&#xA;      &#34;id&#34;: &#34;TIcWaTRsDD52irGN4xUQyA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2125&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2125 https://bugzilla.redhat.com/show_bug.cgi?id=2099590 https://www.cve.org/CVERecord?id=CVE-2022-2125 https://nvd.nist.gov/vuln/detail/CVE-2022-2125 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2125.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TL19l7Dr/wLwmp6malQ4FQ==&#34;: {&#xA;      &#34;id&#34;: &#34;TL19l7Dr/wLwmp6malQ4FQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48619&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. A malicious server can exploit the HTTP/2 client by sending an unlimited number of ORIGIN frames. This can lead to an Out of Memory error on the client, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48619 https://bugzilla.redhat.com/show_bug.cgi?id=2493325 https://www.cve.org/CVERecord?id=CVE-2026-48619 https://nvd.nist.gov/vuln/detail/CVE-2026-48619 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48619.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TSYnGqVe9WLIg9cR9McW7A==&#34;: {&#xA;      &#34;id&#34;: &#34;TSYnGqVe9WLIg9cR9McW7A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59873&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:22:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59873 https://bugzilla.redhat.com/show_bug.cgi?id=2498120 https://www.cve.org/CVERecord?id=CVE-2026-59873 https://nvd.nist.gov/vuln/detail/CVE-2026-59873 https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3 https://github.com/isaacs/node-tar/releases/tag/v7.5.19 https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59873.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TT6ujth4uzblGI4VcnKBOw==&#34;: {&#xA;      &#34;id&#34;: &#34;TT6ujth4uzblGI4VcnKBOw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-12084&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in cpython. This vulnerability allows impacted availability via a quadratic algorithm in `xml.dom.minidom` methods, such as `appendChild()`, when building excessively nested documents due to a dependency on `_clear_id_cache()`&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-03T18:55:32Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-12084 https://bugzilla.redhat.com/show_bug.cgi?id=2418655 https://www.cve.org/CVERecord?id=CVE-2025-12084 https://nvd.nist.gov/vuln/detail/CVE-2025-12084 https://github.com/python/cpython/issues/142145 https://github.com/python/cpython/pull/142146 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-12084.json https://access.redhat.com/errata/RHSA-2026:1478&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TZnGp6lc5MuTXKrvF6Ln8Q==&#34;: {&#xA;      &#34;id&#34;: &#34;TZnGp6lc5MuTXKrvF6Ln8Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-26996&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in minimatch. A remote attacker could exploit this Regular Expression Denial of Service (ReDoS) vulnerability by providing a specially crafted glob pattern. This pattern, containing numerous consecutive wildcard characters, causes excessive processing and exponential backtracking in the regular expression engine. Successful exploitation leads to a Denial of Service (DoS), making the application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-20T03:05:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-26996 https://bugzilla.redhat.com/show_bug.cgi?id=2441268 https://www.cve.org/CVERecord?id=CVE-2026-26996 https://nvd.nist.gov/vuln/detail/CVE-2026-26996 https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5 https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26996.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TccjTp2Y8sTyWrjrm24IKA==&#34;: {&#xA;      &#34;id&#34;: &#34;TccjTp2Y8sTyWrjrm24IKA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14104&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1913&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libmount&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.37.4-21.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Teb2ue8GsbLkJUoUyGyGsA==&#34;: {&#xA;      &#34;id&#34;: &#34;Teb2ue8GsbLkJUoUyGyGsA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34180&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34180 https://bugzilla.redhat.com/show_bug.cgi?id=2481881 https://www.cve.org/CVERecord?id=CVE-2026-34180 https://nvd.nist.gov/vuln/detail/CVE-2026-34180 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34180.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Tp2zZ0uvWY7vBbgviQPk7w==&#34;: {&#xA;      &#34;id&#34;: &#34;Tp2zZ0uvWY7vBbgviQPk7w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1526&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A remote attacker can exploit this vulnerability by sending a specially crafted compressed frame, known as a \&#34;decompression bomb,\&#34; during permessage-deflate decompression. The undici WebSocket client does not properly limit the size of decompressed data, leading to unbounded memory consumption. This can cause the Node.js process to exhaust available memory, resulting in a denial of service (DoS) where the process crashes or becomes unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:08:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1526 https://bugzilla.redhat.com/show_bug.cgi?id=2447142 https://www.cve.org/CVERecord?id=CVE-2026-1526 https://nvd.nist.gov/vuln/detail/CVE-2026-1526 https://cna.openjsf.org/security-advisories.html https://datatracker.ietf.org/doc/html/rfc7692 https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q https://hackerone.com/reports/3481206 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1526.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TrnW8DIZgc2e/W4a1+ccJw==&#34;: {&#xA;      &#34;id&#34;: &#34;TrnW8DIZgc2e/W4a1+ccJw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4775&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-24T14:33:35Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4775 https://bugzilla.redhat.com/show_bug.cgi?id=2450768 https://www.cve.org/CVERecord?id=CVE-2026-4775 https://nvd.nist.gov/vuln/detail/CVE-2026-4775 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4775.json https://access.redhat.com/errata/RHSA-2026:19363&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtiff-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:4.4.0-18.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TsVNXuAeF3PhiRZhIOjjtQ==&#34;: {&#xA;      &#34;id&#34;: &#34;TsVNXuAeF3PhiRZhIOjjtQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-50182&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can enable a remote attacker to control the redirect destination, leading to arbitrary URL redirection. Consequently, an attacker can redirect users to malicious websites. This \nvulnerability stems from a failure to constrain the redirect target.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-06-19T01:42:44Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-50182 https://bugzilla.redhat.com/show_bug.cgi?id=2373800 https://www.cve.org/CVERecord?id=CVE-2025-50182 https://nvd.nist.gov/vuln/detail/CVE-2025-50182 https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-50182.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-pip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TvusqX9NwPqfJWjNoF5ThA==&#34;: {&#xA;      &#34;id&#34;: &#34;TvusqX9NwPqfJWjNoF5ThA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42770&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A malicious peer can exploit this vulnerability by presenting a specially crafted DHX (X9.42) peer key. Due to improper validation of the peer key&#39;s subgroup membership, an attacker can recover the victim&#39;s private key after a small number of key exchange attempts. This information disclosure can lead to unauthorized access or further compromise of affected systems.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42770 https://bugzilla.redhat.com/show_bug.cgi?id=2481894 https://www.cve.org/CVERecord?id=CVE-2026-42770 https://nvd.nist.gov/vuln/detail/CVE-2026-42770 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42770.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;TwbA7fBttKRHAyCkVC4IDQ==&#34;: {&#xA;      &#34;id&#34;: &#34;TwbA7fBttKRHAyCkVC4IDQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5450&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:55:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-minimal-langpack&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-272.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;U6rJ6LmaVlYRjI8Lq/aM/A==&#34;: {&#xA;      &#34;id&#34;: &#34;U6rJ6LmaVlYRjI8Lq/aM/A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-58011&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-58011 https://bugzilla.redhat.com/show_bug.cgi?id=2492245 https://www.cve.org/CVERecord?id=CVE-2026-58011 https://nvd.nist.gov/vuln/detail/CVE-2026-58011 https://gitlab.gnome.org/GNOME/glib/-/issues/3917 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58011.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;U8pdHlQlr/x1RsdiZ3YQOg==&#34;: {&#xA;      &#34;id&#34;: &#34;U8pdHlQlr/x1RsdiZ3YQOg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;UBzPfwycyyJOBETwdSTG/w==&#34;: {&#xA;      &#34;id&#34;: &#34;UBzPfwycyyJOBETwdSTG/w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-47814&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. When closing a buffer visible in a window, a `BufWinLeave` auto command can trigger a use-after-free if this auto command happens to reopen the same buffer in a new split window. This issue can potentially cause Vim to crash, leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-10-07T21:16:01Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-47814 https://bugzilla.redhat.com/show_bug.cgi?id=2317096 https://www.cve.org/CVERecord?id=CVE-2024-47814 https://nvd.nist.gov/vuln/detail/CVE-2024-47814 https://github.com/vim/vim/commit/51b62387be93c65fa56bbabe1c3 https://github.com/vim/vim/security/advisories/GHSA-rj48-v4mq-j4vg https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-47814.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;UG+yX6nADJgJWegetH+HQg==&#34;: {&#xA;      &#34;id&#34;: &#34;UG+yX6nADJgJWegetH+HQg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59997&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. The internal-sftp component within sshd incorrectly processes command-line arguments, recognizing only the first nine. This limitation can prevent the application of intended security configurations for SFTP (SSH File Transfer Protocol) connections, potentially leading to a bypass of security properties.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T00:09:04Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59997 https://bugzilla.redhat.com/show_bug.cgi?id=2497929 https://www.cve.org/CVERecord?id=CVE-2026-59997 https://nvd.nist.gov/vuln/detail/CVE-2026-59997 https://marc.info/?l=openssh-unix-dev\u0026m=178333966933090\u0026w=2 https://www.openssh.org/releasenotes.html#10.4p1 https://www.openwall.com/lists/oss-security/2026/07/06/5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59997.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;UIYVfnZoS2Er3ahTNsELrg==&#34;: {&#xA;      &#34;id&#34;: &#34;UIYVfnZoS2Er3ahTNsELrg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48935&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. The Permission API allows a local user to modify file metadata on paths that have been explicitly set as read-only. This can lead to unauthorized changes in file properties, impacting the integrity of the file system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48935 https://bugzilla.redhat.com/show_bug.cgi?id=2493329 https://www.cve.org/CVERecord?id=CVE-2026-48935 https://nvd.nist.gov/vuln/detail/CVE-2026-48935 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48935.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;UL/j2Mi69IC+SfjF07J7rg==&#34;: {&#xA;      &#34;id&#34;: &#34;UL/j2Mi69IC+SfjF07J7rg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-56407&#34;,&#xA;      &#34;description&#34;: &#34;An integer overflow exists in libexpat&#39;s doProlog function due to improper handling of entity value lengths. A local attacker could exploit this to execute arbitrary code or access sensitive system data.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-21T15:49:35Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-56407 https://bugzilla.redhat.com/show_bug.cgi?id=2491184 https://www.cve.org/CVERecord?id=CVE-2026-56407 https://nvd.nist.gov/vuln/detail/CVE-2026-56407 https://github.com/libexpat/libexpat/pull/1262 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56407.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;UUa5vuAfloHekZLBPCTvFQ==&#34;: {&#xA;      &#34;id&#34;: &#34;UUa5vuAfloHekZLBPCTvFQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6238&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T16:43:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-gconv-extra&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;UivJsSMDjJ5Fv8zzjiEyGg==&#34;: {&#xA;      &#34;id&#34;: &#34;UivJsSMDjJ5Fv8zzjiEyGg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5450&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:55:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-locale-source&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-272.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Uk5o/hpaP3fKN3OvrwIC+w==&#34;: {&#xA;      &#34;id&#34;: &#34;Uk5o/hpaP3fKN3OvrwIC+w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-56412&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. This vulnerability, present in versions before 2.8.2, stems from improper handling of XML CDATA sections, where the library fails to adequately track the depth of handler calls. This can result in a &#39;use-after-free&#39; error, a type of memory corruption that could allow an attacker to crash the application or potentially gain unauthorized control.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-21T15:58:59Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-56412 https://bugzilla.redhat.com/show_bug.cgi?id=2491203 https://www.cve.org/CVERecord?id=CVE-2026-56412 https://nvd.nist.gov/vuln/detail/CVE-2026-56412 https://github.com/libexpat/libexpat/pull/1278 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56412.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Ur6VVwVyUIHSLLbySiZhfA==&#34;: {&#xA;      &#34;id&#34;: &#34;Ur6VVwVyUIHSLLbySiZhfA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59996&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH, a widely used tool for secure remote access. When a user attempts to copy files between two different remote systems using the `scp` command, the file might be incorrectly placed in a directory above the intended destination. This unintended file placement could lead to data integrity issues or, in some cases, unauthorized access to sensitive information if files are stored in an exposed location.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T00:07:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59996 https://bugzilla.redhat.com/show_bug.cgi?id=2497944 https://www.cve.org/CVERecord?id=CVE-2026-59996 https://nvd.nist.gov/vuln/detail/CVE-2026-59996 https://marc.info/?l=openssh-unix-dev\u0026m=178333966933090\u0026w=2 https://www.openssh.org/releasenotes.html#10.4p1 https://www.openwall.com/lists/oss-security/2026/07/06/5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59996.json https://access.redhat.com/errata/RHSA-2026:47756&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-9.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;UsEuyAuS2VCokppecP9FXw==&#34;: {&#xA;      &#34;id&#34;: &#34;UsEuyAuS2VCokppecP9FXw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5435&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T11:58:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-headers&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;UwZunDPz4Z/GxKWN3p1+/Q==&#34;: {&#xA;      &#34;id&#34;: &#34;UwZunDPz4Z/GxKWN3p1+/Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-15588&#34;,&#xA;      &#34;description&#34;: &#34;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-12T10:10:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-15588 https://bugzilla.redhat.com/show_bug.cgi?id=2499675 https://www.cve.org/CVERecord?id=CVE-2026-15588 https://nvd.nist.gov/vuln/detail/CVE-2026-15588 https://gitlab.gnome.org/GNOME/glib/-/issues/3985 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15588.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Uwj2IeJYZ6kg0JLABYAJ/Q==&#34;: {&#xA;      &#34;id&#34;: &#34;Uwj2IeJYZ6kg0JLABYAJ/Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33416&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng, a library used for processing PNG (Portable Network Graphics) image files. This vulnerability arises from improper memory management where a heap-allocated buffer is aliased between internal data structures. When specific functions are called, a freed memory region can still be referenced, leading to a use-after-free condition. An attacker could potentially exploit this to achieve arbitrary code execution or cause a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-26T16:48:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33416 https://bugzilla.redhat.com/show_bug.cgi?id=2451805 https://www.cve.org/CVERecord?id=CVE-2026-33416 https://nvd.nist.gov/vuln/detail/CVE-2026-33416 https://github.com/pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb https://github.com/pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667 https://github.com/pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25 https://github.com/pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1 https://github.com/pnggroup/libpng/pull/824 https://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33416.json https://access.redhat.com/errata/RHSA-2026:18028&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.4&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;V1rPWqhvOrQycOtSN8Ve9g==&#34;: {&#xA;      &#34;id&#34;: &#34;V1rPWqhvOrQycOtSN8Ve9g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-bundled-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;V2/vsNJeH5BxrzuVis91/A==&#34;: {&#xA;      &#34;id&#34;: &#34;V2/vsNJeH5BxrzuVis91/A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15282&#34;,&#xA;      &#34;description&#34;: &#34;Missing newline filtering has been discovered in Python. User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:35:13Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15282 https://bugzilla.redhat.com/show_bug.cgi?id=2431366 https://www.cve.org/CVERecord?id=CVE-2025-15282 https://nvd.nist.gov/vuln/detail/CVE-2025-15282 https://github.com/python/cpython/issues/143925 https://github.com/python/cpython/pull/143926 https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15282.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;V8tjixCGBsaAWvQP5Hvn+A==&#34;: {&#xA;      &#34;id&#34;: &#34;V8tjixCGBsaAWvQP5Hvn+A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5713&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python. A malicious Python process could exploit the \&#34;profiling.sampling\&#34; module and \&#34;asyncio introspection capabilities\&#34; to read and write memory addresses within a privileged process. This vulnerability occurs when the privileged process connects to the malicious process via its remote debugging feature, potentially leading to information disclosure and arbitrary code execution. Successful exploitation requires repeated connections, which may cause instability in the connecting process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-14T15:11:51Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5713 https://bugzilla.redhat.com/show_bug.cgi?id=2458239 https://www.cve.org/CVERecord?id=CVE-2026-5713 https://nvd.nist.gov/vuln/detail/CVE-2026-5713 https://github.com/python/cpython/issues/148178 https://github.com/python/cpython/pull/148187 https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5713.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;VHPIyM/Zt8Ma4iUgT7UsMw==&#34;: {&#xA;      &#34;id&#34;: &#34;VHPIyM/Zt8Ma4iUgT7UsMw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45445&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. Applications that use the AES-OCB encryption method with a specific one-shot interface (EVP_Cipher()) will have their provided Initialization Vector (IV) silently discarded. This leads to the same internal cryptographic value being used repeatedly, which compromises the confidentiality of encrypted data. Additionally, this issue allows for the universal forgery of authentication tags, undermining the integrity of communications.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45445 https://bugzilla.redhat.com/show_bug.cgi?id=2481896 https://www.cve.org/CVERecord?id=CVE-2026-45445 https://nvd.nist.gov/vuln/detail/CVE-2026-45445 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45445.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;VJENPcmZwV+YJWnk88f2ug==&#34;: {&#xA;      &#34;id&#34;: &#34;VJENPcmZwV+YJWnk88f2ug==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9149&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-20T22:19:32Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9149 https://bugzilla.redhat.com/show_bug.cgi?id=2460380 https://www.cve.org/CVERecord?id=CVE-2026-9149 https://nvd.nist.gov/vuln/detail/CVE-2026-9149 https://github.com/openSUSE/libsolv/pull/617 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9149.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libsolv&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;VL0JOGDvBKQkxcjlKcpvoA==&#34;: {&#xA;      &#34;id&#34;: &#34;VL0JOGDvBKQkxcjlKcpvoA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-13149&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-30T08:30:34Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-13149 https://bugzilla.redhat.com/show_bug.cgi?id=2494813 https://www.cve.org/CVERecord?id=CVE-2026-13149 https://nvd.nist.gov/vuln/detail/CVE-2026-13149 https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754 https://www.npmjs.com/package/brace-expansion https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;VWEbeFnFOHy1IkG21b5a5g==&#34;: {&#xA;      &#34;id&#34;: &#34;VWEbeFnFOHy1IkG21b5a5g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-30571&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in libarchive. This issue can cause a race condition in a multi-threaded use of archive_write_disk_header() on posix based systems, which could allow implicit directory creation with permissions 777, without sticky bit, which means any low privileged user on the system can delete and rename files inside those directories.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-05-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-30571 https://bugzilla.redhat.com/show_bug.cgi?id=2210921 https://www.cve.org/CVERecord?id=CVE-2023-30571 https://nvd.nist.gov/vuln/detail/CVE-2023-30571 https://access.redhat.com/solutions/7033331 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-30571.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;VYGbkY0i6P3tRJd9mM1wNg==&#34;: {&#xA;      &#34;id&#34;: &#34;VYGbkY0i6P3tRJd9mM1wNg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1489&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1489 https://bugzilla.redhat.com/show_bug.cgi?id=2433348 https://www.cve.org/CVERecord?id=CVE-2026-1489 https://nvd.nist.gov/vuln/detail/CVE-2026-1489 https://gitlab.gnome.org/GNOME/glib/-/issues/3872 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1489.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;VgtQ3XmdoIWt3qbuW7WZzQ==&#34;: {&#xA;      &#34;id&#34;: &#34;VgtQ3XmdoIWt3qbuW7WZzQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55130&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55130 https://bugzilla.redhat.com/show_bug.cgi?id=2431352 https://www.cve.org/CVERecord?id=CVE-2025-55130 https://nvd.nist.gov/vuln/detail/CVE-2025-55130 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55130.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Vm1exr1mz0tcpwIoZQ3ySQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Vm1exr1mz0tcpwIoZQ3ySQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35387&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows the system to use unintended Elliptic Curve Digital Signature Algorithm (ECDSA) algorithms. This occurs because the configuration for accepted public key algorithms is misinterpreted, leading to the use of weaker cryptographic methods than intended. This could potentially allow an attacker to compromise the confidentiality of data.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:52:53Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35387 https://bugzilla.redhat.com/show_bug.cgi?id=2454494 https://www.cve.org/CVERecord?id=CVE-2026-35387 https://nvd.nist.gov/vuln/detail/CVE-2026-35387 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35387.json https://access.redhat.com/errata/RHSA-2026:13381&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-49.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;VpM36keMJ87mG4yZ97wQdw==&#34;: {&#xA;      &#34;id&#34;: &#34;VpM36keMJ87mG4yZ97wQdw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48933&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48933 https://bugzilla.redhat.com/show_bug.cgi?id=2493331 https://www.cve.org/CVERecord?id=CVE-2026-48933 https://nvd.nist.gov/vuln/detail/CVE-2026-48933 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Vt9MtkEoE3rKa0ninTNTkg==&#34;: {&#xA;      &#34;id&#34;: &#34;Vt9MtkEoE3rKa0ninTNTkg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4786&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Python webbrowser.open() API. If a specially crafted URL containing \&#34;%action\&#34; is processed, an attacker could bypass a previous mitigation for CVE-2026-4519. This bypass allows for command injection into the underlying shell, potentially leading to arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-13T21:52:19Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4786 https://bugzilla.redhat.com/show_bug.cgi?id=2458049 https://www.cve.org/CVERecord?id=CVE-2026-4786 https://nvd.nist.gov/vuln/detail/CVE-2026-4786 https://github.com/python/cpython/issues/148169 https://github.com/python/cpython/pull/148170 https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4786.json https://access.redhat.com/errata/RHSA-2026:19216&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;VuDrFzex6yJBFISXUtfUGQ==&#34;: {&#xA;      &#34;id&#34;: &#34;VuDrFzex6yJBFISXUtfUGQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-13462&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the `tarfile` module of cpython. This vulnerability allows a remote attacker to craft a malicious tar archive that, when processed, could be misinterpreted by the `tarfile` module. This misinterpretation occurs because the module incorrectly applies normalization of `AREGTYPE` blocks to `DIRTYPE` during the processing of multi-block members, such as `GNUTYPE_LONGNAME` or `GNUTYPE_LONGLINK`. The consequence is that the `tarfile` module may process the archive differently than intended, potentially leading to unexpected file system changes or data integrity issues.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T17:59:26Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-13462 https://bugzilla.redhat.com/show_bug.cgi?id=2447082 https://www.cve.org/CVERecord?id=CVE-2025-13462 https://nvd.nist.gov/vuln/detail/CVE-2025-13462 https://github.com/python/cpython/issues/141707 https://github.com/python/cpython/pull/143934 https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13462.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;VvaHtDrsl/vKtefhsm7IUA==&#34;: {&#xA;      &#34;id&#34;: &#34;VvaHtDrsl/vKtefhsm7IUA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-io-console&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.7.1-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;VwRZMkFc1pqkTIff/cjZtQ==&#34;: {&#xA;      &#34;id&#34;: &#34;VwRZMkFc1pqkTIff/cjZtQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-6075&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability in Python’s os.path.expandvars() function that can cause performance degradation. When processing specially crafted, user-controlled input with nested environment variable patterns, the function exhibits quadratic time complexity, potentially leading to excessive CPU usage and denial of service (DoS) conditions. No code execution or data exposure occurs, so the impact is limited to performance slowdown.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-31T16:41:34Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-6075 https://bugzilla.redhat.com/show_bug.cgi?id=2408891 https://www.cve.org/CVERecord?id=CVE-2025-6075 https://nvd.nist.gov/vuln/detail/CVE-2025-6075 https://github.com/python/cpython/issues/136065 https://mail.python.org/archives/list/security-announce@python.org/thread/IUP5QJ6D4KK6ULHOMPC7DPNKRYQTQNLA/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6075.json https://access.redhat.com/errata/RHSA-2025:23342&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-2.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;W+GZex0uR6OUn0BnVKDRXQ==&#34;: {&#xA;      &#34;id&#34;: &#34;W+GZex0uR6OUn0BnVKDRXQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5419&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5419 https://bugzilla.redhat.com/show_bug.cgi?id=2467686 https://www.cve.org/CVERecord?id=CVE-2026-5419 https://nvd.nist.gov/vuln/detail/CVE-2026-5419 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5419.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;W/xTZXt8arFxTmTRnfh2+g==&#34;: {&#xA;      &#34;id&#34;: &#34;W/xTZXt8arFxTmTRnfh2+g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4046&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T17:16:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-common&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;W0TAw6aTfwXOMlJwloDkZA==&#34;: {&#xA;      &#34;id&#34;: &#34;W0TAw6aTfwXOMlJwloDkZA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-4136&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. A possible heap-based buffer overflow could allow an attacker to input a specially crafted file leading to a crash or code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-12-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-4136 https://bugzilla.redhat.com/show_bug.cgi?id=2034720 https://www.cve.org/CVERecord?id=CVE-2021-4136 https://nvd.nist.gov/vuln/detail/CVE-2021-4136 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-4136.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;W3SNJz91vyAPBvH2kz/itQ==&#34;: {&#xA;      &#34;id&#34;: &#34;W3SNJz91vyAPBvH2kz/itQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.22-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;W9ATeYhnrC0UlelRIXFecQ==&#34;: {&#xA;      &#34;id&#34;: &#34;W9ATeYhnrC0UlelRIXFecQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6238&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T16:43:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-headers&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;WHfk9C+FqONS5L1MuNtP+g==&#34;: {&#xA;      &#34;id&#34;: &#34;WHfk9C+FqONS5L1MuNtP+g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-54411&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Linux-PAM&#39;s `pam_userdb` module. This vulnerability, categorized as an Observable Timing Discrepancy (CWE-208), allows a local or network-adjacent attacker to recover plaintext passwords. By repeatedly attempting authentication and measuring response-timing differences during plaintext password comparison, an attacker can deduce the password. This flaw is exploitable when the `pam_userdb` module is configured to store and compare credentials in plaintext, which is not a default setting.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-14T17:21:43Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-54411 https://bugzilla.redhat.com/show_bug.cgi?id=2488766 https://www.cve.org/CVERecord?id=CVE-2026-54411 https://nvd.nist.gov/vuln/detail/CVE-2026-54411 https://cwe.mitre.org/data/definitions/208.html https://github.com/linux-pam/linux-pam https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54411.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pam&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;WbtmlW8SfW38NUPRnGwbsA==&#34;: {&#xA;      &#34;id&#34;: &#34;WbtmlW8SfW38NUPRnGwbsA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-bundled-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;WhQSrxicq09HlEU8PxUQSQ==&#34;: {&#xA;      &#34;id&#34;: &#34;WhQSrxicq09HlEU8PxUQSQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15468&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. A remote attacker could trigger a NULL pointer dereference by sending an unknown or unsupported cipher ID during the client hello callback in applications using the QUIC (Quick UDP Internet Connections) protocol. This vulnerability, occurring when the SSL_CIPHER_find() function is called in this specific context, leads to an abnormal termination of the running process, causing a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15468 https://bugzilla.redhat.com/show_bug.cgi?id=2430377 https://www.cve.org/CVERecord?id=CVE-2025-15468 https://nvd.nist.gov/vuln/detail/CVE-2025-15468 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15468.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;WhY0uvyUG/ImjnbaewZftw==&#34;: {&#xA;      &#34;id&#34;: &#34;WhY0uvyUG/ImjnbaewZftw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22796&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a denial of service (DoS) by providing specially crafted PKCS#7 data to an application that performs signature verification. The vulnerability occurs because the application accesses an ASN1_TYPE union member without proper type validation, leading to an invalid or NULL pointer dereference and a crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22796 https://bugzilla.redhat.com/show_bug.cgi?id=2430390 https://www.cve.org/CVERecord?id=CVE-2026-22796 https://nvd.nist.gov/vuln/detail/CVE-2026-22796 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22796.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;WiJ6DYPst5oap7CBdVnD1A==&#34;: {&#xA;      &#34;id&#34;: &#34;WiJ6DYPst5oap7CBdVnD1A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27135&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 frame, leading to an assertion failure and a denial of service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-18T17:59:02Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27135 https://bugzilla.redhat.com/show_bug.cgi?id=2448754 https://www.cve.org/CVERecord?id=CVE-2026-27135 https://nvd.nist.gov/vuln/detail/CVE-2026-27135 https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1 https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;WjQCog+GPmCa3VQIGXKhRg==&#34;: {&#xA;      &#34;id&#34;: &#34;WjQCog+GPmCa3VQIGXKhRg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-58010&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses \u003e instead of \u003e=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-26T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-58010 https://bugzilla.redhat.com/show_bug.cgi?id=2492243 https://www.cve.org/CVERecord?id=CVE-2026-58010 https://nvd.nist.gov/vuln/detail/CVE-2026-58010 https://gitlab.gnome.org/GNOME/glib/-/issues/3915 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58010.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;WwAqpmlCgSYKoG1knafv5A==&#34;: {&#xA;      &#34;id&#34;: &#34;WwAqpmlCgSYKoG1knafv5A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-54370&#34;,&#xA;      &#34;description&#34;: &#34;A time-of-check to time-of-use (TOCTOU) race condition vulnerability was found in `acl`. By replacing a pathname component with a symbolic link between a security check and subsequent file operations, an attacker can redirect file access control list operations. This occurs when privileged processes invoke `getfacl` or `setfacl` over an attacker-controlled path, potentially leading to local privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-29T13:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-54370 https://bugzilla.redhat.com/show_bug.cgi?id=2490279 https://www.cve.org/CVERecord?id=CVE-2026-54370 https://nvd.nist.gov/vuln/detail/CVE-2026-54370 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54370.json https://access.redhat.com/errata/RHSA-2026:42736&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;acl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.4.0-1.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;WywM/OB6w5X8T3BuZ5B9Ow==&#34;: {&#xA;      &#34;id&#34;: &#34;WywM/OB6w5X8T3BuZ5B9Ow==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5450&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:55:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-langpack-en&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-272.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;X10PEbhI2yv6KYFUPacecg==&#34;: {&#xA;      &#34;id&#34;: &#34;X10PEbhI2yv6KYFUPacecg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-1619&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim, which is vulnerable to a heap-buffer-overflow in cmdline_erase_chars of the ex_getln.c function. This flaw allows a specially crafted file to crash software, modify memory or execute code when opened in vim.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-05-08T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-1619 https://bugzilla.redhat.com/show_bug.cgi?id=2083026 https://www.cve.org/CVERecord?id=CVE-2022-1619 https://nvd.nist.gov/vuln/detail/CVE-2022-1619 https://huntr.dev/bounties/b3200483-624e-4c76-a070-e246f62a7450/ https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-1619.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;X4Ym25zfqcH7/samBN+yPw==&#34;: {&#xA;      &#34;id&#34;: &#34;X4Ym25zfqcH7/samBN+yPw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5545&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5545 https://bugzilla.redhat.com/show_bug.cgi?id=2461204 https://www.cve.org/CVERecord?id=CVE-2026-5545 https://nvd.nist.gov/vuln/detail/CVE-2026-5545 https://curl.se/docs/CVE-2026-5545.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5545.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;X7DmUVoCri5i6vdYVBBgXg==&#34;: {&#xA;      &#34;id&#34;: &#34;X7DmUVoCri5i6vdYVBBgXg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1965&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. When an application uses libcurl to make multiple Negotiate-authenticated HTTP or HTTPS requests to the same server with different credentials, libcurl may incorrectly reuse an existing connection. This logical error can cause a subsequent request to be sent using the authentication of a previous user, leading to an authentication bypass.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-11T10:08:52Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1965 https://bugzilla.redhat.com/show_bug.cgi?id=2446448 https://www.cve.org/CVERecord?id=CVE-2026-1965 https://nvd.nist.gov/vuln/detail/CVE-2026-1965 https://curl.se/docs/CVE-2026-1965.html https://curl.se/docs/CVE-2026-1965.json https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1965.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;X8OJykaOJlN5EhVA7Y11uQ==&#34;: {&#xA;      &#34;id&#34;: &#34;X8OJykaOJlN5EhVA7Y11uQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-40467&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gawk. A Use After Free vulnerability exists in the do_getline_redir() routine within the io.c program file. This vulnerability can be triggered by an attacker, potentially leading to a system crash and causing a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-13T12:07:52Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-40467 https://bugzilla.redhat.com/show_bug.cgi?id=2499658 https://www.cve.org/CVERecord?id=CVE-2026-40467 https://nvd.nist.gov/vuln/detail/CVE-2026-40467 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40467.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gawk&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XIh88yJoOK2Ff8cGZL7F+g==&#34;: {&#xA;      &#34;id&#34;: &#34;XIh88yJoOK2Ff8cGZL7F+g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1525&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici, a Node.js HTTP/1.1 client. A remote attacker could exploit this vulnerability by sending HTTP/1.1 requests that include duplicate Content-Length headers with different casing (e.g., \&#34;Content-Length\&#34; and \&#34;content-length\&#34;). This can lead to HTTP Request Smuggling, a technique where an attacker sends an ambiguous request that is interpreted differently by a proxy and a backend server. Successful exploitation could result in unauthorized access, cache poisoning, or credential hijacking. It may also cause a Denial of Service (DoS) if strict HTTP parsers reject the malformed requests.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T19:56:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1525 https://bugzilla.redhat.com/show_bug.cgi?id=2447144 https://www.cve.org/CVERecord?id=CVE-2026-1525 https://nvd.nist.gov/vuln/detail/CVE-2026-1525 https://cna.openjsf.org/security-advisories.html https://cwe.mitre.org/data/definitions/444.html https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm https://hackerone.com/reports/3556037 https://www.rfc-editor.org/rfc/rfc9110.html#section-8.6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1525.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XKTHMaJwDxmLjk9FkUhg8Q==&#34;: {&#xA;      &#34;id&#34;: &#34;XKTHMaJwDxmLjk9FkUhg8Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-28390&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T22:00:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-28390 https://bugzilla.redhat.com/show_bug.cgi?id=2456314 https://www.cve.org/CVERecord?id=CVE-2026-28390 https://nvd.nist.gov/vuln/detail/CVE-2026-28390 https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6 https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4 https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788 https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28390.json https://access.redhat.com/errata/RHSA-2026:22312&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-3.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XKuZX/r+YD1eQ8+4f77NQQ==&#34;: {&#xA;      &#34;id&#34;: &#34;XKuZX/r+YD1eQ8+4f77NQQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-9086&#34;,&#xA;      &#34;description&#34;: &#34;An out of bounds read flaw has been discovered in the curl project. Under specific conditions the path comparison logic makes curl read outside a heap buffer boundary. This bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-12T05:10:03Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-9086 https://bugzilla.redhat.com/show_bug.cgi?id=2394750 https://www.cve.org/CVERecord?id=CVE-2025-9086 https://nvd.nist.gov/vuln/detail/CVE-2025-9086 https://curl.se/docs/CVE-2025-9086.html https://curl.se/docs/CVE-2025-9086.json https://github.com/curl/curl/commit/c6ae07c6a541e0e96d0040afb6 https://hackerone.com/reports/3294999 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9086.json https://access.redhat.com/errata/RHSA-2026:1350&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libcurl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:7.76.1-35.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XL+Z1BeLmN8Pi7RZ6D6z/w==&#34;: {&#xA;      &#34;id&#34;: &#34;XL+Z1BeLmN8Pi7RZ6D6z/w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15366&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the imaplib module in the Python standard library. The imaplib module does not reject control characters, such as newlines, in user-controlled input passed to IMAP commands. This issue allows an attacker to inject additional commands to be executed in the IMAP server.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:40:24Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15366 https://bugzilla.redhat.com/show_bug.cgi?id=2431368 https://www.cve.org/CVERecord?id=CVE-2025-15366 https://nvd.nist.gov/vuln/detail/CVE-2025-15366 https://github.com/python/cpython/issues/143921 https://github.com/python/cpython/pull/143922 https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15366.json https://access.redhat.com/errata/RHSA-2026:4168&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XL1Nv8y45q8aiA92A99YyA==&#34;: {&#xA;      &#34;id&#34;: &#34;XL1Nv8y45q8aiA92A99YyA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-0512&#34;,&#xA;      &#34;description&#34;: &#34;A divide-by-zero flaw was found in Vim&#39;s adjust_skipcol() function in the move.c file. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a floating point exception error and causing an application to crash, eventually leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-01-30T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-0512 https://bugzilla.redhat.com/show_bug.cgi?id=2165798 https://www.cve.org/CVERecord?id=CVE-2023-0512 https://nvd.nist.gov/vuln/detail/CVE-2023-0512 https://huntr.dev/bounties/de83736a-1936-4872-830b-f1e9b0ad2a74 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0512.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XPUXyp+BOEJyEGOgXafi8Q==&#34;: {&#xA;      &#34;id&#34;: &#34;XPUXyp+BOEJyEGOgXafi8Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-27943&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-03-26T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-27943 https://bugzilla.redhat.com/show_bug.cgi?id=2071728 https://www.cve.org/CVERecord?id=CVE-2022-27943 https://nvd.nist.gov/vuln/detail/CVE-2022-27943 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-27943.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gcc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XPfYdQhyLnN89+qpSA6LWg==&#34;: {&#xA;      &#34;id&#34;: &#34;XPfYdQhyLnN89+qpSA6LWg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45447&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45447 https://bugzilla.redhat.com/show_bug.cgi?id=2481898 https://www.cve.org/CVERecord?id=CVE-2026-45447 https://nvd.nist.gov/vuln/detail/CVE-2026-45447 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XQDeROSRzMSiFTbbLCST/A==&#34;: {&#xA;      &#34;id&#34;: &#34;XQDeROSRzMSiFTbbLCST/A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59857&#34;,&#xA;      &#34;description&#34;: &#34;An out-of-bounds write vulnerability in Vim&#39;s spell_soundfold_sal() function allows an attacker to corrupt memory and crash the editor (Denial of Service) by supplying a specially crafted word during spell sound-folding.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-09T22:34:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59857 https://bugzilla.redhat.com/show_bug.cgi?id=2498863 https://www.cve.org/CVERecord?id=CVE-2026-59857 https://nvd.nist.gov/vuln/detail/CVE-2026-59857 https://github.com/vim/vim/commit/d22ff1c955ff87e8273210eae125aab0e85b6c30 https://github.com/vim/vim/security/advisories/GHSA-m3hf-xcm3-xhm2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59857.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XW4X9/W6MfETfE/VICA4Jw==&#34;: {&#xA;      &#34;id&#34;: &#34;XW4X9/W6MfETfE/VICA4Jw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-1376&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GNU elfutils. This vulnerability allows denial of service via manipulation of the function elf_strptr in /libelf/elf_strptr.c.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-17T04:31:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-1376 https://bugzilla.redhat.com/show_bug.cgi?id=2346061 https://www.cve.org/CVERecord?id=CVE-2025-1376 https://nvd.nist.gov/vuln/detail/CVE-2025-1376 https://sourceware.org/bugzilla/attachment.cgi?id=15940 https://sourceware.org/bugzilla/show_bug.cgi?id=32672 https://sourceware.org/bugzilla/show_bug.cgi?id=32672#c3 https://vuldb.com/?ctiid.295984 https://vuldb.com/?id.295984 https://vuldb.com/?submit.497538 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1376.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;elfutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XkiVaSOj/tcz5wNKnglN4w==&#34;: {&#xA;      &#34;id&#34;: &#34;XkiVaSOj/tcz5wNKnglN4w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33412&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. By including a newline character in a pattern passed to Vim&#39;s glob() function, an attacker may be able to execute arbitrary shell commands. This command injection vulnerability allows for arbitrary code execution, depending on the user&#39;s shell settings.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-24T19:43:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33412 https://bugzilla.redhat.com/show_bug.cgi?id=2450907 https://www.cve.org/CVERecord?id=CVE-2026-33412 https://nvd.nist.gov/vuln/detail/CVE-2026-33412 https://github.com/vim/vim/commit/645ed6597d1ea896c712cd7ddbb6edee79577e9a https://github.com/vim/vim/releases/tag/v9.2.0202 https://github.com/vim/vim/security/advisories/GHSA-w5jw-f54h-x46c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33412.json https://access.redhat.com/errata/RHSA-2026:8259&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim-minimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:8.2.2637-23.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Xms/F5NRiyBcCNuPxw8aoA==&#34;: {&#xA;      &#34;id&#34;: &#34;Xms/F5NRiyBcCNuPxw8aoA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-28164&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng. This buffer overflow vulnerability allows a local attacker to cause a denial of service (DoS) by exploiting the `png_create_read_struct()` function. This can lead to the affected system becoming unresponsive or crashing.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-28164 https://bugzilla.redhat.com/show_bug.cgi?id=2433398 https://www.cve.org/CVERecord?id=CVE-2025-28164 https://nvd.nist.gov/vuln/detail/CVE-2025-28164 https://gist.github.com/kittener/506516f8c22178005b4379c8b2a7de20 https://github.com/pnggroup/libpng/issues/655 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-28164.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Xnj4Kpl+tPifTh/+xOnglw==&#34;: {&#xA;      &#34;id&#34;: &#34;Xnj4Kpl+tPifTh/+xOnglw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11187&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When an application processes a maliciously crafted PKCS#12 file, an attacker can exploit a stack buffer overflow or a NULL pointer dereference. This can lead to a denial of service (DoS) by crashing the application, and in some cases, may enable arbitrary code execution. The vulnerability arises from the lack of validation for PBKDF2 salt and keylength parameters within the PKCS#12 file.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11187 https://bugzilla.redhat.com/show_bug.cgi?id=2430375 https://www.cve.org/CVERecord?id=CVE-2025-11187 https://nvd.nist.gov/vuln/detail/CVE-2025-11187 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11187.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XuMP4XKeqFlYH9jgvFKXXw==&#34;: {&#xA;      &#34;id&#34;: &#34;XuMP4XKeqFlYH9jgvFKXXw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-2609&#34;,&#xA;      &#34;description&#34;: &#34;NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-05-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-2609 https://bugzilla.redhat.com/show_bug.cgi?id=2209050 https://www.cve.org/CVERecord?id=CVE-2023-2609 https://nvd.nist.gov/vuln/detail/CVE-2023-2609 https://huntr.dev/bounties/1679be5a-565f-4a44-a430-836412a0b622 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-2609.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Xvp9bEwIvwUrD61DySkWgA==&#34;: {&#xA;      &#34;id&#34;: &#34;Xvp9bEwIvwUrD61DySkWgA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-io-console&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.7.1-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;XwLJYEytIMCdc6/A4MTJHg==&#34;: {&#xA;      &#34;id&#34;: &#34;XwLJYEytIMCdc6/A4MTJHg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5958&#34;,&#xA;      &#34;description&#34;: &#34;A Time-of-Check Time-of-Use (TOCTOU) race condition was found in GNU sed. When the -i (in-place) and --follow-symlinks options are used together, sed resolves the symlink but reopens the path for writing. An attacker with write access to the directory containing the symlink can swap it between the check and the open operations. If a privileged user executes sed in this manner on a path influenced by the attacker, it can lead to arbitrary file overwrites and potential privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5958 https://bugzilla.redhat.com/show_bug.cgi?id=2458960 https://www.cve.org/CVERecord?id=CVE-2026-5958 https://nvd.nist.gov/vuln/detail/CVE-2026-5958 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5958.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;sed&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Y/6FiFNJ+h2jXNTlPOzrnQ==&#34;: {&#xA;      &#34;id&#34;: &#34;Y/6FiFNJ+h2jXNTlPOzrnQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-0051&#34;,&#xA;      &#34;description&#34;: &#34;A heap-based buffer overflow was found in Vim in the msg_puts_printf function in the message.c file. The issue occurs because of an invalid memory access when calculating the length of a string when a specially crafted input is processed. This flaw allows an attacker who can trick a user into opening a specially crafted file into triggering the heap-based buffer overflow, causing the application to crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-01-03T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-0051 https://bugzilla.redhat.com/show_bug.cgi?id=2161348 https://www.cve.org/CVERecord?id=CVE-2023-0051 https://nvd.nist.gov/vuln/detail/CVE-2023-0051 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0051.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Y1YZsYV7ls1vsluhREpXlw==&#34;: {&#xA;      &#34;id&#34;: &#34;Y1YZsYV7ls1vsluhREpXlw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48618&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. This flaw involves a mismatch in how Node.js handles TLS (Transport Layer Security) hostnames and unicode dot separators during authentication. This mismatch can lead to a wildcard-depth authentication bypass. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access and confidentiality impact.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48618 https://bugzilla.redhat.com/show_bug.cgi?id=2493337 https://www.cve.org/CVERecord?id=CVE-2026-48618 https://nvd.nist.gov/vuln/detail/CVE-2026-48618 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Y3fno6fRSl46BTZQlReNKg==&#34;: {&#xA;      &#34;id&#34;: &#34;Y3fno6fRSl46BTZQlReNKg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34181&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This vulnerability allows a remote attacker to forge PKCS#12 (Public-Key Cryptography Standards #12) files that use Password-Based Message Authentication Code 1 (PBMAC1) with short HMAC (Hash-based Message Authentication Code) keys. This can lead to a service accepting attacker-controlled certificates and private keys with a 1 in 256 probability, potentially enabling impersonation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34181 https://bugzilla.redhat.com/show_bug.cgi?id=2481882 https://www.cve.org/CVERecord?id=CVE-2026-34181 https://nvd.nist.gov/vuln/detail/CVE-2026-34181 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34181.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Y6TEBwH0+CoZ50j5sQV23w==&#34;: {&#xA;      &#34;id&#34;: &#34;Y6TEBwH0+CoZ50j5sQV23w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-3968&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. A possible heap use-after-free vulnerability could allow an attacker to input a specially crafted file leading to a crash or code execution. The highest threat from this vulnerability is to system availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-11-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-3968 https://bugzilla.redhat.com/show_bug.cgi?id=2025056 https://www.cve.org/CVERecord?id=CVE-2021-3968 https://nvd.nist.gov/vuln/detail/CVE-2021-3968 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-3968.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Y7j+Hhv6OMvu2cmEQkev4Q==&#34;: {&#xA;      &#34;id&#34;: &#34;Y7j+Hhv6OMvu2cmEQkev4Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-5642&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in Python/CPython that does not disallow configuring an empty list (\&#34;[]\&#34;) for SSLContext.set_npn_protocols(), which is an invalid value for the underlying OpenSSL API. This issue results in a buffer over-read when NPN is used. See CVE -2024-5535 for OpenSSL for more information.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-06-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-5642 https://bugzilla.redhat.com/show_bug.cgi?id=2294682 https://www.cve.org/CVERecord?id=CVE-2024-5642 https://nvd.nist.gov/vuln/detail/CVE-2024-5642 https://mail.python.org/archives/list/security-announce@python.org/thread/PLP2JI3PJY33YG6P5BZYSSNU66HASXBQ/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-5642.json https://access.redhat.com/errata/RHSA-2025:23342&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-2.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YKgthSAonF3epY42eqsMRw==&#34;: {&#xA;      &#34;id&#34;: &#34;YKgthSAonF3epY42eqsMRw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-3497&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the OpenSSH GSSAPI (Generic Security Service Application Program Interface) delta patches, as included in various Linux distributions. A remote attacker could exploit this by sending an unexpected GSSAPI message type during the key exchange process. This occurs because the `sshpkt_disconnect()` function, when called on an error, does not properly terminate the process, leading to the continued execution of the program with uninitialized connection variables. Accessing these uninitialized variables can lead to undefined behavior, potentially resulting in information disclosure or a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T18:27:44Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-3497 https://bugzilla.redhat.com/show_bug.cgi?id=2447085 https://www.cve.org/CVERecord?id=CVE-2026-3497 https://nvd.nist.gov/vuln/detail/CVE-2026-3497 https://ubuntu.com/security/CVE-2026-3497 https://www.openwall.com/lists/oss-security/2026/03/12/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3497.json https://access.redhat.com/errata/RHSA-2026:6462&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-48.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YQGeiQ1baJrwVuNrCjd79A==&#34;: {&#xA;      &#34;id&#34;: &#34;YQGeiQ1baJrwVuNrCjd79A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55132&#34;,&#xA;      &#34;description&#34;: &#34;A file access flaw has been discovered in NodeJS. A file&#39;s access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55132 https://bugzilla.redhat.com/show_bug.cgi?id=2431338 https://www.cve.org/CVERecord?id=CVE-2025-55132 https://nvd.nist.gov/vuln/detail/CVE-2025-55132 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55132.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YR9IlxlHBBSlj3ZLdc6/eQ==&#34;: {&#xA;      &#34;id&#34;: &#34;YR9IlxlHBBSlj3ZLdc6/eQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YSP3jWIJP4TspvpKDx/wvA==&#34;: {&#xA;      &#34;id&#34;: &#34;YSP3jWIJP4TspvpKDx/wvA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-58016&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-08T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-58016 https://bugzilla.redhat.com/show_bug.cgi?id=2492257 https://www.cve.org/CVERecord?id=CVE-2026-58016 https://nvd.nist.gov/vuln/detail/CVE-2026-58016 https://gitlab.gnome.org/GNOME/glib/-/issues/3932 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58016.json https://access.redhat.com/errata/RHSA-2026:42089&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-19.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YUwZZ9Cg1FloxBZV60vOCg==&#34;: {&#xA;      &#34;id&#34;: &#34;YUwZZ9Cg1FloxBZV60vOCg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2522&#34;,&#xA;      &#34;description&#34;: &#34;A heap buffer overflow vulnerability was found in vim&#39;s ins_compl_infercase_gettext() function of the src/insexpand.c file. This flaw occurs when vim tries to access uninitialized memory when completing a long line. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap-based buffer overflow that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-07-25T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2522 https://bugzilla.redhat.com/show_bug.cgi?id=2112299 https://www.cve.org/CVERecord?id=CVE-2022-2522 https://nvd.nist.gov/vuln/detail/CVE-2022-2522 https://huntr.dev/bounties/3a2d83af-9542-4d93-8784-98b115135a22 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2522.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YX2rGofSXHBcNhTOGpNkAA==&#34;: {&#xA;      &#34;id&#34;: &#34;YX2rGofSXHBcNhTOGpNkAA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4424&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4424 https://bugzilla.redhat.com/show_bug.cgi?id=2449006 https://www.cve.org/CVERecord?id=CVE-2026-4424 https://nvd.nist.gov/vuln/detail/CVE-2026-4424 https://github.com/libarchive/libarchive/pull/2898 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4424.json https://access.redhat.com/errata/RHSA-2026:8510&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.3-9.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YXlS56JkLiuXwjbDNwkvdw==&#34;: {&#xA;      &#34;id&#34;: &#34;YXlS56JkLiuXwjbDNwkvdw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-5642&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in Python/CPython that does not disallow configuring an empty list (\&#34;[]\&#34;) for SSLContext.set_npn_protocols(), which is an invalid value for the underlying OpenSSL API. This issue results in a buffer over-read when NPN is used. See CVE -2024-5535 for OpenSSL for more information.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-06-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-5642 https://bugzilla.redhat.com/show_bug.cgi?id=2294682 https://www.cve.org/CVERecord?id=CVE-2024-5642 https://nvd.nist.gov/vuln/detail/CVE-2024-5642 https://mail.python.org/archives/list/security-announce@python.org/thread/PLP2JI3PJY33YG6P5BZYSSNU66HASXBQ/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-5642.json https://access.redhat.com/errata/RHSA-2025:23342&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-2.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YdpqbsRbo4xx71CiWUF39Q==&#34;: {&#xA;      &#34;id&#34;: &#34;YdpqbsRbo4xx71CiWUF39Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21441&#34;,&#xA;      &#34;description&#34;: &#34;urllib3 is an HTTP client library for Python. urllib3&#39;s streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-07T22:09:01Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21441 https://bugzilla.redhat.com/show_bug.cgi?id=2427726 https://www.cve.org/CVERecord?id=CVE-2026-21441 https://nvd.nist.gov/vuln/detail/CVE-2026-21441 https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.json https://access.redhat.com/errata/RHSA-2026:1087&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-urllib3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.26.5-6.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YfN4DMNLaz3lIsbsDdrsLA==&#34;: {&#xA;      &#34;id&#34;: &#34;YfN4DMNLaz3lIsbsDdrsLA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5450&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:55:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-headers&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-272.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YgehfkOilPM31dosmRXxDA==&#34;: {&#xA;      &#34;id&#34;: &#34;YgehfkOilPM31dosmRXxDA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35386&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows a remote attacker to achieve arbitrary command execution by injecting shell metacharacters into a username provided on the command line. Exploitation requires an untrusted username and a non-default configuration of the &#39;%&#39; character in `ssh_config`.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:44:27Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35386 https://bugzilla.redhat.com/show_bug.cgi?id=2454506 https://www.cve.org/CVERecord?id=CVE-2026-35386 https://nvd.nist.gov/vuln/detail/CVE-2026-35386 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35386.json https://access.redhat.com/errata/RHSA-2026:13381&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-49.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YoLm41YhtgLxKYJ1/exB9g==&#34;: {&#xA;      &#34;id&#34;: &#34;YoLm41YhtgLxKYJ1/exB9g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YodqYykSYwoW2Z78DZNfRA==&#34;: {&#xA;      &#34;id&#34;: &#34;YodqYykSYwoW2Z78DZNfRA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-12912&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-12912 https://bugzilla.redhat.com/show_bug.cgi?id=2492871 https://www.cve.org/CVERecord?id=CVE-2026-12912 https://nvd.nist.gov/vuln/detail/CVE-2026-12912 https://gitlab.com/libtiff/libtiff/-/merge_requests/873 https://gitlab.com/libtiff/libtiff/-/work_items/824 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12912.json https://access.redhat.com/errata/RHSA-2026:42668&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtiff-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:4.4.0-18.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Ywdulqdw8k75jjL2qb8gPg==&#34;: {&#xA;      &#34;id&#34;: &#34;Ywdulqdw8k75jjL2qb8gPg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5704&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-06T13:36:20Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5704 https://bugzilla.redhat.com/show_bug.cgi?id=2455360 https://www.cve.org/CVERecord?id=CVE-2026-5704 https://nvd.nist.gov/vuln/detail/CVE-2026-5704 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5704.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;YwrNcgB1VRavvqQXhCICXg==&#34;: {&#xA;      &#34;id&#34;: &#34;YwrNcgB1VRavvqQXhCICXg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5435&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T11:58:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-common&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Z/nuiLo/kSAcxolOXcSWYw==&#34;: {&#xA;      &#34;id&#34;: &#34;Z/nuiLo/kSAcxolOXcSWYw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21637&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21637 https://bugzilla.redhat.com/show_bug.cgi?id=2431340 https://www.cve.org/CVERecord?id=CVE-2026-21637 https://nvd.nist.gov/vuln/detail/CVE-2026-21637 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21637.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;Z0bbSkX8e3OUKdJa86CbBw==&#34;: {&#xA;      &#34;id&#34;: &#34;Z0bbSkX8e3OUKdJa86CbBw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-4217&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in unzip.  The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-01-14T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-4217 https://bugzilla.redhat.com/show_bug.cgi?id=2044583 https://www.cve.org/CVERecord?id=CVE-2021-4217 https://nvd.nist.gov/vuln/detail/CVE-2021-4217 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-4217.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;unzip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ZA3vHdd4PXjvIsTBPl1mxg==&#34;: {&#xA;      &#34;id&#34;: &#34;ZA3vHdd4PXjvIsTBPl1mxg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1528&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a specially crafted WebSocket frame with an extremely large 64-bit length. This causes undici&#39;s ByteParser to overflow its internal calculations, leading to an invalid state and a fatal TypeError. The primary consequence is a Denial of Service (DoS), which terminates the process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:21:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1528 https://bugzilla.redhat.com/show_bug.cgi?id=2447145 https://www.cve.org/CVERecord?id=CVE-2026-1528 https://nvd.nist.gov/vuln/detail/CVE-2026-1528 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj https://hackerone.com/reports/3537648 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1528.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ZCLP8N4soyt53A9I5VdxcA==&#34;: {&#xA;      &#34;id&#34;: &#34;ZCLP8N4soyt53A9I5VdxcA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35388&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows for a low integrity impact due to the omission of connection multiplexing confirmation for proxy-mode multiplexing sessions. A local user, under specific and complex conditions requiring user interaction, could potentially establish a multiplexed session without explicit confirmation, leading to unintended data handling.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:57:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35388 https://bugzilla.redhat.com/show_bug.cgi?id=2454500 https://www.cve.org/CVERecord?id=CVE-2026-35388 https://nvd.nist.gov/vuln/detail/CVE-2026-35388 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35388.json https://access.redhat.com/errata/RHSA-2026:19219&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ZMqtUXBs3IUyb3eHhTEM+Q==&#34;: {&#xA;      &#34;id&#34;: &#34;ZMqtUXBs3IUyb3eHhTEM+Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:37:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ZNpRshLHRo06/00CGV605Q==&#34;: {&#xA;      &#34;id&#34;: &#34;ZNpRshLHRo06/00CGV605Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11083&#34;,&#xA;      &#34;description&#34;: &#34;A head based buffer overflow flaw has been discovered in GNU bin utilities. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-27T23:02:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11083 https://bugzilla.redhat.com/show_bug.cgi?id=2399948 https://www.cve.org/CVERecord?id=CVE-2025-11083 https://nvd.nist.gov/vuln/detail/CVE-2025-11083 https://sourceware.org/bugzilla/attachment.cgi?id=16353 https://sourceware.org/bugzilla/show_bug.cgi?id=33457 https://sourceware.org/bugzilla/show_bug.cgi?id=33457#c1 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9ca499644a21ceb3f946d1c179c38a83be084490 https://vuldb.com/?ctiid.326124 https://vuldb.com/?id.326124 https://vuldb.com/?submit.661277 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11083.json https://access.redhat.com/errata/RHSA-2025:23343&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.35.2-67.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ZRSF+MayCxLJlIAPWIqUVA==&#34;: {&#xA;      &#34;id&#34;: &#34;ZRSF+MayCxLJlIAPWIqUVA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ZhTLRTlcbZumWmiritxOAw==&#34;: {&#xA;      &#34;id&#34;: &#34;ZhTLRTlcbZumWmiritxOAw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6100&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python&#39;s decompression modules, including `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile`. This vulnerability, a use-after-free, can occur if a program attempts to re-use a decompression object after a memory allocation error, especially when the system is experiencing high memory usage. Exploitation of this flaw could potentially allow an attacker to execute arbitrary code or access sensitive data. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-13T17:15:47Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6100 https://bugzilla.redhat.com/show_bug.cgi?id=2457932 https://www.cve.org/CVERecord?id=CVE-2026-6100 https://nvd.nist.gov/vuln/detail/CVE-2026-6100 https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2 https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20 https://github.com/python/cpython/issues/148395 https://github.com/python/cpython/pull/148396 https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json https://access.redhat.com/errata/RHSA-2026:10949&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ZkozpC3UXStcW3ZbPMbsTA==&#34;: {&#xA;      &#34;id&#34;: &#34;ZkozpC3UXStcW3ZbPMbsTA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14512&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib&#39;s GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-11T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14512 https://bugzilla.redhat.com/show_bug.cgi?id=2421339 https://www.cve.org/CVERecord?id=CVE-2025-14512 https://nvd.nist.gov/vuln/detail/CVE-2025-14512 https://gitlab.gnome.org/GNOME/glib/-/issues/3845 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14512.json https://access.redhat.com/errata/RHSA-2026:15971&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-18.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ZuhhG1bpyIKZ8+BvJQvoUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;ZuhhG1bpyIKZ8+BvJQvoUQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-7210&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the `python` and `expat` components. Insufficient entropy in the hash-flooding protection mechanism of `xml.parsers.expat` and `xml.etree.ElementTree` allows a remote attacker to craft a malicious XML document. This crafted document can trigger a hash flooding attack, leading to a denial of service (DoS) condition.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-11T17:19:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-7210 https://bugzilla.redhat.com/show_bug.cgi?id=2469216 https://www.cve.org/CVERecord?id=CVE-2026-7210 https://nvd.nist.gov/vuln/detail/CVE-2026-7210 https://github.com/python/cpython/issues/149018 https://github.com/python/cpython/pull/149023 https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7210.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;a8Muru+syePTNtU2/rVrUg==&#34;: {&#xA;      &#34;id&#34;: &#34;a8Muru+syePTNtU2/rVrUg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1525&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici, a Node.js HTTP/1.1 client. A remote attacker could exploit this vulnerability by sending HTTP/1.1 requests that include duplicate Content-Length headers with different casing (e.g., \&#34;Content-Length\&#34; and \&#34;content-length\&#34;). This can lead to HTTP Request Smuggling, a technique where an attacker sends an ambiguous request that is interpreted differently by a proxy and a backend server. Successful exploitation could result in unauthorized access, cache poisoning, or credential hijacking. It may also cause a Denial of Service (DoS) if strict HTTP parsers reject the malformed requests.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T19:56:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1525 https://bugzilla.redhat.com/show_bug.cgi?id=2447144 https://www.cve.org/CVERecord?id=CVE-2026-1525 https://nvd.nist.gov/vuln/detail/CVE-2026-1525 https://cna.openjsf.org/security-advisories.html https://cwe.mitre.org/data/definitions/444.html https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm https://hackerone.com/reports/3556037 https://www.rfc-editor.org/rfc/rfc9110.html#section-8.6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1525.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;aJsQ4a3gp8/jsNBVC56QHw==&#34;: {&#xA;      &#34;id&#34;: &#34;aJsQ4a3gp8/jsNBVC56QHw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48930&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. This vulnerability in the TLS (Transport Layer Security) hostname handling allows embedded null characters in hostnames. This can lead to silent authority rebinding, potentially enabling an attacker to redirect network traffic to an unintended server and disclose sensitive information.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:37Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48930 https://bugzilla.redhat.com/show_bug.cgi?id=2493326 https://www.cve.org/CVERecord?id=CVE-2026-48930 https://nvd.nist.gov/vuln/detail/CVE-2026-48930 https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e https://hackerone.com/reports/3656716 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48930.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;aK9Mq6KdK8L3Pl0r1rTwYA==&#34;: {&#xA;      &#34;id&#34;: &#34;aK9Mq6KdK8L3Pl0r1rTwYA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-55653&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-22T23:17:43Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-55653 https://bugzilla.redhat.com/show_bug.cgi?id=2462351 https://www.cve.org/CVERecord?id=CVE-2026-55653 https://nvd.nist.gov/vuln/detail/CVE-2026-55653 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55653.json https://access.redhat.com/errata/RHSA-2026:47756&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-9.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;aKS5Pwr8YswsXS77DXcixA==&#34;: {&#xA;      &#34;id&#34;: &#34;aKS5Pwr8YswsXS77DXcixA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4786&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Python webbrowser.open() API. If a specially crafted URL containing \&#34;%action\&#34; is processed, an attacker could bypass a previous mitigation for CVE-2026-4519. This bypass allows for command injection into the underlying shell, potentially leading to arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-13T21:52:19Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4786 https://bugzilla.redhat.com/show_bug.cgi?id=2458049 https://www.cve.org/CVERecord?id=CVE-2026-4786 https://nvd.nist.gov/vuln/detail/CVE-2026-4786 https://github.com/python/cpython/issues/148169 https://github.com/python/cpython/pull/148170 https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4786.json https://access.redhat.com/errata/RHSA-2026:19216&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;aKcPzJFDOswSNCIlBX5/jQ==&#34;: {&#xA;      &#34;id&#34;: &#34;aKcPzJFDOswSNCIlBX5/jQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33636&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng. A remote attacker could exploit an out-of-bounds read and write vulnerability in the ARM/AArch64 Neon-optimized palette expansion path. This occurs when processing a final partial chunk of 8-bit paletted rows without verifying sufficient input pixels, leading to dereferencing pointers before the start of the row buffer and writing expanded pixel data to underflowed positions. This flaw can result in information disclosure and denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-26T16:51:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33636 https://bugzilla.redhat.com/show_bug.cgi?id=2451819 https://www.cve.org/CVERecord?id=CVE-2026-33636 https://nvd.nist.gov/vuln/detail/CVE-2026-33636 https://github.com/pnggroup/libpng/commit/7734cda20cf1236aef60f3bbd2267c97bbb40869 https://github.com/pnggroup/libpng/commit/aba9f18eba870d14fb52c5ba5d73451349e339c3 https://github.com/pnggroup/libpng/security/advisories/GHSA-wjr5-c57x-95m2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33636.json https://access.redhat.com/errata/RHSA-2026:14791&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;aMOKwSAvMIKqreq1+gZ2ow==&#34;: {&#xA;      &#34;id&#34;: &#34;aMOKwSAvMIKqreq1+gZ2ow==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4046&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T17:16:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;aN7J4vjcApPz2ZabMR0Irg==&#34;: {&#xA;      &#34;id&#34;: &#34;aN7J4vjcApPz2ZabMR0Irg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bundler&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.5.22-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;aOUfuyvyyWEe7Z1IZT+fGw==&#34;: {&#xA;      &#34;id&#34;: &#34;aOUfuyvyyWEe7Z1IZT+fGw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34743&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in XZ Utils. When the `lzma_index_decoder()` function processes an empty index, and a subsequent `lzma_index_append()` operation is performed, insufficient memory is allocated. This can lead to a buffer overflow, potentially causing a denial of service (DoS) for affected systems.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T18:36:37Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34743 https://bugzilla.redhat.com/show_bug.cgi?id=2454589 https://www.cve.org/CVERecord?id=CVE-2026-34743 https://nvd.nist.gov/vuln/detail/CVE-2026-34743 https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87 https://github.com/tukaani-project/xz/releases/tag/v5.8.3 https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34743.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;xz&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;aQGx6Am8fU9TZmcyiMNL4A==&#34;: {&#xA;      &#34;id&#34;: &#34;aQGx6Am8fU9TZmcyiMNL4A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-43802&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. This issue may allow a heap-buffer overflow via improper management of the typeahead buffer, leading to crashes when error messages occur in combination with several long mappings.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-08-26T19:15:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-43802 https://bugzilla.redhat.com/show_bug.cgi?id=2307995 https://www.cve.org/CVERecord?id=CVE-2024-43802 https://nvd.nist.gov/vuln/detail/CVE-2024-43802 https://github.com/vim/vim/commit/322ba9108612bead5eb https://github.com/vim/vim/security/advisories/GHSA-4ghr-c62x-cqfh https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-43802.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;aWSD4ccAhJBO5Heyt5mTxQ==&#34;: {&#xA;      &#34;id&#34;: &#34;aWSD4ccAhJBO5Heyt5mTxQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-6069&#34;,&#xA;      &#34;description&#34;: &#34;A denial-of-service (DoS) vulnerability has been discovered in Python&#39;s html.parser.HTMLParser class. When processing specially malformed HTML input, the parsing runtime can become quadratic with respect to the input size. This significantly increased processing time can lead to excessive resource consumption, ultimately causing a denial-of-service condition in applications that rely on this parser.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-06-17T13:39:46Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-6069 https://bugzilla.redhat.com/show_bug.cgi?id=2373234 https://www.cve.org/CVERecord?id=CVE-2025-6069 https://nvd.nist.gov/vuln/detail/CVE-2025-6069 https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949 https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41 https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b https://github.com/python/cpython/issues/135462 https://github.com/python/cpython/pull/135464 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6069.json https://access.redhat.com/errata/RHSA-2025:23342&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-2.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ajT6YifLzju5PlaUiX+EvA==&#34;: {&#xA;      &#34;id&#34;: &#34;ajT6YifLzju5PlaUiX+EvA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11850&#34;,&#xA;      &#34;description&#34;: &#34;An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len \u003c 2, triggering the underflow when the KDC or kadmind reads principal data.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-10T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11850 https://bugzilla.redhat.com/show_bug.cgi?id=2459970 https://www.cve.org/CVERecord?id=CVE-2026-11850 https://nvd.nist.gov/vuln/detail/CVE-2026-11850 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11850.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;krb5&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;axpLUf/WfpliDV7UixDwiQ==&#34;: {&#xA;      &#34;id&#34;: &#34;axpLUf/WfpliDV7UixDwiQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55132&#34;,&#xA;      &#34;description&#34;: &#34;A file access flaw has been discovered in NodeJS. A file&#39;s access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55132 https://bugzilla.redhat.com/show_bug.cgi?id=2431338 https://www.cve.org/CVERecord?id=CVE-2025-55132 https://nvd.nist.gov/vuln/detail/CVE-2025-55132 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55132.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ayJ94QRlWYBn8mXMxBDr+Q==&#34;: {&#xA;      &#34;id&#34;: &#34;ayJ94QRlWYBn8mXMxBDr+Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11525&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. When undici processes Set-Cookie headers, it incorrectly interprets the SameSite attribute, accepting partial matches instead of exact ones. This allows a malicious server to downgrade a cookie&#39;s SameSite policy to a less secure setting, potentially leading to unintended information disclosure or a weakening of security protections for the user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:31:03Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11525 https://bugzilla.redhat.com/show_bug.cgi?id=2490008 https://www.cve.org/CVERecord?id=CVE-2026-11525 https://nvd.nist.gov/vuln/detail/CVE-2026-11525 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11525.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;b+WKHvVRvScXQjTpsI/dQA==&#34;: {&#xA;      &#34;id&#34;: &#34;b+WKHvVRvScXQjTpsI/dQA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-6176&#34;,&#xA;      &#34;description&#34;: &#34;Scrapy are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-31T00:00:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-6176 https://bugzilla.redhat.com/show_bug.cgi?id=2408762 https://www.cve.org/CVERecord?id=CVE-2025-6176 https://nvd.nist.gov/vuln/detail/CVE-2025-6176 https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6176.json https://access.redhat.com/errata/RHSA-2026:2042&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libbrotli&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.0.9-9.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;b1aMkFsUYzQ15fp9A4JV2w==&#34;: {&#xA;      &#34;id&#34;: &#34;b1aMkFsUYzQ15fp9A4JV2w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55130&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55130 https://bugzilla.redhat.com/show_bug.cgi?id=2431352 https://www.cve.org/CVERecord?id=CVE-2025-55130 https://nvd.nist.gov/vuln/detail/CVE-2025-55130 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55130.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.4-1.22.22.0.1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;b2xf65/2S45gOxG8Grxy0g==&#34;: {&#xA;      &#34;id&#34;: &#34;b2xf65/2S45gOxG8Grxy0g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-5441&#34;,&#xA;      &#34;description&#34;: &#34;A NULL pointer dereference vulnerability was found in Vim. This flaw allows an attacker who can trick a user into processing a specially crafted file to trigger the NULL pointer dereference, causing the application to crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-10-01T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-5441 https://bugzilla.redhat.com/show_bug.cgi?id=2242926 https://www.cve.org/CVERecord?id=CVE-2023-5441 https://nvd.nist.gov/vuln/detail/CVE-2023-5441 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-5441.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;b9vpp7YMXEAHYnt8gPj4PA==&#34;: {&#xA;      &#34;id&#34;: &#34;b9vpp7YMXEAHYnt8gPj4PA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15469&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. When a user signs or verifies files larger than 16MB using the `openssl dgst` command with one-shot algorithms, the tool silently truncates the input to 16MB. This creates an integrity gap, allowing trailing data beyond the initial 16MB to be modified without detection because it remains unauthenticated. This vulnerability primarily impacts workflows that both sign and verify files using the affected `openssl dgst` command.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15469 https://bugzilla.redhat.com/show_bug.cgi?id=2430378 https://www.cve.org/CVERecord?id=CVE-2025-15469 https://nvd.nist.gov/vuln/detail/CVE-2025-15469 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15469.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bACUKZThWu3kcO82NfO4eg==&#34;: {&#xA;      &#34;id&#34;: &#34;bACUKZThWu3kcO82NfO4eg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-1264&#34;,&#xA;      &#34;description&#34;: &#34;A NULL pointer dereference vulnerability was discovered in vim&#39;s utfc_ptr2len() function in the mbyte.c file. This issue is due to using a NULL pointer with the nested :open command. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering an issue that causes an application to crash, leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-03-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-1264 https://bugzilla.redhat.com/show_bug.cgi?id=2176413 https://www.cve.org/CVERecord?id=CVE-2023-1264 https://nvd.nist.gov/vuln/detail/CVE-2023-1264 https://huntr.dev/bounties/b2989095-88f3-413a-9a39-c1c58a6e6815 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1264.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bCZjE4S4e+JRkpJeCZ485w==&#34;: {&#xA;      &#34;id&#34;: &#34;bCZjE4S4e+JRkpJeCZ485w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-irb&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.13.1-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bHbadSMaYCdCzwHNWG3fzw==&#34;: {&#xA;      &#34;id&#34;: &#34;bHbadSMaYCdCzwHNWG3fzw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55132&#34;,&#xA;      &#34;description&#34;: &#34;A file access flaw has been discovered in NodeJS. A file&#39;s access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55132 https://bugzilla.redhat.com/show_bug.cgi?id=2431338 https://www.cve.org/CVERecord?id=CVE-2025-55132 https://nvd.nist.gov/vuln/detail/CVE-2025-55132 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55132.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bJGGlc8FG/c2T93ktUh6Ig==&#34;: {&#xA;      &#34;id&#34;: &#34;bJGGlc8FG/c2T93ktUh6Ig==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66418&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in urllib3 Python library that could lead to a Denial of Service condition. A remote, malicious server can exploit this flaw by responding to a client request with an HTTP message that uses an excessive number of chained compression algorithms. This unlimited decompression chain causes the client system to consume a virtually unbounded amount of CPU resources and memory. The high resource usage leads to service disruption, making the application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T16:02:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66418 https://bugzilla.redhat.com/show_bug.cgi?id=2419455 https://www.cve.org/CVERecord?id=CVE-2025-66418 https://nvd.nist.gov/vuln/detail/CVE-2025-66418 https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8 https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66418.json https://access.redhat.com/errata/RHSA-2026:1087&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-urllib3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.26.5-6.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bNVewgNMQNWC+EwlyIyTlA==&#34;: {&#xA;      &#34;id&#34;: &#34;bNVewgNMQNWC+EwlyIyTlA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45447&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45447 https://bugzilla.redhat.com/show_bug.cgi?id=2481898 https://www.cve.org/CVERecord?id=CVE-2026-45447 https://nvd.nist.gov/vuln/detail/CVE-2026-45447 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bOC69k4Gpn8Av1w/ra2Tdw==&#34;: {&#xA;      &#34;id&#34;: &#34;bOC69k4Gpn8Av1w/ra2Tdw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14104&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1913&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libuuid&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.37.4-21.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bQ1N5xPGM/wU59iAjdfQ6A==&#34;: {&#xA;      &#34;id&#34;: &#34;bQ1N5xPGM/wU59iAjdfQ6A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15468&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. A remote attacker could trigger a NULL pointer dereference by sending an unknown or unsupported cipher ID during the client hello callback in applications using the QUIC (Quick UDP Internet Connections) protocol. This vulnerability, occurring when the SSL_CIPHER_find() function is called in this specific context, leads to an abnormal termination of the running process, causing a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15468 https://bugzilla.redhat.com/show_bug.cgi?id=2430377 https://www.cve.org/CVERecord?id=CVE-2025-15468 https://nvd.nist.gov/vuln/detail/CVE-2025-15468 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15468.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bS47R6kjzBYQaQepU2dXHw==&#34;: {&#xA;      &#34;id&#34;: &#34;bS47R6kjzBYQaQepU2dXHw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42769&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Certificate Management Protocol (CMP) implementation within OpenSSL. An attacker with existing Registration Authority (RA) level credentials could exploit an error in the certificate verification process during a Root Certificate Authority (CA) key update. This vulnerability allows the attacker to replace the root CA certificate for CMP clients with a fraudulent one. The primary consequence is an escalation of privileges, enabling the attacker to gain control equivalent to the root CA.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42769 https://bugzilla.redhat.com/show_bug.cgi?id=2481893 https://www.cve.org/CVERecord?id=CVE-2026-42769 https://nvd.nist.gov/vuln/detail/CVE-2026-42769 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42769.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bXKnVRmmXzNE9gSoSjNlOQ==&#34;: {&#xA;      &#34;id&#34;: &#34;bXKnVRmmXzNE9gSoSjNlOQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6477&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in PostgreSQL libpq. A server superuser can exploit a buffer overflow vulnerability in the PQfn function, which is used by client functions such as lo_export(), lo_read(), lo_lseek64(), and lo_tell64(). This allows the superuser to send an arbitrarily large response, overwriting the client&#39;s stack memory, specifically in tools like psql and pg_dump. This could lead to arbitrary code execution on the client system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-14T13:00:12Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6477 https://bugzilla.redhat.com/show_bug.cgi?id=2477442 https://www.cve.org/CVERecord?id=CVE-2026-6477 https://nvd.nist.gov/vuln/detail/CVE-2026-6477 https://www.postgresql.org/support/security/CVE-2026-6477/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6477.json https://access.redhat.com/errata/RHSA-2026:44308&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpq&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:13.23-3.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bZGx+ktPNqzyr9hXBoIOTA==&#34;: {&#xA;      &#34;id&#34;: &#34;bZGx+ktPNqzyr9hXBoIOTA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-4598&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original&#39;s privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner&#39;s permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original&#39;s SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-4598 https://bugzilla.redhat.com/show_bug.cgi?id=2369242 https://www.cve.org/CVERecord?id=CVE-2025-4598 https://nvd.nist.gov/vuln/detail/CVE-2025-4598 https://www.openwall.com/lists/oss-security/2025/05/29/3 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4598.json https://access.redhat.com/errata/RHSA-2025:22660&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-55.el9_7.7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bbylqjYpcbE9/Bm4AdduVQ==&#34;: {&#xA;      &#34;id&#34;: &#34;bbylqjYpcbE9/Bm4AdduVQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-irb&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.13.1-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bcO+GuPgyR+iGLy6+mF2Cg==&#34;: {&#xA;      &#34;id&#34;: &#34;bcO+GuPgyR+iGLy6+mF2Cg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-55892&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open-source command-line text editor. A remote attacker could exploit this vulnerability by convincing a user to load a specially crafted spell file. This malicious file can trigger a stack out-of-bounds write, which corrupts the editor&#39;s memory and causes it to crash. This leads to a Denial of Service (DoS), making the editor unavailable to the user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-25T15:32:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-55892 https://bugzilla.redhat.com/show_bug.cgi?id=2492975 https://www.cve.org/CVERecord?id=CVE-2026-55892 https://nvd.nist.gov/vuln/detail/CVE-2026-55892 https://github.com/vim/vim/commit/8325b193bba5f01e7a7d8241f https://github.com/vim/vim/releases/tag/v9.2.0662 https://github.com/vim/vim/security/advisories/GHSA-qm9w-fmpj-879h https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55892.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bf41zTvm6HAv6xdiXpwGWQ==&#34;: {&#xA;      &#34;id&#34;: &#34;bf41zTvm6HAv6xdiXpwGWQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-32728&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. In affected versions of sshd, the DisableForwarding directive does not fully adhere to the intended functionality as documented. Specifically, it fails to disable X11 and agent forwarding, which may allow unintended access under certain configurations.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-04-10T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-32728 https://bugzilla.redhat.com/show_bug.cgi?id=2358767 https://www.cve.org/CVERecord?id=CVE-2025-32728 https://nvd.nist.gov/vuln/detail/CVE-2025-32728 https://lists.mindrot.org/pipermail/openssh-unix-dev/2025-April/041879.html https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-32728.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bg8JYRcvY0wFh5b8Bl6Gmw==&#34;: {&#xA;      &#34;id&#34;: &#34;bg8JYRcvY0wFh5b8Bl6Gmw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42766&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42766 https://bugzilla.redhat.com/show_bug.cgi?id=2481890 https://www.cve.org/CVERecord?id=CVE-2026-42766 https://nvd.nist.gov/vuln/detail/CVE-2026-42766 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42766.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bh7RRRlNP555+LOFASdB0w==&#34;: {&#xA;      &#34;id&#34;: &#34;bh7RRRlNP555+LOFASdB0w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2980&#34;,&#xA;      &#34;description&#34;: &#34;A NULL pointer dereference vulnerability was found in vim&#39;s do_mouse() function of the src/mouse.c file. The issue occurs with a mouse click when it is not initialized. This flaw allows an attacker to trick a user into opening a specially crafted input file, triggering the vulnerability that could cause an application to crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-25T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2980 https://bugzilla.redhat.com/show_bug.cgi?id=2123709 https://www.cve.org/CVERecord?id=CVE-2022-2980 https://nvd.nist.gov/vuln/detail/CVE-2022-2980 https://huntr.dev/bounties/6e7b12a5-242c-453d-b39e-9625d563b0ea https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2980.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bjyLMZdYnkrpUxDySiQ34Q==&#34;: {&#xA;      &#34;id&#34;: &#34;bjyLMZdYnkrpUxDySiQ34Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15468&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. A remote attacker could trigger a NULL pointer dereference by sending an unknown or unsupported cipher ID during the client hello callback in applications using the QUIC (Quick UDP Internet Connections) protocol. This vulnerability, occurring when the SSL_CIPHER_find() function is called in this specific context, leads to an abnormal termination of the running process, causing a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15468 https://bugzilla.redhat.com/show_bug.cgi?id=2430377 https://www.cve.org/CVERecord?id=CVE-2025-15468 https://nvd.nist.gov/vuln/detail/CVE-2025-15468 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15468.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bk6ikdg+f6vAFzgypr0cOw==&#34;: {&#xA;      &#34;id&#34;: &#34;bk6ikdg+f6vAFzgypr0cOw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48618&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. This flaw involves a mismatch in how Node.js handles TLS (Transport Layer Security) hostnames and unicode dot separators during authentication. This mismatch can lead to a wildcard-depth authentication bypass. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access and confidentiality impact.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48618 https://bugzilla.redhat.com/show_bug.cgi?id=2493337 https://www.cve.org/CVERecord?id=CVE-2026-48618 https://nvd.nist.gov/vuln/detail/CVE-2026-48618 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;boWBDvSNZPI7kiGalqeu1g==&#34;: {&#xA;      &#34;id&#34;: &#34;boWBDvSNZPI7kiGalqeu1g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-json&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.7.2-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bpwdCug2xQZhmaazCqwIew==&#34;: {&#xA;      &#34;id&#34;: &#34;bpwdCug2xQZhmaazCqwIew==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-51767&#34;,&#xA;      &#34;description&#34;: &#34;An authentication bypass vulnerability was found in a modified version of OpenSSH. When common types of DRAM memory are used, it might allow row hammer attacks because the integer value of authenticated authpassword does not resist flips of a single bit. Exploiting a Rowhammer-style attack to flip bits in memory, forces successful authentication by setting the return code to 0.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-12-24T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-51767 https://bugzilla.redhat.com/show_bug.cgi?id=2255850 https://www.cve.org/CVERecord?id=CVE-2023-51767 https://nvd.nist.gov/vuln/detail/CVE-2023-51767 https://arxiv.org/abs/2309.02545 https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77 https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-51767.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;br+ShorUFea/O+vyZNDWZQ==&#34;: {&#xA;      &#34;id&#34;: &#34;br+ShorUFea/O+vyZNDWZQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-34459&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the xmllint program distributed by the libxml2 package. A buffer over-read in the xmlHTMLPrintFileContext function in the xmllint.c file may be triggered when a crafted file is processed with the xmllint program using the `--htmlout` command line option, causing an application crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-05-08T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-34459 https://bugzilla.redhat.com/show_bug.cgi?id=2280532 https://www.cve.org/CVERecord?id=CVE-2024-34459 https://nvd.nist.gov/vuln/detail/CVE-2024-34459 https://gitlab.gnome.org/GNOME/libxml2/-/issues/720 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-34459.json https://access.redhat.com/errata/RHSA-2026:28254&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.9.13-14.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;bugTfOdgCaATW4vTnuXTSQ==&#34;: {&#xA;      &#34;id&#34;: &#34;bugTfOdgCaATW4vTnuXTSQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-70873&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in SQLite. This information disclosure vulnerability exists within the zipfile extension, specifically in the zipfileInflate function. A remote attacker could exploit this by providing a specially crafted ZIP file. Successful exploitation could lead to the disclosure of sensitive heap memory information.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-70873 https://bugzilla.redhat.com/show_bug.cgi?id=2447086 https://www.cve.org/CVERecord?id=CVE-2025-70873 https://nvd.nist.gov/vuln/detail/CVE-2025-70873 https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054 https://sqlite.org/forum/forumpost/761eac3c82 https://sqlite.org/src/info/3d459f1fb1bd1b5e https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-70873.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;sqlite&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;c2gL4Z8Tbc2Ge5iwCDCV9Q==&#34;: {&#xA;      &#34;id&#34;: &#34;c2gL4Z8Tbc2Ge5iwCDCV9Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.22-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;c76DQiDMr2npmMChLqBaow==&#34;: {&#xA;      &#34;id&#34;: &#34;c76DQiDMr2npmMChLqBaow==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48928 https://bugzilla.redhat.com/show_bug.cgi?id=2493333 https://www.cve.org/CVERecord?id=CVE-2026-48928 https://nvd.nist.gov/vuln/detail/CVE-2026-48928 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48928.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;cI+dz7I9kKgyQoTuHBA+4Q==&#34;: {&#xA;      &#34;id&#34;: &#34;cI+dz7I9kKgyQoTuHBA+4Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-2229&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the undici WebSocket client. A remote malicious server can exploit this vulnerability by sending a WebSocket frame with an invalid `server_max_window_bits` parameter within the permessage-deflate extension. This improper validation causes the client&#39;s Node.js process to terminate, leading to a denial-of-service (DoS) condition for the client.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:27:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-2229 https://bugzilla.redhat.com/show_bug.cgi?id=2447143 https://www.cve.org/CVERecord?id=CVE-2026-2229 https://nvd.nist.gov/vuln/detail/CVE-2026-2229 https://cna.openjsf.org/security-advisories.html https://datatracker.ietf.org/doc/html/rfc7692 https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8 https://hackerone.com/reports/3487486 https://nodejs.org/api/zlib.html#class-zlibinflateraw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2229.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;cMY+6QfPqyOZE380Mf5rIQ==&#34;: {&#xA;      &#34;id&#34;: &#34;cMY+6QfPqyOZE380Mf5rIQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-0351&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. The vulnerability occurs due to too many recursions, which can lead to a segmentation fault. This flaw allows an attacker to input a specially crafted file, leading to a crash or code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-01-23T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-0351 https://bugzilla.redhat.com/show_bug.cgi?id=2046436 https://www.cve.org/CVERecord?id=CVE-2022-0351 https://nvd.nist.gov/vuln/detail/CVE-2022-0351 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-0351.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;cQ4uQyL9nbrYK9Ka1PjEaQ==&#34;: {&#xA;      &#34;id&#34;: &#34;cQ4uQyL9nbrYK9Ka1PjEaQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59873&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:22:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59873 https://bugzilla.redhat.com/show_bug.cgi?id=2498120 https://www.cve.org/CVERecord?id=CVE-2026-59873 https://nvd.nist.gov/vuln/detail/CVE-2026-59873 https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3 https://github.com/isaacs/node-tar/releases/tag/v7.5.19 https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59873.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;cQHSxL+ZfKCYmJnTVIzcRw==&#34;: {&#xA;      &#34;id&#34;: &#34;cQHSxL+ZfKCYmJnTVIzcRw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48615&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48615 https://bugzilla.redhat.com/show_bug.cgi?id=2493335 https://www.cve.org/CVERecord?id=CVE-2026-48615 https://nvd.nist.gov/vuln/detail/CVE-2026-48615 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48615.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;cXB5uJOI3UJ7dOyNiQwFDg==&#34;: {&#xA;      &#34;id&#34;: &#34;cXB5uJOI3UJ7dOyNiQwFDg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-46195&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was discovered in the GNU libiberty library within the demangle_path() function in rust-demangle.c, as distributed in the GNU Compiler Collection (GCC). This flaw allows a crafted symbol to cause stack memory to be exhausted, leading to a crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-01-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-46195 https://bugzilla.redhat.com/show_bug.cgi?id=2046300 https://www.cve.org/CVERecord?id=CVE-2021-46195 https://nvd.nist.gov/vuln/detail/CVE-2021-46195 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-46195.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gcc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;cebQbn0Dg58LegYW4JDjIA==&#34;: {&#xA;      &#34;id&#34;: &#34;cebQbn0Dg58LegYW4JDjIA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4775&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-24T14:33:35Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4775 https://bugzilla.redhat.com/show_bug.cgi?id=2450768 https://www.cve.org/CVERecord?id=CVE-2026-4775 https://nvd.nist.gov/vuln/detail/CVE-2026-4775 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4775.json https://access.redhat.com/errata/RHSA-2026:19363&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtiff&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:4.4.0-18.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;chGqAT1jYixNKwXlctnUeg==&#34;: {&#xA;      &#34;id&#34;: &#34;chGqAT1jYixNKwXlctnUeg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-59465&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in NodeJS. A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-59465 https://bugzilla.redhat.com/show_bug.cgi?id=2431349 https://www.cve.org/CVERecord?id=CVE-2025-59465 https://nvd.nist.gov/vuln/detail/CVE-2025-59465 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59465.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;cjoCrbQlAeGxtTPUlcMPuA==&#34;: {&#xA;      &#34;id&#34;: &#34;cjoCrbQlAeGxtTPUlcMPuA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-26603&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim&#39;s :redir command. This vulnerability allows a use-after-free condition via redirecting the :display command to a clipboard register (* or +), which allows access to freed memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-18T19:04:24Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-26603 https://bugzilla.redhat.com/show_bug.cgi?id=2346346 https://www.cve.org/CVERecord?id=CVE-2025-26603 https://nvd.nist.gov/vuln/detail/CVE-2025-26603 https://github.com/vim/vim/commit/c0f0e2380e5954f4a52a131bf6b8 https://github.com/vim/vim/security/advisories/GHSA-63p5-mwg2-787v https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-26603.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;cly/G/AvUZQM2J1YMymkpQ==&#34;: {&#xA;      &#34;id&#34;: &#34;cly/G/AvUZQM2J1YMymkpQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66866&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in BinUtils. An attacker can exploit a vulnerability in the `d_abi_tags` function within the `cp-demangle.c` file by providing a specially crafted Portable Executable (PE) file. This can lead to a Denial of Service (DoS), making the affected application unavailable to legitimate users.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66866 https://bugzilla.redhat.com/show_bug.cgi?id=2425830 https://www.cve.org/CVERecord?id=CVE-2025-66866 https://nvd.nist.gov/vuln/detail/CVE-2025-66866 https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66866.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ctALzLE36TiW3KdxIlF4Mw==&#34;: {&#xA;      &#34;id&#34;: &#34;ctALzLE36TiW3KdxIlF4Mw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-8924&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl&#39;s cookie parsing logic. A malicious HTTP server can exploit this by setting &#39;super cookies&#39; that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-03T06:15:04Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-8924 https://bugzilla.redhat.com/show_bug.cgi?id=2496765 https://www.cve.org/CVERecord?id=CVE-2026-8924 https://nvd.nist.gov/vuln/detail/CVE-2026-8924 https://curl.se/docs/CVE-2026-8924.html https://curl.se/docs/CVE-2026-8924.json https://hackerone.com/reports/3733905 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8924.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;cxMZ2TEnkk6RdtuU9fDThg==&#34;: {&#xA;      &#34;id&#34;: &#34;cxMZ2TEnkk6RdtuU9fDThg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-3927&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. A possible heap-based buffer overflow could allow an attacker to input a specially crafted file leading to a crash or code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-10-26T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-3927 https://bugzilla.redhat.com/show_bug.cgi?id=2021290 https://www.cve.org/CVERecord?id=CVE-2021-3927 https://nvd.nist.gov/vuln/detail/CVE-2021-3927 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-3927.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;czyzjx8xL/qpVEGcPiV7Og==&#34;: {&#xA;      &#34;id&#34;: &#34;czyzjx8xL/qpVEGcPiV7Og==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-12086&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client&#39;s machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-01-14T15:06:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-12086 https://bugzilla.redhat.com/show_bug.cgi?id=2330577 https://www.cve.org/CVERecord?id=CVE-2024-12086 https://nvd.nist.gov/vuln/detail/CVE-2024-12086 https://kb.cert.org/vuls/id/952657 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-12086.json https://access.redhat.com/errata/RHSA-2026:19368&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.2.5-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;d+D4c9x4GMdq33+dJrszxQ==&#34;: {&#xA;      &#34;id&#34;: &#34;d+D4c9x4GMdq33+dJrszxQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-19548&#34;,&#xA;      &#34;description&#34;: &#34;Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry-\u003ethe_bfd-\u003emy_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd-\u003emy_archive via bfd_usrdata(abfd-\u003emy_archive)\n2. Line ~1493: multiple accesses to abfd and abfd-\u003emy_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd-\u003emy_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd-\u003emy_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-08-12T13:40:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-19548 https://bugzilla.redhat.com/show_bug.cgi?id=2507832 https://www.cve.org/CVERecord?id=CVE-2026-19548 https://nvd.nist.gov/vuln/detail/CVE-2026-19548 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19548.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;d/522T+B/ARMNSG+3QfAWA==&#34;: {&#xA;      &#34;id&#34;: &#34;d/522T+B/ARMNSG+3QfAWA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22185&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load. When processing malformed input, a local attacker can exploit a heap buffer underflow vulnerability in the readline() function. This can lead to an out-of-bounds read, potentially causing a denial of service (DoS) and limited disclosure of heap memory contents.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-07T20:26:30Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22185 https://bugzilla.redhat.com/show_bug.cgi?id=2427679 https://www.cve.org/CVERecord?id=CVE-2026-22185 https://nvd.nist.gov/vuln/detail/CVE-2026-22185 https://seclists.org/fulldisclosure/2026/Jan/5 https://seclists.org/fulldisclosure/2026/Jan/8 https://www.openldap.org/ https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22185.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openldap&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;d0nPfXoEZybRuV9TMDY3YQ==&#34;: {&#xA;      &#34;id&#34;: &#34;d0nPfXoEZybRuV9TMDY3YQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6253&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy&#39;s credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6253 https://bugzilla.redhat.com/show_bug.cgi?id=2461202 https://www.cve.org/CVERecord?id=CVE-2026-6253 https://nvd.nist.gov/vuln/detail/CVE-2026-6253 https://curl.se/docs/CVE-2026-6253.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6253.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;d28O4EsS+H4v4JSsIykoOg==&#34;: {&#xA;      &#34;id&#34;: &#34;d28O4EsS+H4v4JSsIykoOg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48615&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48615 https://bugzilla.redhat.com/show_bug.cgi?id=2493335 https://www.cve.org/CVERecord?id=CVE-2026-48615 https://nvd.nist.gov/vuln/detail/CVE-2026-48615 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48615.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;d3Z1riL6AkoWkk27zYoWCw==&#34;: {&#xA;      &#34;id&#34;: &#34;d3Z1riL6AkoWkk27zYoWCw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-58055&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in nghttp2&#39;s nghttpx proxy allows a remote attacker to perform HTTP request smuggling and cross-client response-queue poisoning. This occurs because the proxy ambiguously forwards HTTP/1.1 Upgrade requests that contain a Content-Length header to reusable keep-alive backend connections.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-28T01:32:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-58055 https://bugzilla.redhat.com/show_bug.cgi?id=2493954 https://www.cve.org/CVERecord?id=CVE-2026-58055 https://nvd.nist.gov/vuln/detail/CVE-2026-58055 https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58055.json https://access.redhat.com/errata/RHSA-2026:54662&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libnghttp2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.43.0-6.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;d9oy2JiAKtie2N1lu2J6ew==&#34;: {&#xA;      &#34;id&#34;: &#34;d9oy2JiAKtie2N1lu2J6ew==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4224&#34;,&#xA;      &#34;description&#34;: &#34;A stack overflow flaw has been discovered in the python pyexpat module. When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. This will result in a program crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-16T17:52:26Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4224 https://bugzilla.redhat.com/show_bug.cgi?id=2448181 https://www.cve.org/CVERecord?id=CVE-2026-4224 https://nvd.nist.gov/vuln/detail/CVE-2026-4224 https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3 https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768 https://github.com/python/cpython/issues/145986 https://github.com/python/cpython/pull/145987 https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4224.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dDPwWBP+ziJTbpE/idIe+w==&#34;: {&#xA;      &#34;id&#34;: &#34;dDPwWBP+ziJTbpE/idIe+w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34181&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This vulnerability allows a remote attacker to forge PKCS#12 (Public-Key Cryptography Standards #12) files that use Password-Based Message Authentication Code 1 (PBMAC1) with short HMAC (Hash-based Message Authentication Code) keys. This can lead to a service accepting attacker-controlled certificates and private keys with a 1 in 256 probability, potentially enabling impersonation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34181 https://bugzilla.redhat.com/show_bug.cgi?id=2481882 https://www.cve.org/CVERecord?id=CVE-2026-34181 https://nvd.nist.gov/vuln/detail/CVE-2026-34181 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34181.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dKzgwwkG/spsYd8PVvrk6A==&#34;: {&#xA;      &#34;id&#34;: &#34;dKzgwwkG/spsYd8PVvrk6A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-39804&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in tar. This issue occurs when extended attributes are processed in PAX archives, and could allow an attacker to cause an application crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-12-11T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-39804 https://bugzilla.redhat.com/show_bug.cgi?id=2254067 https://www.cve.org/CVERecord?id=CVE-2023-39804 https://nvd.nist.gov/vuln/detail/CVE-2023-39804 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-39804.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dNLHuLPIX/j9HB0bv6uBww==&#34;: {&#xA;      &#34;id&#34;: &#34;dNLHuLPIX/j9HB0bv6uBww==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33636&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng. A remote attacker could exploit an out-of-bounds read and write vulnerability in the ARM/AArch64 Neon-optimized palette expansion path. This occurs when processing a final partial chunk of 8-bit paletted rows without verifying sufficient input pixels, leading to dereferencing pointers before the start of the row buffer and writing expanded pixel data to underflowed positions. This flaw can result in information disclosure and denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-26T16:51:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33636 https://bugzilla.redhat.com/show_bug.cgi?id=2451819 https://www.cve.org/CVERecord?id=CVE-2026-33636 https://nvd.nist.gov/vuln/detail/CVE-2026-33636 https://github.com/pnggroup/libpng/commit/7734cda20cf1236aef60f3bbd2267c97bbb40869 https://github.com/pnggroup/libpng/commit/aba9f18eba870d14fb52c5ba5d73451349e339c3 https://github.com/pnggroup/libpng/security/advisories/GHSA-wjr5-c57x-95m2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33636.json https://access.redhat.com/errata/RHSA-2026:28255&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-15.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dO/rj/SVo/ZlfJAB2ajOEQ==&#34;: {&#xA;      &#34;id&#34;: &#34;dO/rj/SVo/ZlfJAB2ajOEQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-5535&#34;,&#xA;      &#34;description&#34;: &#34;A heap-based buffer overflow vulnerability was found in some affected packages of Vim. This flaw allows an attacker to send a specially crafted file that could lead to a complete system compromise when opened by a victim.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-10-10T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-5535 https://bugzilla.redhat.com/show_bug.cgi?id=2244101 https://www.cve.org/CVERecord?id=CVE-2023-5535 https://nvd.nist.gov/vuln/detail/CVE-2023-5535 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-5535.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dOcg60kDi70nJl9Km2ugWQ==&#34;: {&#xA;      &#34;id&#34;: &#34;dOcg60kDi70nJl9Km2ugWQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4519&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python. The `webbrowser.open()` API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T15:08:32Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4519 https://bugzilla.redhat.com/show_bug.cgi?id=2449649 https://www.cve.org/CVERecord?id=CVE-2026-4519 https://nvd.nist.gov/vuln/detail/CVE-2026-4519 https://github.com/python/cpython/issues/143930 https://github.com/python/cpython/pull/143931 https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4519.json https://access.redhat.com/errata/RHSA-2026:19216&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dQM2EJNgLlaaPe53GlhnMg==&#34;: {&#xA;      &#34;id&#34;: &#34;dQM2EJNgLlaaPe53GlhnMg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34183&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL&#39;s QUIC PATH_CHALLENGE handler. A remote attacker can exploit this vulnerability by flooding a QUIC client or server with specially crafted PATH_CHALLENGE frames. This leads to unbounded memory allocation within the local QUIC stack, as the system continuously allocates PATH_RESPONSE frames without them being acknowledged. The primary consequence is a Denial of Service (DoS), causing the affected application to terminate abnormally due to memory exhaustion.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34183 https://bugzilla.redhat.com/show_bug.cgi?id=2481885 https://www.cve.org/CVERecord?id=CVE-2026-34183 https://nvd.nist.gov/vuln/detail/CVE-2026-34183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34183.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dTHv7xNEey4Rvi0jaC90Ng==&#34;: {&#xA;      &#34;id&#34;: &#34;dTHv7xNEey4Rvi0jaC90Ng==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rake&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:13.1.0-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dXN2fYt7gJPawfay7UcWxA==&#34;: {&#xA;      &#34;id&#34;: &#34;dXN2fYt7gJPawfay7UcWxA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33636&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libpng. A remote attacker could exploit an out-of-bounds read and write vulnerability in the ARM/AArch64 Neon-optimized palette expansion path. This occurs when processing a final partial chunk of 8-bit paletted rows without verifying sufficient input pixels, leading to dereferencing pointers before the start of the row buffer and writing expanded pixel data to underflowed positions. This flaw can result in information disclosure and denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-26T16:51:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33636 https://bugzilla.redhat.com/show_bug.cgi?id=2451819 https://www.cve.org/CVERecord?id=CVE-2026-33636 https://nvd.nist.gov/vuln/detail/CVE-2026-33636 https://github.com/pnggroup/libpng/commit/7734cda20cf1236aef60f3bbd2267c97bbb40869 https://github.com/pnggroup/libpng/commit/aba9f18eba870d14fb52c5ba5d73451349e339c3 https://github.com/pnggroup/libpng/security/advisories/GHSA-wjr5-c57x-95m2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33636.json https://access.redhat.com/errata/RHSA-2026:14791&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dZ7ryQ0b1w50+eNxXX/Jcg==&#34;: {&#xA;      &#34;id&#34;: &#34;dZ7ryQ0b1w50+eNxXX/Jcg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-29111&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-23T21:03:56Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-29111 https://bugzilla.redhat.com/show_bug.cgi?id=2450505 https://www.cve.org/CVERecord?id=CVE-2026-29111 https://nvd.nist.gov/vuln/detail/CVE-2026-29111 https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6 https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8 https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29111.json https://access.redhat.com/errata/RHSA-2026:13677&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-55.el9_7.9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dcH4AHY4X+K0bO3O9nqJrQ==&#34;: {&#xA;      &#34;id&#34;: &#34;dcH4AHY4X+K0bO3O9nqJrQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69652&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted ELF binary file containing malformed DWARF abbrev or debug information with the readelf program using the -w abbrev command line option can trigger an abort, causing a crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69652 https://bugzilla.redhat.com/show_bug.cgi?id=2445296 https://www.cve.org/CVERecord?id=CVE-2025-69652 https://nvd.nist.gov/vuln/detail/CVE-2025-69652 https://sourceware.org/bugzilla/show_bug.cgi?id=33701 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69652.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;doax1FtBT8uwFLYDyWb1Bg==&#34;: {&#xA;      &#34;id&#34;: &#34;doax1FtBT8uwFLYDyWb1Bg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4438&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4438 https://bugzilla.redhat.com/show_bug.cgi?id=2449783 https://www.cve.org/CVERecord?id=CVE-2026-4438 https://nvd.nist.gov/vuln/detail/CVE-2026-4438 https://sourceware.org/bugzilla/show_bug.cgi?id=34015 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4438.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dtQx2uUyC6Kj72i0o1bELQ==&#34;: {&#xA;      &#34;id&#34;: &#34;dtQx2uUyC6Kj72i0o1bELQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35414&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability arises from the incorrect handling of the authorized_keys principals option in uncommon scenarios. Specifically, when a principals list is used with a Certificate Authority that includes comma characters, OpenSSH may misinterpret the input. This could lead to security bypasses, potentially allowing unintended access or information disclosure in specific authentication contexts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T17:08:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35414 https://bugzilla.redhat.com/show_bug.cgi?id=2454490 https://www.cve.org/CVERecord?id=CVE-2026-35414 https://nvd.nist.gov/vuln/detail/CVE-2026-35414 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35414.json https://access.redhat.com/errata/RHSA-2026:13381&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-49.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dw03VWGdtImJ58988UyhtQ==&#34;: {&#xA;      &#34;id&#34;: &#34;dw03VWGdtImJ58988UyhtQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42764&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the OpenSSL QUIC (Quick UDP Internet Connections) server. A remote attacker could send a specially crafted QUIC initial packet with an invalid token. If the server&#39;s address validation is explicitly disabled, this could lead to a NULL pointer dereference, causing the server process to terminate abnormally and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42764 https://bugzilla.redhat.com/show_bug.cgi?id=2481887 https://www.cve.org/CVERecord?id=CVE-2026-42764 https://nvd.nist.gov/vuln/detail/CVE-2026-42764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42764.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dz5oxhJicudEulHfFUUHJw==&#34;: {&#xA;      &#34;id&#34;: &#34;dz5oxhJicudEulHfFUUHJw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-3360&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-3360 https://bugzilla.redhat.com/show_bug.cgi?id=2357754 https://www.cve.org/CVERecord?id=CVE-2025-3360 https://nvd.nist.gov/vuln/detail/CVE-2025-3360 https://gitlab.gnome.org/GNOME/glib/-/issues/3647 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-3360.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;dzniYI3/1uomz0XJinM4FA==&#34;: {&#xA;      &#34;id&#34;: &#34;dzniYI3/1uomz0XJinM4FA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6238&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T16:43:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-locale-source&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;e+FXR06J5tPREKXnCKeZWg==&#34;: {&#xA;      &#34;id&#34;: &#34;e+FXR06J5tPREKXnCKeZWg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-40356&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit an integer underflow and an out-of-bounds read vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the process terminating, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-40356 https://bugzilla.redhat.com/show_bug.cgi?id=2463368 https://www.cve.org/CVERecord?id=CVE-2026-40356 https://nvd.nist.gov/vuln/detail/CVE-2026-40356 https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f https://web.mit.edu/kerberos/advisories/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40356.json https://access.redhat.com/errata/RHSA-2026:19357&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;krb5-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.21.1-10.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;e/EuZlSZUQTHCSl8kHuFag==&#34;: {&#xA;      &#34;id&#34;: &#34;e/EuZlSZUQTHCSl8kHuFag==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11187&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When an application processes a maliciously crafted PKCS#12 file, an attacker can exploit a stack buffer overflow or a NULL pointer dereference. This can lead to a denial of service (DoS) by crashing the application, and in some cases, may enable arbitrary code execution. The vulnerability arises from the lack of validation for PBKDF2 salt and keylength parameters within the PKCS#12 file.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11187 https://bugzilla.redhat.com/show_bug.cgi?id=2430375 https://www.cve.org/CVERecord?id=CVE-2025-11187 https://nvd.nist.gov/vuln/detail/CVE-2025-11187 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11187.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;e/bnYsWq3UNe4TO8qzzb8A==&#34;: {&#xA;      &#34;id&#34;: &#34;e/bnYsWq3UNe4TO8qzzb8A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-47010&#34;,&#xA;      &#34;description&#34;: &#34;A memory leak flaw was found in binutils in the pr_function_type function. This flaw allows an attacker to use a set of steps to trigger a memory leak and perform a denial of service, resulting in a loss of the system&#39;s availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-18T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-47010 https://bugzilla.redhat.com/show_bug.cgi?id=2233988 https://www.cve.org/CVERecord?id=CVE-2022-47010 https://nvd.nist.gov/vuln/detail/CVE-2022-47010 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-47010.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;e0/Fzu8wfMZp9zX32i9rMQ==&#34;: {&#xA;      &#34;id&#34;: &#34;e0/Fzu8wfMZp9zX32i9rMQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27456&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-03T21:23:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27456 https://bugzilla.redhat.com/show_bug.cgi?id=2454956 https://www.cve.org/CVERecord?id=CVE-2026-27456 https://nvd.nist.gov/vuln/detail/CVE-2026-27456 https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4 https://github.com/util-linux/util-linux/releases/tag/v2.41.4 https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27456.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;util-linux&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;e57+W7idPeSI15OIacmH5Q==&#34;: {&#xA;      &#34;id&#34;: &#34;e57+W7idPeSI15OIacmH5Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rdoc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:6.6.3.1-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;e7h3lwyDkLbzwbeza9/TWw==&#34;: {&#xA;      &#34;id&#34;: &#34;e7h3lwyDkLbzwbeza9/TWw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-4293&#34;,&#xA;      &#34;description&#34;: &#34;A floating point exception flaw was found in Vim&#39;s num_divide() function of the eval.c file. This issue occurs when dividing the largest negative number by -1. This could allow an attacker to trick a user into opening a specially crafted file, triggering an application to crash and leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-12-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-4293 https://bugzilla.redhat.com/show_bug.cgi?id=2151566 https://www.cve.org/CVERecord?id=CVE-2022-4293 https://nvd.nist.gov/vuln/detail/CVE-2022-4293 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-4293.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;eM2mlJEyKuGpc2sJMlq4xA==&#34;: {&#xA;      &#34;id&#34;: &#34;eM2mlJEyKuGpc2sJMlq4xA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-3276&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the `unicodedata.normalize()` function in Python. This vulnerability allows a remote attacker to cause excessive CPU consumption by providing specially crafted Unicode input. Successful exploitation can lead to a Denial of Service (DoS) on the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-03T14:29:39Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-3276 https://bugzilla.redhat.com/show_bug.cgi?id=2484424 https://www.cve.org/CVERecord?id=CVE-2026-3276 https://nvd.nist.gov/vuln/detail/CVE-2026-3276 https://github.com/python/cpython/issues/149079 https://github.com/python/cpython/pull/149080 https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3276.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;eWiVyh/zommMEkP0Gx9Oow==&#34;: {&#xA;      &#34;id&#34;: &#34;eWiVyh/zommMEkP0Gx9Oow==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-31790&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-31790 https://bugzilla.redhat.com/show_bug.cgi?id=2451094 https://www.cve.org/CVERecord?id=CVE-2026-31790 https://nvd.nist.gov/vuln/detail/CVE-2026-31790 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31790.json https://access.redhat.com/errata/RHSA-2026:19218&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-2.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;eZAX5+dryNgqi55C7fN1LQ==&#34;: {&#xA;      &#34;id&#34;: &#34;eZAX5+dryNgqi55C7fN1LQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;eaoaQZQXOAlAomwMnyNLSQ==&#34;: {&#xA;      &#34;id&#34;: &#34;eaoaQZQXOAlAomwMnyNLSQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5435&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T11:58:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;edQImQW6OalMt0U0nrXR2Q==&#34;: {&#xA;      &#34;id&#34;: &#34;edQImQW6OalMt0U0nrXR2Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-26996&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in minimatch. A remote attacker could exploit this Regular Expression Denial of Service (ReDoS) vulnerability by providing a specially crafted glob pattern. This pattern, containing numerous consecutive wildcard characters, causes excessive processing and exponential backtracking in the regular expression engine. Successful exploitation leads to a Denial of Service (DoS), making the application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-20T03:05:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-26996 https://bugzilla.redhat.com/show_bug.cgi?id=2441268 https://www.cve.org/CVERecord?id=CVE-2026-26996 https://nvd.nist.gov/vuln/detail/CVE-2026-26996 https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5 https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26996.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;eekbTUpqIafepE8Hfmhn6g==&#34;: {&#xA;      &#34;id&#34;: &#34;eekbTUpqIafepE8Hfmhn6g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-4187&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. A possible use after free vulnerability could allow an attacker to input a specially crafted file leading to a crash or code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-12-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-4187 https://bugzilla.redhat.com/show_bug.cgi?id=2036129 https://www.cve.org/CVERecord?id=CVE-2021-4187 https://nvd.nist.gov/vuln/detail/CVE-2021-4187 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-4187.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;egAiHhCEkMFVMFqpyh1hdw==&#34;: {&#xA;      &#34;id&#34;: &#34;egAiHhCEkMFVMFqpyh1hdw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6733&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici&#39;s HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:14:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6733 https://bugzilla.redhat.com/show_bug.cgi?id=2490006 https://www.cve.org/CVERecord?id=CVE-2026-6733 https://nvd.nist.gov/vuln/detail/CVE-2026-6733 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 https://hackerone.com/reports/3582376 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6733.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;eiMh0pZiJlWSr3FHHfVKhg==&#34;: {&#xA;      &#34;id&#34;: &#34;eiMh0pZiJlWSr3FHHfVKhg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11083&#34;,&#xA;      &#34;description&#34;: &#34;A head based buffer overflow flaw has been discovered in GNU bin utilities. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-27T23:02:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11083 https://bugzilla.redhat.com/show_bug.cgi?id=2399948 https://www.cve.org/CVERecord?id=CVE-2025-11083 https://nvd.nist.gov/vuln/detail/CVE-2025-11083 https://sourceware.org/bugzilla/attachment.cgi?id=16353 https://sourceware.org/bugzilla/show_bug.cgi?id=33457 https://sourceware.org/bugzilla/show_bug.cgi?id=33457#c1 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9ca499644a21ceb3f946d1c179c38a83be084490 https://vuldb.com/?ctiid.326124 https://vuldb.com/?id.326124 https://vuldb.com/?submit.661277 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11083.json https://access.redhat.com/errata/RHSA-2025:23343&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils-gold&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.35.2-67.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;f0N8ZEj6GTGaAo1R6vDhMw==&#34;: {&#xA;      &#34;id&#34;: &#34;f0N8ZEj6GTGaAo1R6vDhMw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-59465&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in NodeJS. A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-59465 https://bugzilla.redhat.com/show_bug.cgi?id=2431349 https://www.cve.org/CVERecord?id=CVE-2025-59465 https://nvd.nist.gov/vuln/detail/CVE-2025-59465 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59465.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;f2M9JeIe3F0Fc9CFbQ6bTQ==&#34;: {&#xA;      &#34;id&#34;: &#34;f2M9JeIe3F0Fc9CFbQ6bTQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-14164&#34;,&#xA;      &#34;description&#34;: &#34;A double free issue has been identified in libarchive&#39;s RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-24T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-14164 https://bugzilla.redhat.com/show_bug.cgi?id=2493411 https://www.cve.org/CVERecord?id=CVE-2026-14164 https://nvd.nist.gov/vuln/detail/CVE-2026-14164 https://github.com/libarchive/libarchive/issues/3069 https://github.com/libarchive/libarchive/pull/3071 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14164.json https://access.redhat.com/errata/RHSA-2026:52674&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;bsdtar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.3-11.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;f6JDKuVN2cqa3h32gmRjXA==&#34;: {&#xA;      &#34;id&#34;: &#34;f6JDKuVN2cqa3h32gmRjXA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-json&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.7.2-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;f6oGdnhZomBa/bs3snB3kA==&#34;: {&#xA;      &#34;id&#34;: &#34;f6oGdnhZomBa/bs3snB3kA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14831&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-09T14:26:34Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14831 https://bugzilla.redhat.com/show_bug.cgi?id=2423177 https://www.cve.org/CVERecord?id=CVE-2025-14831 https://nvd.nist.gov/vuln/detail/CVE-2025-14831 https://gitlab.com/gnutls/gnutls/-/issues/1773 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14831.json https://access.redhat.com/errata/RHSA-2026:4188&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.3-10.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;fKu2JVqQCl/zwzvO3uUkJw==&#34;: {&#xA;      &#34;id&#34;: &#34;fKu2JVqQCl/zwzvO3uUkJw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-26996&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in minimatch. A remote attacker could exploit this Regular Expression Denial of Service (ReDoS) vulnerability by providing a specially crafted glob pattern. This pattern, containing numerous consecutive wildcard characters, causes excessive processing and exponential backtracking in the regular expression engine. Successful exploitation leads to a Denial of Service (DoS), making the application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-20T03:05:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-26996 https://bugzilla.redhat.com/show_bug.cgi?id=2441268 https://www.cve.org/CVERecord?id=CVE-2026-26996 https://nvd.nist.gov/vuln/detail/CVE-2026-26996 https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5 https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26996.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;fPh6cJ7fj6ecJeD/S/iyJg==&#34;: {&#xA;      &#34;id&#34;: &#34;fPh6cJ7fj6ecJeD/S/iyJg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-58015&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-08T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-58015 https://bugzilla.redhat.com/show_bug.cgi?id=2492256 https://www.cve.org/CVERecord?id=CVE-2026-58015 https://nvd.nist.gov/vuln/detail/CVE-2026-58015 https://gitlab.gnome.org/GNOME/glib/-/issues/3931 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58015.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;fSeU4QTAs+fY+ihLpgdM9A==&#34;: {&#xA;      &#34;id&#34;: &#34;fSeU4QTAs+fY+ihLpgdM9A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-1377&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GNU elfutils. This vulnerability allows denial of service via manipulation of the gelf_getsymshndx function in strip.c.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-17T05:00:19Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-1377 https://bugzilla.redhat.com/show_bug.cgi?id=2346066 https://www.cve.org/CVERecord?id=CVE-2025-1377 https://nvd.nist.gov/vuln/detail/CVE-2025-1377 https://sourceware.org/bugzilla/attachment.cgi?id=15941 https://sourceware.org/bugzilla/show_bug.cgi?id=32673 https://sourceware.org/bugzilla/show_bug.cgi?id=32673#c2 https://vuldb.com/?ctiid.295985 https://vuldb.com/?id.295985 https://vuldb.com/?submit.497539 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1377.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;elfutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ffV5WUu4x4B5YykIdxqFhA==&#34;: {&#xA;      &#34;id&#34;: &#34;ffV5WUu4x4B5YykIdxqFhA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42764&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the OpenSSL QUIC (Quick UDP Internet Connections) server. A remote attacker could send a specially crafted QUIC initial packet with an invalid token. If the server&#39;s address validation is explicitly disabled, this could lead to a NULL pointer dereference, causing the server process to terminate abnormally and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42764 https://bugzilla.redhat.com/show_bug.cgi?id=2481887 https://www.cve.org/CVERecord?id=CVE-2026-42764 https://nvd.nist.gov/vuln/detail/CVE-2026-42764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42764.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;fqP9GV2+ELPjUr/DY2avpQ==&#34;: {&#xA;      &#34;id&#34;: &#34;fqP9GV2+ELPjUr/DY2avpQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1525&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici, a Node.js HTTP/1.1 client. A remote attacker could exploit this vulnerability by sending HTTP/1.1 requests that include duplicate Content-Length headers with different casing (e.g., \&#34;Content-Length\&#34; and \&#34;content-length\&#34;). This can lead to HTTP Request Smuggling, a technique where an attacker sends an ambiguous request that is interpreted differently by a proxy and a backend server. Successful exploitation could result in unauthorized access, cache poisoning, or credential hijacking. It may also cause a Denial of Service (DoS) if strict HTTP parsers reject the malformed requests.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T19:56:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1525 https://bugzilla.redhat.com/show_bug.cgi?id=2447144 https://www.cve.org/CVERecord?id=CVE-2026-1525 https://nvd.nist.gov/vuln/detail/CVE-2026-1525 https://cna.openjsf.org/security-advisories.html https://cwe.mitre.org/data/definitions/444.html https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm https://hackerone.com/reports/3556037 https://www.rfc-editor.org/rfc/rfc9110.html#section-8.6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1525.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;fuOmX+MQWgJjrWZ2kXbtlQ==&#34;: {&#xA;      &#34;id&#34;: &#34;fuOmX+MQWgJjrWZ2kXbtlQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0672&#34;,&#xA;      &#34;description&#34;: &#34;An injection flaw has been discovered in Python. When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:52:33Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0672 https://bugzilla.redhat.com/show_bug.cgi?id=2431374 https://www.cve.org/CVERecord?id=CVE-2026-0672 https://nvd.nist.gov/vuln/detail/CVE-2026-0672 https://github.com/python/cpython/issues/143919 https://github.com/python/cpython/pull/143920 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0672.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;fzE91AQotuZJ8swhDTTd+g==&#34;: {&#xA;      &#34;id&#34;: &#34;fzE91AQotuZJ8swhDTTd+g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14087&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14087 https://bugzilla.redhat.com/show_bug.cgi?id=2419093 https://www.cve.org/CVERecord?id=CVE-2025-14087 https://nvd.nist.gov/vuln/detail/CVE-2025-14087 https://gitlab.gnome.org/GNOME/glib/-/issues/3834 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14087.json https://access.redhat.com/errata/RHSA-2026:19361&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-19.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;g6spFzT6DoopzuQCE0pjRg==&#34;: {&#xA;      &#34;id&#34;: &#34;g6spFzT6DoopzuQCE0pjRg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2285&#34;,&#xA;      &#34;description&#34;: &#34;Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-07-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2285 https://bugzilla.redhat.com/show_bug.cgi?id=2103874 https://www.cve.org/CVERecord?id=CVE-2022-2285 https://nvd.nist.gov/vuln/detail/CVE-2022-2285 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2285.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;g7YHFtZ3mWRLeNfv7s6g4w==&#34;: {&#xA;      &#34;id&#34;: &#34;g7YHFtZ3mWRLeNfv7s6g4w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0865&#34;,&#xA;      &#34;description&#34;: &#34;Missing newline filtering has been discovered in Python. User-controlled header names and values containing newlines can allow injecting HTTP headers.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:26:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0865 https://bugzilla.redhat.com/show_bug.cgi?id=2431367 https://www.cve.org/CVERecord?id=CVE-2026-0865 https://nvd.nist.gov/vuln/detail/CVE-2026-0865 https://github.com/python/cpython/issues/143916 https://github.com/python/cpython/pull/143917 https://mail.python.org/archives/list/security-announce@python.org/thread/BJ6QPHNSHJTS3A7CFV6IBMCAP2DWRVNT/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0865.json https://access.redhat.com/errata/RHSA-2026:18693&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-5.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gBKPfFUBWkIoh/DpIktgJA==&#34;: {&#xA;      &#34;id&#34;: &#34;gBKPfFUBWkIoh/DpIktgJA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-default-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gET5R3f4XDkfL+cBxb3pJQ==&#34;: {&#xA;      &#34;id&#34;: &#34;gET5R3f4XDkfL+cBxb3pJQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4046&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T17:16:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gFKfr+coMvRSD0OxrJHXPQ==&#34;: {&#xA;      &#34;id&#34;: &#34;gFKfr+coMvRSD0OxrJHXPQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55131&#34;,&#xA;      &#34;description&#34;: &#34;A memory exposure flaw has been discovered in Node.js. A flaw in Node.js&#39;s buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain leftover data from previous operations, allowing in-process secrets like tokens or passwords to leak or causing data corruption.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55131 https://bugzilla.redhat.com/show_bug.cgi?id=2431350 https://www.cve.org/CVERecord?id=CVE-2025-55131 https://nvd.nist.gov/vuln/detail/CVE-2025-55131 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55131.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gGrGej/Pj6/poAgebFb+dg==&#34;: {&#xA;      &#34;id&#34;: &#34;gGrGej/Pj6/poAgebFb+dg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3352&#34;,&#xA;      &#34;description&#34;: &#34;Use After Free in GitHub repository vim/vim prior to 9.0.0614.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3352 https://bugzilla.redhat.com/show_bug.cgi?id=2131087 https://www.cve.org/CVERecord?id=CVE-2022-3352 https://nvd.nist.gov/vuln/detail/CVE-2022-3352 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3352.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gNGv6C2nj/tHk2ntVJUOWw==&#34;: {&#xA;      &#34;id&#34;: &#34;gNGv6C2nj/tHk2ntVJUOWw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-47011&#34;,&#xA;      &#34;description&#34;: &#34;A memory leak flaw was found in binutils. This flaw allows an attacker to use a set of steps to trigger a memory leak and perform a denial of service, resulting in a loss of the system&#39;s availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-18T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-47011 https://bugzilla.redhat.com/show_bug.cgi?id=2233992 https://www.cve.org/CVERecord?id=CVE-2022-47011 https://nvd.nist.gov/vuln/detail/CVE-2022-47011 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-47011.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gPjSjC7XxsCvs5w6EQPViQ==&#34;: {&#xA;      &#34;id&#34;: &#34;gPjSjC7XxsCvs5w6EQPViQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-68160&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This vulnerability involves an out-of-bounds write in the line-buffering BIO filter, which can lead to memory corruption. While exploitation is unlikely to be under direct attacker control, a successful attack could cause an application to crash, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-68160 https://bugzilla.redhat.com/show_bug.cgi?id=2430380 https://www.cve.org/CVERecord?id=CVE-2025-68160 https://nvd.nist.gov/vuln/detail/CVE-2025-68160 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68160.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gRH01HjqQn159522OfR71A==&#34;: {&#xA;      &#34;id&#34;: &#34;gRH01HjqQn159522OfR71A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9678&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Undici. The cache interceptor in shared-cache mode incorrectly classifies certain responses as cacheable due to improper handling of whitespace-padded Cache-Control header field names. This vulnerability allows an unauthenticated attacker to access authenticated user data from the cache, leading to information disclosure. This occurs when both authenticated and unauthenticated requests resolve to the same cache key.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:04:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9678 https://bugzilla.redhat.com/show_bug.cgi?id=2490000 https://www.cve.org/CVERecord?id=CVE-2026-9678 https://nvd.nist.gov/vuln/detail/CVE-2026-9678 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9678.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gSYlqWWhsq36L2EzWb/x+w==&#34;: {&#xA;      &#34;id&#34;: &#34;gSYlqWWhsq36L2EzWb/x+w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rake&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:13.1.0-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gg6QYPBlPoN8zpwNyr7x6w==&#34;: {&#xA;      &#34;id&#34;: &#34;gg6QYPBlPoN8zpwNyr7x6w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-29111&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-23T21:03:56Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-29111 https://bugzilla.redhat.com/show_bug.cgi?id=2450505 https://www.cve.org/CVERecord?id=CVE-2026-29111 https://nvd.nist.gov/vuln/detail/CVE-2026-29111 https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6 https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8 https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29111.json https://access.redhat.com/errata/RHSA-2026:13677&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-55.el9_7.9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gjKjRZqPuBXFD+3YZ4GvNg==&#34;: {&#xA;      &#34;id&#34;: &#34;gjKjRZqPuBXFD+3YZ4GvNg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-25547&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the brace-expansion component. This denial of service (DoS) vulnerability allows a remote attacker to provide specially crafted input containing repeated numeric brace ranges. This input causes the library to attempt an unbounded expansion, consuming excessive CPU and memory resources. This can lead to a system crash, impacting the availability of the service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-04T21:51:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-25547 https://bugzilla.redhat.com/show_bug.cgi?id=2436942 https://www.cve.org/CVERecord?id=CVE-2026-25547 https://nvd.nist.gov/vuln/detail/CVE-2026-25547 https://github.com/isaacs/brace-expansion/security/advisories/GHSA-7h2j-956f-4vf2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25547.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;glhykijCt1euysZQdgNP+A==&#34;: {&#xA;      &#34;id&#34;: &#34;glhykijCt1euysZQdgNP+A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4046&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T17:16:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-langpack-en&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gn3bQe/78AdzPhooNm1KQw==&#34;: {&#xA;      &#34;id&#34;: &#34;gn3bQe/78AdzPhooNm1KQw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66293&#34;,&#xA;      &#34;description&#34;: &#34;An out of bounds read vulnerability has been discovered in libpng. This vulnerability is in libpng&#39;s simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng&#39;s internal state management.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-03T20:33:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66293 https://bugzilla.redhat.com/show_bug.cgi?id=2418711 https://www.cve.org/CVERecord?id=CVE-2025-66293 https://nvd.nist.gov/vuln/detail/CVE-2025-66293 https://github.com/pnggroup/libpng/commit/788a624d7387a758ffd5c7ab010f1870dea753a1 https://github.com/pnggroup/libpng/commit/a05a48b756de63e3234ea6b3b938b8f5f862484a https://github.com/pnggroup/libpng/issues/764 https://github.com/pnggroup/libpng/security/advisories/GHSA-9mpm-9pxh-mg4f https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66293.json https://access.redhat.com/errata/RHSA-2026:0238&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gpPTgXxcA95Uk2vaf3/2dw==&#34;: {&#xA;      &#34;id&#34;: &#34;gpPTgXxcA95Uk2vaf3/2dw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-45803&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in urllib3, an HTTP client library for Python. urllib3 doesn&#39;t remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303, after changing the method in a request from one that could accept a request body such as `POST` to `GET`, as is required by HTTP RFCs. This issue requires a previously trusted service to become compromised in order to have an impact on confidentiality, therefore, the exploitability of this vulnerability is low. Additionally, many users aren&#39;t putting sensitive data in HTTP request bodies; if this is the case, this vulnerability isn&#39;t exploitable.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-10-13T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-45803 https://bugzilla.redhat.com/show_bug.cgi?id=2246840 https://www.cve.org/CVERecord?id=CVE-2023-45803 https://nvd.nist.gov/vuln/detail/CVE-2023-45803 https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9 https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4 https://www.rfc-editor.org/rfc/rfc9110.html#name-get https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-45803.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-pip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;gt3d97KykHIhCqEzLKzqHQ==&#34;: {&#xA;      &#34;id&#34;: &#34;gt3d97KykHIhCqEzLKzqHQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.22-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;guG+lyS5JQIDSZS6MEfIow==&#34;: {&#xA;      &#34;id&#34;: &#34;guG+lyS5JQIDSZS6MEfIow==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11840&#34;,&#xA;      &#34;description&#34;: &#34;An out of bounds read flaw has been discovered in GNU binutils. The `vfinfo` function in the `ldmisc.c` file. Exploitation of this flaw requires local access and may cause a program crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-16T15:32:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11840 https://bugzilla.redhat.com/show_bug.cgi?id=2404481 https://www.cve.org/CVERecord?id=CVE-2025-11840 https://nvd.nist.gov/vuln/detail/CVE-2025-11840 https://sourceware.org/bugzilla/attachment.cgi?id=16351 https://sourceware.org/bugzilla/attachment.cgi?id=16357 https://sourceware.org/bugzilla/show_bug.cgi?id=33455 https://vuldb.com/?ctiid.328775 https://vuldb.com/?id.328775 https://vuldb.com/?submit.661281 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11840.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;h+nOQU6khNxAH7kkGqVqkQ==&#34;: {&#xA;      &#34;id&#34;: &#34;h+nOQU6khNxAH7kkGqVqkQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3296&#34;,&#xA;      &#34;description&#34;: &#34;A stack-based buffer overflow vulnerability was found in vim&#39;s ex_finally() function of the src/ex_eval.c file. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a bug that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-25T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3296 https://bugzilla.redhat.com/show_bug.cgi?id=2129835 https://www.cve.org/CVERecord?id=CVE-2022-3296 https://nvd.nist.gov/vuln/detail/CVE-2022-3296 https://huntr.dev/bounties/958866b8-526a-4979-9471-39392e0c9077 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3296.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;hHDtCxiuvJ9VSCSwnEG0Fw==&#34;: {&#xA;      &#34;id&#34;: &#34;hHDtCxiuvJ9VSCSwnEG0Fw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27135&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 frame, leading to an assertion failure and a denial of service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-18T17:59:02Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27135 https://bugzilla.redhat.com/show_bug.cgi?id=2448754 https://www.cve.org/CVERecord?id=CVE-2026-27135 https://nvd.nist.gov/vuln/detail/CVE-2026-27135 https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1 https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json https://access.redhat.com/errata/RHSA-2026:7668&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libnghttp2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.43.0-6.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;hLNqQASPtA3T5zDQurOMBA==&#34;: {&#xA;      &#34;id&#34;: &#34;hLNqQASPtA3T5zDQurOMBA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-15308&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python. Its incremental HTML parser can be exploited by a remote attacker. By sending specially crafted, uncontrolled data with repeated, incomplete markup declarations, the attacker can cause the system to consume excessive central processing unit (CPU) resources. This leads to a denial of service, making the affected system unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-09T17:10:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-15308 https://bugzilla.redhat.com/show_bug.cgi?id=2498608 https://www.cve.org/CVERecord?id=CVE-2026-15308 https://nvd.nist.gov/vuln/detail/CVE-2026-15308 https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9 https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606 https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd https://github.com/python/cpython/issues/153030 https://github.com/python/cpython/pull/153031 https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15308.json https://access.redhat.com/errata/RHSA-2026:39798&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-7.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;hLbfRT5oTN6ilWiJVmH5Uw==&#34;: {&#xA;      &#34;id&#34;: &#34;hLbfRT5oTN6ilWiJVmH5Uw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-bundled-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;hMMTiPhU7F2ErldK8mMkDQ==&#34;: {&#xA;      &#34;id&#34;: &#34;hMMTiPhU7F2ErldK8mMkDQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48615&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48615 https://bugzilla.redhat.com/show_bug.cgi?id=2493335 https://www.cve.org/CVERecord?id=CVE-2026-48615 https://nvd.nist.gov/vuln/detail/CVE-2026-48615 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48615.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;hUC86VV8kD262xFcev0ZiA==&#34;: {&#xA;      &#34;id&#34;: &#34;hUC86VV8kD262xFcev0ZiA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11412&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted object file with the ld linker can trigger an out-of-bounds read in the bfd_elf_gc_record_vtentry function in the bfd/elflink.c file due to a missing sanity check, causing a crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-07T22:02:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11412 https://bugzilla.redhat.com/show_bug.cgi?id=2402425 https://www.cve.org/CVERecord?id=CVE-2025-11412 https://nvd.nist.gov/vuln/detail/CVE-2025-11412 https://sourceware.org/bugzilla/show_bug.cgi?id=33452 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=047435dd988a3975d40c6626a8f739a0b2e154bc https://vuldb.com/?id.327348 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11412.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;hUsu+oNx2zrpqDVbukPejw==&#34;: {&#xA;      &#34;id&#34;: &#34;hUsu+oNx2zrpqDVbukPejw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0865&#34;,&#xA;      &#34;description&#34;: &#34;Missing newline filtering has been discovered in Python. User-controlled header names and values containing newlines can allow injecting HTTP headers.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:26:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0865 https://bugzilla.redhat.com/show_bug.cgi?id=2431367 https://www.cve.org/CVERecord?id=CVE-2026-0865 https://nvd.nist.gov/vuln/detail/CVE-2026-0865 https://github.com/python/cpython/issues/143916 https://github.com/python/cpython/pull/143917 https://mail.python.org/archives/list/security-announce@python.org/thread/BJ6QPHNSHJTS3A7CFV6IBMCAP2DWRVNT/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0865.json https://access.redhat.com/errata/RHSA-2026:18693&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-5.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;haC60dPgMQIFAnJX4zid+A==&#34;: {&#xA;      &#34;id&#34;: &#34;haC60dPgMQIFAnJX4zid+A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rdoc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:6.6.3.1-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;haEbUAG+u1TE1V7073rUjA==&#34;: {&#xA;      &#34;id&#34;: &#34;haEbUAG+u1TE1V7073rUjA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bigdecimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.1.5-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;hbenTywo0l7anle5/bJQBw==&#34;: {&#xA;      &#34;id&#34;: &#34;hbenTywo0l7anle5/bJQBw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34182&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL&#39;s Cryptographic Message Services (CMS) AuthEnvelopedData processing. An on-path attacker can exploit insufficient input validation on cipher and tag length fields by sending specially crafted CMS messages. This can lead to the forging of messages or bypassing integrity validation. Consequently, an attacker may achieve key-equivalent functionality for a given CMS recipient.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34182 https://bugzilla.redhat.com/show_bug.cgi?id=2481884 https://www.cve.org/CVERecord?id=CVE-2026-34182 https://nvd.nist.gov/vuln/detail/CVE-2026-34182 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34182.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;hxluEp8Si16NQcfaJDWcLg==&#34;: {&#xA;      &#34;id&#34;: &#34;hxluEp8Si16NQcfaJDWcLg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3324&#34;,&#xA;      &#34;description&#34;: &#34;A stack-based buffer overflow vulnerability was found in Vim&#39;s win_redr_ruler() function of the src/drawscreen.c file. The issue occurs when using a negative array index with a negative width window. This flaw allows an attacker to trick a user into opening a specially crafted file, which triggers the bug, causing an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-28T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3324 https://bugzilla.redhat.com/show_bug.cgi?id=2132558 https://www.cve.org/CVERecord?id=CVE-2022-3324 https://nvd.nist.gov/vuln/detail/CVE-2022-3324 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3324.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;hxsQAGbTfRAveju4VaX/RA==&#34;: {&#xA;      &#34;id&#34;: &#34;hxsQAGbTfRAveju4VaX/RA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21637&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21637 https://bugzilla.redhat.com/show_bug.cgi?id=2431340 https://www.cve.org/CVERecord?id=CVE-2026-21637 https://nvd.nist.gov/vuln/detail/CVE-2026-21637 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21637.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;i2CsObRdsFCFCIvnyVzw5g==&#34;: {&#xA;      &#34;id&#34;: &#34;i2CsObRdsFCFCIvnyVzw5g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66863&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in BinUtils. Attackers can exploit this vulnerability by providing a specially crafted Portable Executable (PE) file. This can lead to a denial of service, making the affected application unavailable.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66863 https://bugzilla.redhat.com/show_bug.cgi?id=2425824 https://www.cve.org/CVERecord?id=CVE-2025-66863 https://nvd.nist.gov/vuln/detail/CVE-2025-66863 https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66863.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;i6aHe7Qjo768bvS9xSorFw==&#34;: {&#xA;      &#34;id&#34;: &#34;i6aHe7Qjo768bvS9xSorFw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-40403&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libxslt package. Processing web content may disclose sensitive information. This issue was addressed with improved memory handling.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-09-26T20:14:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-40403 https://bugzilla.redhat.com/show_bug.cgi?id=2349766 https://www.cve.org/CVERecord?id=CVE-2023-40403 https://nvd.nist.gov/vuln/detail/CVE-2023-40403 http://seclists.org/fulldisclosure/2023/Oct/10 http://seclists.org/fulldisclosure/2023/Oct/3 http://seclists.org/fulldisclosure/2023/Oct/4 http://seclists.org/fulldisclosure/2023/Oct/5 http://seclists.org/fulldisclosure/2023/Oct/6 http://seclists.org/fulldisclosure/2023/Oct/8 http://seclists.org/fulldisclosure/2023/Oct/9 https://bugs.chromium.org/p/chromium/issues/detail?id=1356211 https://bugzilla.gnome.org/show_bug.cgi?id=751621 https://gitlab.gnome.org/GNOME/libxslt/-/issues/94 https://support.apple.com/en-us/HT213927 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-40403.json https://access.redhat.com/errata/RHSA-2026:6266&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxslt&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.1.34-14.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;i9sUrKKUObLH200e/JvjcA==&#34;: {&#xA;      &#34;id&#34;: &#34;i9sUrKKUObLH200e/JvjcA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59873&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:22:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59873 https://bugzilla.redhat.com/show_bug.cgi?id=2498120 https://www.cve.org/CVERecord?id=CVE-2026-59873 https://nvd.nist.gov/vuln/detail/CVE-2026-59873 https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3 https://github.com/isaacs/node-tar/releases/tag/v7.5.19 https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59873.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;iCq8lbTZO3yBSlU4d4JPMQ==&#34;: {&#xA;      &#34;id&#34;: &#34;iCq8lbTZO3yBSlU4d4JPMQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-59466&#34;,&#xA;      &#34;description&#34;: &#34;A stack overflow flaw has been discovered in Node.js error handling where \&#34;Maximum call stack size exceeded\&#34; errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on(&#39;uncaughtException&#39;)`, the process terminates, making the crash unrecoverable. Applications that rely on `AsyncLocalStorage` (v22, v20) or `async_hooks.createHook()` (v24, v22, v20) become vulnerable to denial-of-service crashes triggered by deep recursion under specific conditions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-59466 https://bugzilla.redhat.com/show_bug.cgi?id=2431343 https://www.cve.org/CVERecord?id=CVE-2025-59466 https://nvd.nist.gov/vuln/detail/CVE-2025-59466 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59466.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;iF/o4aDbQf1DAw7R+LiVQw==&#34;: {&#xA;      &#34;id&#34;: &#34;iF/o4aDbQf1DAw7R+LiVQw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-68972&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GnuPG. An adversary can exploit this vulnerability by crafting a signed message that includes a form feed character (\\f) at the end of a plaintext line. This allows the adversary to append additional, unsigned text to the message while the signature verification still reports success. This issue leads to an integrity bypass, potentially enabling the spoofing of signed communications.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-27T22:52:30Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-68972 https://bugzilla.redhat.com/show_bug.cgi?id=2425646 https://www.cve.org/CVERecord?id=CVE-2025-68972 https://nvd.nist.gov/vuln/detail/CVE-2025-68972 https://gpg.fail/formfeed https://news.ycombinator.com/item?id=46404339 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68972.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnupg2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;iFdXYPdbzmitrrthD7u8yA==&#34;: {&#xA;      &#34;id&#34;: &#34;iFdXYPdbzmitrrthD7u8yA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59874&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:23:47Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59874 https://bugzilla.redhat.com/show_bug.cgi?id=2498116 https://www.cve.org/CVERecord?id=CVE-2026-59874 https://nvd.nist.gov/vuln/detail/CVE-2026-59874 https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59874.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;iSzOvPxPGZr2PfJTBTQBCQ==&#34;: {&#xA;      &#34;id&#34;: &#34;iSzOvPxPGZr2PfJTBTQBCQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-29040&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the tpm2-tss package, where it was not checked to see if the magic number in the attest is equal to the TPM2_GENERATED_VALUE. This flaw allows an attacker to generate arbitrary quote data, which may not be detected by Fapi_VerifyQuote.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-04-30T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-29040 https://bugzilla.redhat.com/show_bug.cgi?id=2278077 https://www.cve.org/CVERecord?id=CVE-2024-29040 https://nvd.nist.gov/vuln/detail/CVE-2024-29040 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-29040.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tpm2-tss&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;iT0wLV5um6Novvux5XEDSA==&#34;: {&#xA;      &#34;id&#34;: &#34;iT0wLV5um6Novvux5XEDSA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.22-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;iYahLjRBvYk4Zq4Nz9JtHg==&#34;: {&#xA;      &#34;id&#34;: &#34;iYahLjRBvYk4Zq4Nz9JtHg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-66382&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. This vulnerability allows a denial of service (DoS) by processing a crafted file with an approximate size of 2 MiB, leading to dozens of seconds of processing time.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-28T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-66382 https://bugzilla.redhat.com/show_bug.cgi?id=2417661 https://www.cve.org/CVERecord?id=CVE-2025-66382 https://nvd.nist.gov/vuln/detail/CVE-2025-66382 https://github.com/libexpat/libexpat/issues/1076 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66382.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;idDdN00zXJT8ntMCqQfdkA==&#34;: {&#xA;      &#34;id&#34;: &#34;idDdN00zXJT8ntMCqQfdkA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35414&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability arises from the incorrect handling of the authorized_keys principals option in uncommon scenarios. Specifically, when a principals list is used with a Certificate Authority that includes comma characters, OpenSSH may misinterpret the input. This could lead to security bypasses, potentially allowing unintended access or information disclosure in specific authentication contexts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T17:08:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35414 https://bugzilla.redhat.com/show_bug.cgi?id=2454490 https://www.cve.org/CVERecord?id=CVE-2026-35414 https://nvd.nist.gov/vuln/detail/CVE-2026-35414 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35414.json https://access.redhat.com/errata/RHSA-2026:19219&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;iwe2PkNe91EUwDENn+pmew==&#34;: {&#xA;      &#34;id&#34;: &#34;iwe2PkNe91EUwDENn+pmew==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-40468&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gawk. An integer overflow vulnerability could allow a local attacker to cause memory exhaustion, leading to a denial of service. This flaw may also enable an attacker to corrupt gawk&#39;s internal memory, potentially leading to system instability.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-13T12:07:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-40468 https://bugzilla.redhat.com/show_bug.cgi?id=2499655 https://www.cve.org/CVERecord?id=CVE-2026-40468 https://nvd.nist.gov/vuln/detail/CVE-2026-40468 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40468.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gawk&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ixD2h349uZz3eCy55KxIlw==&#34;: {&#xA;      &#34;id&#34;: &#34;ixD2h349uZz3eCy55KxIlw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69421&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by providing a specially crafted, malformed PKCS#12 file to an application that processes it. The flaw occurs due to a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function when handling the malformed file, leading to an application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69421 https://bugzilla.redhat.com/show_bug.cgi?id=2430387 https://www.cve.org/CVERecord?id=CVE-2025-69421 https://nvd.nist.gov/vuln/detail/CVE-2025-69421 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69421.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ixc06f0H9vqMfsbwQSwwvA==&#34;: {&#xA;      &#34;id&#34;: &#34;ixc06f0H9vqMfsbwQSwwvA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-32636&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-12-14T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-32636 https://bugzilla.redhat.com/show_bug.cgi?id=2211833 https://www.cve.org/CVERecord?id=CVE-2023-32636 https://nvd.nist.gov/vuln/detail/CVE-2023-32636 https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835 https://gitlab.gnome.org/GNOME/glib/-/issues/2841 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-32636.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;j/vFtwZCr4ow5q2VPKgR9g==&#34;: {&#xA;      &#34;id&#34;: &#34;j/vFtwZCr4ow5q2VPKgR9g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69418&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When applications directly call the low-level CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions with non-block-aligned lengths in a single call on hardware-accelerated builds, the trailing 1-15 bytes of a message may be exposed in cleartext. These exposed bytes are not covered by the authentication tag, allowing an attacker to read or tamper with them without detection.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69418 https://bugzilla.redhat.com/show_bug.cgi?id=2430381 https://www.cve.org/CVERecord?id=CVE-2025-69418 https://nvd.nist.gov/vuln/detail/CVE-2025-69418 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69418.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;j2qyk9XQmGp7ssMhZKM8jg==&#34;: {&#xA;      &#34;id&#34;: &#34;j2qyk9XQmGp7ssMhZKM8jg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-25749&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open source, command line text editor. This heap buffer overflow vulnerability exists in the tag file resolution logic when processing the &#39;helpfile&#39; option. A local user could exploit this by providing a specially crafted &#39;helpfile&#39; option value, leading to a heap buffer overflow. This could result in arbitrary code execution or a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-06T22:43:38Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-25749 https://bugzilla.redhat.com/show_bug.cgi?id=2437843 https://www.cve.org/CVERecord?id=CVE-2026-25749 https://nvd.nist.gov/vuln/detail/CVE-2026-25749 https://github.com/vim/vim/commit/0714b15940b245108e6e9d7aa2260dd849a26fa9 https://github.com/vim/vim/releases/tag/v9.1.2132 https://github.com/vim/vim/security/advisories/GHSA-5w93-4g67-mm43 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25749.json https://access.redhat.com/errata/RHSA-2026:5602&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim-minimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:8.2.2637-23.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;j3PAipb/hCxnbdoUmJvkNQ==&#34;: {&#xA;      &#34;id&#34;: &#34;j3PAipb/hCxnbdoUmJvkNQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-61984&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH where control characters in usernames were not properly validated when sourced from untrusted inputs like the command line or configuration expansion. If a ProxyCommand is used, these control characters could modify command behavior, potentially leading to code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-61984 https://bugzilla.redhat.com/show_bug.cgi?id=2401960 https://www.cve.org/CVERecord?id=CVE-2025-61984 https://nvd.nist.gov/vuln/detail/CVE-2025-61984 https://marc.info/?l=openssh-unix-dev\u0026m=175974522032149\u0026w=2 https://www.openssh.com/releasenotes.html#10.1p1 https://www.openwall.com/lists/oss-security/2025/10/06/1 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61984.json https://access.redhat.com/errata/RHSA-2025:23480&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-47.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;j71n+HvL+1UIm3Tw+EUHpw==&#34;: {&#xA;      &#34;id&#34;: &#34;j71n+HvL+1UIm3Tw+EUHpw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59999&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in `sshd`, the OpenSSH server daemon. When `DisableForwarding=yes` is configured to prevent network traffic forwarding, it incorrectly fails to take precedence over `PermitTunnel=yes`. This allows a remote attacker to bypass intended security restrictions and establish a tunnel, potentially leading to unauthorized network access or circumvention of security policies, even when forwarding is explicitly disabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T00:13:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59999 https://bugzilla.redhat.com/show_bug.cgi?id=2497942 https://www.cve.org/CVERecord?id=CVE-2026-59999 https://nvd.nist.gov/vuln/detail/CVE-2026-59999 https://marc.info/?l=openssh-unix-dev\u0026m=178333966933090\u0026w=2 https://www.openssh.org/releasenotes.html#10.4p1 https://www.openwall.com/lists/oss-security/2026/07/06/5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59999.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;j7yoSCks+i8LevHtgFwCwQ==&#34;: {&#xA;      &#34;id&#34;: &#34;j7yoSCks+i8LevHtgFwCwQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-24056&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in pkgconf, where a variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. This issue may lead to a buffer overflow, which can crash the software.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-01-21T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-24056 https://bugzilla.redhat.com/show_bug.cgi?id=2165034 https://www.cve.org/CVERecord?id=CVE-2023-24056 https://nvd.nist.gov/vuln/detail/CVE-2023-24056 https://nullprogram.com/blog/2023/01/18/ https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-24056.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;pkgconf&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;j8SFSR8BZ09zBKgRkzC7Jg==&#34;: {&#xA;      &#34;id&#34;: &#34;j8SFSR8BZ09zBKgRkzC7Jg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-61985&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH where the SSH client accepted \\0 (null) characters in ssh:// URIs. When a ProxyCommand is configured, these characters could alter how the command is parsed, potentially leading to code execution depending on how the proxy is set up.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-61985 https://bugzilla.redhat.com/show_bug.cgi?id=2401962 https://www.cve.org/CVERecord?id=CVE-2025-61985 https://nvd.nist.gov/vuln/detail/CVE-2025-61985 https://marc.info/?l=openssh-unix-dev\u0026m=175974522032149\u0026w=2 https://www.openssh.com/releasenotes.html#10.1p1 https://www.openwall.com/lists/oss-security/2025/10/06/1 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61985.json https://access.redhat.com/errata/RHSA-2025:23480&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-47.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;j9OVo/jK62GKOQBSgKgJGw==&#34;: {&#xA;      &#34;id&#34;: &#34;j9OVo/jK62GKOQBSgKgJGw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-12151&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T16:05:38Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-12151 https://bugzilla.redhat.com/show_bug.cgi?id=2489980 https://www.cve.org/CVERecord?id=CVE-2026-12151 https://nvd.nist.gov/vuln/detail/CVE-2026-12151 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;jAAGS0/fgd26tdTkBYM5+w==&#34;: {&#xA;      &#34;id&#34;: &#34;jAAGS0/fgd26tdTkBYM5+w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27135&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 frame, leading to an assertion failure and a denial of service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-18T17:59:02Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27135 https://bugzilla.redhat.com/show_bug.cgi?id=2448754 https://www.cve.org/CVERecord?id=CVE-2026-27135 https://nvd.nist.gov/vuln/detail/CVE-2026-27135 https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1 https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;jGwIyHTli8TFB8vvlYRLgQ==&#34;: {&#xA;      &#34;id&#34;: &#34;jGwIyHTli8TFB8vvlYRLgQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-32284&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the msgpack decoder. A remote attacker could send specially crafted, truncated fixext data to an application using the msgpack library. This improper input validation can lead to an out-of-bounds read and a runtime panic, resulting in a denial of service (DoS) attack against the application.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-26T19:40:51Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-32284 https://bugzilla.redhat.com/show_bug.cgi?id=2451851 https://www.cve.org/CVERecord?id=CVE-2026-32284 https://nvd.nist.gov/vuln/detail/CVE-2026-32284 https://github.com/golang/vulndb/issues/4513 https://github.com/shamaton/msgpack/issues/59 https://pkg.go.dev/vuln/GO-2026-4513 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32284.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-pip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;jJU1rFjbneT5RWmoUr6uxw==&#34;: {&#xA;      &#34;id&#34;: &#34;jJU1rFjbneT5RWmoUr6uxw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27135&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 frame, leading to an assertion failure and a denial of service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-18T17:59:02Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27135 https://bugzilla.redhat.com/show_bug.cgi?id=2448754 https://www.cve.org/CVERecord?id=CVE-2026-27135 https://nvd.nist.gov/vuln/detail/CVE-2026-27135 https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1 https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;jLwTZ1iGPDmq13+JErDhGQ==&#34;: {&#xA;      &#34;id&#34;: &#34;jLwTZ1iGPDmq13+JErDhGQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5435&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T11:58:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-langpack-en&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;jVOV80BPiMF1EYk2uq9ohg==&#34;: {&#xA;      &#34;id&#34;: &#34;jVOV80BPiMF1EYk2uq9ohg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-2100&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-06T08:08:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-2100 https://bugzilla.redhat.com/show_bug.cgi?id=2437308 https://www.cve.org/CVERecord?id=CVE-2026-2100 https://nvd.nist.gov/vuln/detail/CVE-2026-2100 https://github.com/p11-glue/p11-kit/pull/740 https://github.com/p11-glue/p11-kit/releases/tag/0.26.2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2100.json https://access.redhat.com/errata/RHSA-2026:18599&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;p11-kit-trust&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.26.2-1.el9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;jVeIQzIm92EdkbCIlGT1qA==&#34;: {&#xA;      &#34;id&#34;: &#34;jVeIQzIm92EdkbCIlGT1qA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3153&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim, where it is vulnerable to a null-pointer-dereference in the vim_regcomp() function. This flaw allows a specially crafted file to crash a program or execute code.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-08T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3153 https://bugzilla.redhat.com/show_bug.cgi?id=2126401 https://www.cve.org/CVERecord?id=CVE-2022-3153 https://nvd.nist.gov/vuln/detail/CVE-2022-3153 https://huntr.dev/bounties/68331124-620d-48bc-a8fa-cd947b26270a/ https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3153.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;jZO++vSydJTiCIbVesbXEQ==&#34;: {&#xA;      &#34;id&#34;: &#34;jZO++vSydJTiCIbVesbXEQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rake&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:13.1.0-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;jiVVTQmOtKqVixv7agF/Hg==&#34;: {&#xA;      &#34;id&#34;: &#34;jiVVTQmOtKqVixv7agF/Hg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-27113&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libxml2. This vulnerability allows a NULL pointer dereference, leading to a potential crash or denial of service via a crafted XML pattern.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-18T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-27113 https://bugzilla.redhat.com/show_bug.cgi?id=2346410 https://www.cve.org/CVERecord?id=CVE-2025-27113 https://nvd.nist.gov/vuln/detail/CVE-2025-27113 https://gitlab.gnome.org/GNOME/libxml2/-/issues/861 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-27113.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;jw+r2jbroWxBcAHcFZs/eg==&#34;: {&#xA;      &#34;id&#34;: &#34;jw+r2jbroWxBcAHcFZs/eg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-psych&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:5.1.2-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;jyKmIhGp11jpJBCY83RPQA==&#34;: {&#xA;      &#34;id&#34;: &#34;jyKmIhGp11jpJBCY83RPQA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-13149&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-30T08:30:34Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-13149 https://bugzilla.redhat.com/show_bug.cgi?id=2494813 https://www.cve.org/CVERecord?id=CVE-2026-13149 https://nvd.nist.gov/vuln/detail/CVE-2026-13149 https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754 https://www.npmjs.com/package/brace-expansion https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;k9jtJIr2beiO7DTwypDNWw==&#34;: {&#xA;      &#34;id&#34;: &#34;k9jtJIr2beiO7DTwypDNWw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6844&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-13T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6844 https://bugzilla.redhat.com/show_bug.cgi?id=2460016 https://www.cve.org/CVERecord?id=CVE-2026-6844 https://nvd.nist.gov/vuln/detail/CVE-2026-6844 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6844.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;kDNo+1U3zj32TNGC/5DIKw==&#34;: {&#xA;      &#34;id&#34;: &#34;kDNo+1U3zj32TNGC/5DIKw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-8286&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-03T06:14:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-8286 https://bugzilla.redhat.com/show_bug.cgi?id=2496763 https://www.cve.org/CVERecord?id=CVE-2026-8286 https://nvd.nist.gov/vuln/detail/CVE-2026-8286 https://curl.se/docs/CVE-2026-8286.html https://curl.se/docs/CVE-2026-8286.json https://hackerone.com/reports/3718195 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8286.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;kGC5RaOJSDDnqCSoiLqrIA==&#34;: {&#xA;      &#34;id&#34;: &#34;kGC5RaOJSDDnqCSoiLqrIA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-54371&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the `attr` package. This vulnerability allows a local attacker to perform a symlink traversal attack by replacing a pathname component with a symbolic link - either during directory hierarchy traversal by `getfattr` or during backup restoration by `setfattr`, which reads and resolves full pathnames from backup files. In both cases, when these utilities are executed by a privileged process over a path controlled by the attacker, this can lead to local privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-29T13:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-54371 https://bugzilla.redhat.com/show_bug.cgi?id=2490283 https://www.cve.org/CVERecord?id=CVE-2026-54371 https://nvd.nist.gov/vuln/detail/CVE-2026-54371 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;attr&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;kGY3woMWc1W36Wi2YstJ0Q==&#34;: {&#xA;      &#34;id&#34;: &#34;kGY3woMWc1W36Wi2YstJ0Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6791&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program&#39;s stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-08-10T18:41:25Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6791 https://bugzilla.redhat.com/show_bug.cgi?id=2513603 https://www.cve.org/CVERecord?id=CVE-2026-6791 https://nvd.nist.gov/vuln/detail/CVE-2026-6791 https://sourceware.org/bugzilla/show_bug.cgi?id=34091 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6791.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;kHJ1B6H/qaZ/vmirvtTenQ==&#34;: {&#xA;      &#34;id&#34;: &#34;kHJ1B6H/qaZ/vmirvtTenQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27904&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in minimatch. A remote attacker could exploit this vulnerability by providing a specially crafted glob expression with nested unbounded quantifiers. This could lead to catastrophic backtracking in the V8 JavaScript engine, causing the application to become unresponsive and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-26T01:07:42Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27904 https://bugzilla.redhat.com/show_bug.cgi?id=2442922 https://www.cve.org/CVERecord?id=CVE-2026-27904 https://nvd.nist.gov/vuln/detail/CVE-2026-27904 https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27904.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;kR9Bs/gd2Qm09J0HnMmVzg==&#34;: {&#xA;      &#34;id&#34;: &#34;kR9Bs/gd2Qm09J0HnMmVzg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-58014&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-58014 https://bugzilla.redhat.com/show_bug.cgi?id=2492255 https://www.cve.org/CVERecord?id=CVE-2026-58014 https://nvd.nist.gov/vuln/detail/CVE-2026-58014 https://gitlab.gnome.org/GNOME/glib/-/issues/3930 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58014.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;kTyfGInwWoCVv7gGPYCF5g==&#34;: {&#xA;      &#34;id&#34;: &#34;kTyfGInwWoCVv7gGPYCF5g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-2610&#34;,&#xA;      &#34;description&#34;: &#34;Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-05-10T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-2610 https://bugzilla.redhat.com/show_bug.cgi?id=2209048 https://www.cve.org/CVERecord?id=CVE-2023-2610 https://nvd.nist.gov/vuln/detail/CVE-2023-2610 https://huntr.dev/bounties/31e67340-935b-4f6c-a923-f7246bc29c7d https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-2610.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;kXRjhXGDLvcaf9UDToCwQQ==&#34;: {&#xA;      &#34;id&#34;: &#34;kXRjhXGDLvcaf9UDToCwQQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-12912&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-12912 https://bugzilla.redhat.com/show_bug.cgi?id=2492871 https://www.cve.org/CVERecord?id=CVE-2026-12912 https://nvd.nist.gov/vuln/detail/CVE-2026-12912 https://gitlab.com/libtiff/libtiff/-/merge_requests/873 https://gitlab.com/libtiff/libtiff/-/work_items/824 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12912.json https://access.redhat.com/errata/RHSA-2026:42668&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtiff&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:4.4.0-18.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;kaUbMItvWrS1leJMEsAk9A==&#34;: {&#xA;      &#34;id&#34;: &#34;kaUbMItvWrS1leJMEsAk9A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2284&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-07-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2284 https://bugzilla.redhat.com/show_bug.cgi?id=2103872 https://www.cve.org/CVERecord?id=CVE-2022-2284 https://nvd.nist.gov/vuln/detail/CVE-2022-2284 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2284.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;klH60uFrR0WkawaSlcOEKg==&#34;: {&#xA;      &#34;id&#34;: &#34;klH60uFrR0WkawaSlcOEKg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1484&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1484 https://bugzilla.redhat.com/show_bug.cgi?id=2433259 https://www.cve.org/CVERecord?id=CVE-2026-1484 https://nvd.nist.gov/vuln/detail/CVE-2026-1484 https://gitlab.gnome.org/GNOME/glib/-/issues/3870 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1484.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;knUP7wXG3O435cJDvu9Thw==&#34;: {&#xA;      &#34;id&#34;: &#34;knUP7wXG3O435cJDvu9Thw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69647&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted ELF binary file containing malformed DWARF loclists data with the readelf program can trigger an infinite loop and result in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69647 https://bugzilla.redhat.com/show_bug.cgi?id=2445773 https://www.cve.org/CVERecord?id=CVE-2025-69647 https://nvd.nist.gov/vuln/detail/CVE-2025-69647 https://sourceware.org/bugzilla/show_bug.cgi?id=33640 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69647.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;kuuz4akZvpNKTf2txpaWog==&#34;: {&#xA;      &#34;id&#34;: &#34;kuuz4akZvpNKTf2txpaWog==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35386&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows a remote attacker to achieve arbitrary command execution by injecting shell metacharacters into a username provided on the command line. Exploitation requires an untrusted username and a non-default configuration of the &#39;%&#39; character in `ssh_config`.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:44:27Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35386 https://bugzilla.redhat.com/show_bug.cgi?id=2454506 https://www.cve.org/CVERecord?id=CVE-2026-35386 https://nvd.nist.gov/vuln/detail/CVE-2026-35386 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35386.json https://access.redhat.com/errata/RHSA-2026:19219&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;kxWAVe7EWU20jParQphcRA==&#34;: {&#xA;      &#34;id&#34;: &#34;kxWAVe7EWU20jParQphcRA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35414&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability arises from the incorrect handling of the authorized_keys principals option in uncommon scenarios. Specifically, when a principals list is used with a Certificate Authority that includes comma characters, OpenSSH may misinterpret the input. This could lead to security bypasses, potentially allowing unintended access or information disclosure in specific authentication contexts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T17:08:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35414 https://bugzilla.redhat.com/show_bug.cgi?id=2454490 https://www.cve.org/CVERecord?id=CVE-2026-35414 https://nvd.nist.gov/vuln/detail/CVE-2026-35414 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35414.json https://access.redhat.com/errata/RHSA-2026:19219&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;l1pK1ezh6e0g8I+Dp2iK7w==&#34;: {&#xA;      &#34;id&#34;: &#34;l1pK1ezh6e0g8I+Dp2iK7w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-9086&#34;,&#xA;      &#34;description&#34;: &#34;An out of bounds read flaw has been discovered in the curl project. Under specific conditions the path comparison logic makes curl read outside a heap buffer boundary. This bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-12T05:10:03Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-9086 https://bugzilla.redhat.com/show_bug.cgi?id=2394750 https://www.cve.org/CVERecord?id=CVE-2025-9086 https://nvd.nist.gov/vuln/detail/CVE-2025-9086 https://curl.se/docs/CVE-2025-9086.html https://curl.se/docs/CVE-2025-9086.json https://github.com/curl/curl/commit/c6ae07c6a541e0e96d0040afb6 https://hackerone.com/reports/3294999 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9086.json https://access.redhat.com/errata/RHSA-2026:1350&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libcurl-minimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:7.76.1-35.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;l6IrI73Pg+lrisEtcgX+0Q==&#34;: {&#xA;      &#34;id&#34;: &#34;l6IrI73Pg+lrisEtcgX+0Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-3784&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-11T10:09:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-3784 https://bugzilla.redhat.com/show_bug.cgi?id=2446449 https://www.cve.org/CVERecord?id=CVE-2026-3784 https://nvd.nist.gov/vuln/detail/CVE-2026-3784 http://www.openwall.com/lists/oss-security/2026/03/11/3 https://curl.se/docs/CVE-2026-3784.html https://curl.se/docs/CVE-2026-3784.json https://hackerone.com/reports/3584903 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3784.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lCc1jyHfsFJK2HfULjN8pA==&#34;: {&#xA;      &#34;id&#34;: &#34;lCc1jyHfsFJK2HfULjN8pA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-12781&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the base64 module in the Python standard library. The b64decode, standard_b64decode and urlsafe_b64decode functions will always accept the &#39;+&#39; and &#39;/&#39; characters even when an alternative base64 alphabet is specified via the altchars parameter that excludes them. This input validation bypass allows malformed or unexpected data to pass through decoding filters, potentially causing logical errors or data integrity issues in applications relying on strict character sets.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-21T19:34:47Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-12781 https://bugzilla.redhat.com/show_bug.cgi?id=2431736 https://www.cve.org/CVERecord?id=CVE-2025-12781 https://nvd.nist.gov/vuln/detail/CVE-2025-12781 https://github.com/python/cpython/issues/125346 https://github.com/python/cpython/pull/141128 https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-12781.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lFQcTCheSGIjEbZVivulnA==&#34;: {&#xA;      &#34;id&#34;: &#34;lFQcTCheSGIjEbZVivulnA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-json&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.7.2-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lFfYg6015iTLGI5pZVMU7w==&#34;: {&#xA;      &#34;id&#34;: &#34;lFfYg6015iTLGI5pZVMU7w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-58012&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-58012 https://bugzilla.redhat.com/show_bug.cgi?id=2492247 https://www.cve.org/CVERecord?id=CVE-2026-58012 https://nvd.nist.gov/vuln/detail/CVE-2026-58012 https://gitlab.gnome.org/GNOME/glib/-/issues/3918 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58012.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lHLNxD93t7uUJfmDhNwvCQ==&#34;: {&#xA;      &#34;id&#34;: &#34;lHLNxD93t7uUJfmDhNwvCQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3256&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free vulnerability was found in vim&#39;s movemark() function of the src/mark.c file. This issue occurs because vim uses freed memory when &#39;autocmd&#39; changes the mark. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap use-after-free that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-22T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3256 https://bugzilla.redhat.com/show_bug.cgi?id=2132571 https://www.cve.org/CVERecord?id=CVE-2022-3256 https://nvd.nist.gov/vuln/detail/CVE-2022-3256 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3256.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lJ8RTw7m+AgAnWW6upSntA==&#34;: {&#xA;      &#34;id&#34;: &#34;lJ8RTw7m+AgAnWW6upSntA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-45078&#34;,&#xA;      &#34;description&#34;: &#34;An out-of-bounds flaw was found in binutils’ stabs functionality. The attack needs to be initiated locally where an attacker could convince a victim to read a specially crafted file that is processed by objdump, leading to the disclosure of memory and possibly leading to the execution of arbitrary code or causing the utility to crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-12-14T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-45078 https://bugzilla.redhat.com/show_bug.cgi?id=2033715 https://www.cve.org/CVERecord?id=CVE-2021-45078 https://nvd.nist.gov/vuln/detail/CVE-2021-45078 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-45078.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lNSOU9e0rQLWWUuG6KmS+w==&#34;: {&#xA;      &#34;id&#34;: &#34;lNSOU9e0rQLWWUuG6KmS+w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-60002&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. A remote attacker could exploit a use-after-free vulnerability on the client side when a server changes its host key during a key re-exchange. This could lead to high impact on confidentiality and integrity, and low impact on availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T00:17:33Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-60002 https://bugzilla.redhat.com/show_bug.cgi?id=2497936 https://www.cve.org/CVERecord?id=CVE-2026-60002 https://nvd.nist.gov/vuln/detail/CVE-2026-60002 https://marc.info/?l=openssh-unix-dev\u0026m=178333966933090\u0026w=2 https://www.openssh.org/releasenotes.html#10.4p1 https://www.openwall.com/lists/oss-security/2026/07/06/5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-60002.json https://access.redhat.com/errata/RHSA-2026:47756&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-9.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lPpQZfWnRR1kvdFRKr34Kg==&#34;: {&#xA;      &#34;id&#34;: &#34;lPpQZfWnRR1kvdFRKr34Kg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45445&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. Applications that use the AES-OCB encryption method with a specific one-shot interface (EVP_Cipher()) will have their provided Initialization Vector (IV) silently discarded. This leads to the same internal cryptographic value being used repeatedly, which compromises the confidentiality of encrypted data. Additionally, this issue allows for the universal forgery of authentication tags, undermining the integrity of communications.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45445 https://bugzilla.redhat.com/show_bug.cgi?id=2481896 https://www.cve.org/CVERecord?id=CVE-2026-45445 https://nvd.nist.gov/vuln/detail/CVE-2026-45445 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45445.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lQBARBTddFvexevUD04GZA==&#34;: {&#xA;      &#34;id&#34;: &#34;lQBARBTddFvexevUD04GZA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5745&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \&#34;d\&#34; or \&#34;default\&#34; tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5745 https://bugzilla.redhat.com/show_bug.cgi?id=2455921 https://www.cve.org/CVERecord?id=CVE-2026-5745 https://nvd.nist.gov/vuln/detail/CVE-2026-5745 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5745.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lWdVDKK0NI1ECjrQyrQZhA==&#34;: {&#xA;      &#34;id&#34;: &#34;lWdVDKK0NI1ECjrQyrQZhA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11414&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted object file with the ld linker can trigger an out-of-bounds read in the get_link_hash_entry function in the bfd/elflink.c file due to an improper check, causing a crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-07T22:32:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11414 https://bugzilla.redhat.com/show_bug.cgi?id=2402424 https://www.cve.org/CVERecord?id=CVE-2025-11414 https://nvd.nist.gov/vuln/detail/CVE-2025-11414 https://sourceware.org/bugzilla/show_bug.cgi?id=33450 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aeaaa9af6359c8e394ce9cf24911fec4f4d23703 https://vuldb.com/?id.327350 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11414.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lz6O0nYiDpis8SScmTUuSg==&#34;: {&#xA;      &#34;id&#34;: &#34;lz6O0nYiDpis8SScmTUuSg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-1215&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. A local user may be able to trigger memory corruption by using the `--log` option with a non-existent path, which can lead to an application crash or other undefined behavior.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-12T18:31:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-1215 https://bugzilla.redhat.com/show_bug.cgi?id=2345318 https://www.cve.org/CVERecord?id=CVE-2025-1215 https://nvd.nist.gov/vuln/detail/CVE-2025-1215 https://github.com/vim/vim/commit/c5654b84480822817bb7b69ebc97c174c91185e9 https://github.com/vim/vim/issues/16606 https://github.com/vim/vim/releases/tag/v9.1.1097 https://vuldb.com/?ctiid.295174 https://vuldb.com/?id.295174 https://vuldb.com/?submit.497546 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1215.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;lzB4zyDZ+L/0TgHu+34IeA==&#34;: {&#xA;      &#34;id&#34;: &#34;lzB4zyDZ+L/0TgHu+34IeA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41989&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Libgcrypt. A remote attacker could exploit this vulnerability by sending crafted Elliptic Curve Diffie-Hellman (ECDH) ciphertext to the `gcry_pk_decrypt` function. This can lead to a heap-based buffer overflow, potentially causing a denial of service (DoS) condition.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-23T04:30:26Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41989 https://bugzilla.redhat.com/show_bug.cgi?id=2461063 https://www.cve.org/CVERecord?id=CVE-2026-41989 https://nvd.nist.gov/vuln/detail/CVE-2026-41989 https://dev.gnupg.org/T8211 https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html https://www.openwall.com/lists/oss-security/2026/04/21/1 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41989.json https://access.redhat.com/errata/RHSA-2026:50147&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libgcrypt&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.10.0-13.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;m/cpX9gyFETv4B87S/qRxw==&#34;: {&#xA;      &#34;id&#34;: &#34;m/cpX9gyFETv4B87S/qRxw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11468&#34;,&#xA;      &#34;description&#34;: &#34;Missing character filtering has been discovered in Python. When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:09:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11468 https://bugzilla.redhat.com/show_bug.cgi?id=2431375 https://www.cve.org/CVERecord?id=CVE-2025-11468 https://nvd.nist.gov/vuln/detail/CVE-2025-11468 https://github.com/python/cpython/issues/143935 https://github.com/python/cpython/pull/143936 https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11468.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;m9ROycwLgAur/M8HFSigEw==&#34;: {&#xA;      &#34;id&#34;: &#34;m9ROycwLgAur/M8HFSigEw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45130&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open-source command-line text editor. A heap buffer overflow exists in the `read_compound()` function when processing a specially crafted spell file (.spl) with UTF-8 encoding active. A remote attacker could exploit this by convincing a user to open a text file containing a malicious modeline, which could then load a planted malicious spell file. This could lead to a heap overflow, potentially resulting in an application-level denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-08T22:42:35Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45130 https://bugzilla.redhat.com/show_bug.cgi?id=2468422 https://www.cve.org/CVERecord?id=CVE-2026-45130 https://nvd.nist.gov/vuln/detail/CVE-2026-45130 https://github.com/vim/vim/commit/92993329178cb1f72d700fff45ca86e1c2d369f8 https://github.com/vim/vim/releases/tag/v9.2.0450 https://github.com/vim/vim/security/advisories/GHSA-q4jv-r9gj-6cwv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45130.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mCbTv5P9L2CaDsmaEWknNw==&#34;: {&#xA;      &#34;id&#34;: &#34;mCbTv5P9L2CaDsmaEWknNw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bigdecimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.1.5-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mESXtMr2XIcnFGpdxMD0iA==&#34;: {&#xA;      &#34;id&#34;: &#34;mESXtMr2XIcnFGpdxMD0iA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15467&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A remote attacker can exploit a stack buffer overflow vulnerability by supplying a crafted Cryptographic Message Syntax (CMS) message with an oversized Initialization Vector (IV) when parsing AuthEnvelopedData structures that use Authenticated Encryption with Associated Data (AEAD) ciphers such as AES-GCM. This can lead to a crash, causing a Denial of Service (DoS), or potentially allow for remote code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T14:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15467 https://bugzilla.redhat.com/show_bug.cgi?id=2430376 https://www.cve.org/CVERecord?id=CVE-2025-15467 https://nvd.nist.gov/vuln/detail/CVE-2025-15467 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mEw7dcF5jpuxJvu2G3JEew==&#34;: {&#xA;      &#34;id&#34;: &#34;mEw7dcF5jpuxJvu2G3JEew==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34982&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. A modeline is used to set specific editor options directly from a text file. However, the `complete`, `guitabtooltip`, `printheader` options and the `mapset` function lack proper security checks, allowing an attacker to bypass restrictions and cause arbitrary OS command execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-06T15:16:48Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34982 https://bugzilla.redhat.com/show_bug.cgi?id=2455400 https://www.cve.org/CVERecord?id=CVE-2026-34982 https://nvd.nist.gov/vuln/detail/CVE-2026-34982 http://www.openwall.com/lists/oss-security/2026/04/01/1 https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615 https://github.com/vim/vim/releases/tag/v9.2.0276 https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.json https://access.redhat.com/errata/RHSA-2026:11510&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim-filesystem&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:8.2.2637-23.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mINycH+x60PTfgPLuT1gJw==&#34;: {&#xA;      &#34;id&#34;: &#34;mINycH+x60PTfgPLuT1gJw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42767&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. An attacker controlling a Certificate Management Protocol (CMP) server, or acting as a man-in-the-middle, could craft a malicious CMP response. This response, containing a Certificate Request Message Format (CRMF) CertRepMessage with a specific malformed EncryptedValue structure, would trigger a NULL pointer dereference in the OpenSSL CMP client. This vulnerability leads to a crash of the application, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42767 https://bugzilla.redhat.com/show_bug.cgi?id=2481891 https://www.cve.org/CVERecord?id=CVE-2026-42767 https://nvd.nist.gov/vuln/detail/CVE-2026-42767 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42767.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mJw+LvAbCoVMIOZXCXNFpg==&#34;: {&#xA;      &#34;id&#34;: &#34;mJw+LvAbCoVMIOZXCXNFpg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-5916&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-20T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-5916 https://bugzilla.redhat.com/show_bug.cgi?id=2370872 https://www.cve.org/CVERecord?id=CVE-2025-5916 https://nvd.nist.gov/vuln/detail/CVE-2025-5916 https://github.com/libarchive/libarchive/pull/2568 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5916.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mNXETDKAQUXFDVp1hgY7fQ==&#34;: {&#xA;      &#34;id&#34;: &#34;mNXETDKAQUXFDVp1hgY7fQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5435&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-28T11:58:54Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-minimal-langpack&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mXoGTWRL/KLyEYWh5uyvXQ==&#34;: {&#xA;      &#34;id&#34;: &#34;mXoGTWRL/KLyEYWh5uyvXQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-28421&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. This vulnerability, a heap-buffer-overflow and a segmentation fault, exists in the swap file recovery logic. A local attacker could exploit this by providing a specially crafted swap file. This could lead to a denial of service (DoS) or potentially information disclosure.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-27T22:06:34Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-28421 https://bugzilla.redhat.com/show_bug.cgi?id=2443474 https://www.cve.org/CVERecord?id=CVE-2026-28421 https://nvd.nist.gov/vuln/detail/CVE-2026-28421 https://github.com/vim/vim/commit/65c1a143c331c886dc28 https://github.com/vim/vim/releases/tag/v9.2.0077 https://github.com/vim/vim/security/advisories/GHSA-r2gw-2x48-jj5p https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28421.json https://access.redhat.com/errata/RHSA-2026:8259&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim-minimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:8.2.2637-23.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mXtaaJBTQTZ/zl5a00GqaA==&#34;: {&#xA;      &#34;id&#34;: &#34;mXtaaJBTQTZ/zl5a00GqaA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21637&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21637 https://bugzilla.redhat.com/show_bug.cgi?id=2431340 https://www.cve.org/CVERecord?id=CVE-2026-21637 https://nvd.nist.gov/vuln/detail/CVE-2026-21637 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21637.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mZC3gBcn6x1aC7q9hXUpKg==&#34;: {&#xA;      &#34;id&#34;: &#34;mZC3gBcn6x1aC7q9hXUpKg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-3644&#34;,&#xA;      &#34;description&#34;: &#34;A control character validation flaw has been discovered in the Python http.cookie module. The Morsel.update(), |= operator, and unpickling paths were not patched to resolve  CVE-2026-0672, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-16T17:37:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-3644 https://bugzilla.redhat.com/show_bug.cgi?id=2448168 https://www.cve.org/CVERecord?id=CVE-2026-3644 https://nvd.nist.gov/vuln/detail/CVE-2026-3644 https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4 https://github.com/python/cpython/issues/145599 https://github.com/python/cpython/pull/145600 https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3644.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mZCCwO//htsOIXazj/SeOw==&#34;: {&#xA;      &#34;id&#34;: &#34;mZCCwO//htsOIXazj/SeOw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-31789&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This vulnerability, a heap buffer overflow, affects 32-bit systems when processing an unusually large X.509 certificate. If an application or service attempts to print or log such a specially crafted certificate, it could lead to a system crash or potentially allow an attacker to execute arbitrary code. This issue is considered low severity due to the specific conditions required for exploitation, including the need for an extremely large certificate and a 32-bit operating environment.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-31789 https://bugzilla.redhat.com/show_bug.cgi?id=2451095 https://www.cve.org/CVERecord?id=CVE-2026-31789 https://nvd.nist.gov/vuln/detail/CVE-2026-31789 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31789.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mZpS2ltu6/QRC8uFk/t2ag==&#34;: {&#xA;      &#34;id&#34;: &#34;mZpS2ltu6/QRC8uFk/t2ag==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11525&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. When undici processes Set-Cookie headers, it incorrectly interprets the SameSite attribute, accepting partial matches instead of exact ones. This allows a malicious server to downgrade a cookie&#39;s SameSite policy to a less secure setting, potentially leading to unintended information disclosure or a weakening of security protections for the user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:31:03Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11525 https://bugzilla.redhat.com/show_bug.cgi?id=2490008 https://www.cve.org/CVERecord?id=CVE-2026-11525 https://nvd.nist.gov/vuln/detail/CVE-2026-11525 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11525.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mgY0OXX1J12mJy1iNllE3A==&#34;: {&#xA;      &#34;id&#34;: &#34;mgY0OXX1J12mJy1iNllE3A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45447&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45447 https://bugzilla.redhat.com/show_bug.cgi?id=2481898 https://www.cve.org/CVERecord?id=CVE-2026-45447 https://nvd.nist.gov/vuln/detail/CVE-2026-45447 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mllkaOQAaJYNZpdIF7Bkbw==&#34;: {&#xA;      &#34;id&#34;: &#34;mllkaOQAaJYNZpdIF7Bkbw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-9681&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in curl. When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain&#39;s cache entry, making it end sooner or later than intended.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-11-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-9681 https://bugzilla.redhat.com/show_bug.cgi?id=2322969 https://www.cve.org/CVERecord?id=CVE-2024-9681 https://nvd.nist.gov/vuln/detail/CVE-2024-9681 https://curl.se/docs/CVE-2024-9681.html https://hackerone.com/reports/2764830 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-9681.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mmFI4mA7exd6BfbwTUwJfQ==&#34;: {&#xA;      &#34;id&#34;: &#34;mmFI4mA7exd6BfbwTUwJfQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-20197&#34;,&#xA;      &#34;description&#34;: &#34;There is an open race window when writing output in the following utilities in GNU binutils1: ar, objcopy, strip, and ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-01-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-20197 https://bugzilla.redhat.com/show_bug.cgi?id=1913743 https://www.cve.org/CVERecord?id=CVE-2021-20197 https://nvd.nist.gov/vuln/detail/CVE-2021-20197 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-20197.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mt2uKyaY1pD5PD0HEI8sFg==&#34;: {&#xA;      &#34;id&#34;: &#34;mt2uKyaY1pD5PD0HEI8sFg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4438&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4438 https://bugzilla.redhat.com/show_bug.cgi?id=2449783 https://www.cve.org/CVERecord?id=CVE-2026-4438 https://nvd.nist.gov/vuln/detail/CVE-2026-4438 https://sourceware.org/bugzilla/show_bug.cgi?id=34015 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4438.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-headers&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;mwfwMX3+sIJWibPk7jkY/Q==&#34;: {&#xA;      &#34;id&#34;: &#34;mwfwMX3+sIJWibPk7jkY/Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-26996&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in minimatch. A remote attacker could exploit this Regular Expression Denial of Service (ReDoS) vulnerability by providing a specially crafted glob pattern. This pattern, containing numerous consecutive wildcard characters, causes excessive processing and exponential backtracking in the regular expression engine. Successful exploitation leads to a Denial of Service (DoS), making the application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-20T03:05:21Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-26996 https://bugzilla.redhat.com/show_bug.cgi?id=2441268 https://www.cve.org/CVERecord?id=CVE-2026-26996 https://nvd.nist.gov/vuln/detail/CVE-2026-26996 https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5 https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26996.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;n30+9otRNHBUO3IOHvF3kA==&#34;: {&#xA;      &#34;id&#34;: &#34;n30+9otRNHBUO3IOHvF3kA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14104&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1913&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libmount-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.37.4-21.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;n39YhRffL6tFFAy/S18A8Q==&#34;: {&#xA;      &#34;id&#34;: &#34;n39YhRffL6tFFAy/S18A8Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-1371&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GNU elfutils. This vulnerability allows a NULL pointer dereference via the handle_dynamic_symtab function in readelf.c.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-17T02:31:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-1371 https://bugzilla.redhat.com/show_bug.cgi?id=2346055 https://www.cve.org/CVERecord?id=CVE-2025-1371 https://nvd.nist.gov/vuln/detail/CVE-2025-1371 https://sourceware.org/bugzilla/attachment.cgi?id=15926 https://sourceware.org/bugzilla/show_bug.cgi?id=32655 https://sourceware.org/bugzilla/show_bug.cgi?id=32655#c2 https://vuldb.com/?ctiid.295978 https://vuldb.com/?id.295978 https://vuldb.com/?submit.496484 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1371.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;elfutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;nCQ2LebiZFodYZ8OrVfuXw==&#34;: {&#xA;      &#34;id&#34;: &#34;nCQ2LebiZFodYZ8OrVfuXw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-29111&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-23T21:03:56Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-29111 https://bugzilla.redhat.com/show_bug.cgi?id=2450505 https://www.cve.org/CVERecord?id=CVE-2026-29111 https://nvd.nist.gov/vuln/detail/CVE-2026-29111 https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6 https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8 https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29111.json https://access.redhat.com/errata/RHSA-2026:19213&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd-pam&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-67.el9_8.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;nNAYHDwpTrgu1xKD+v9Oww==&#34;: {&#xA;      &#34;id&#34;: &#34;nNAYHDwpTrgu1xKD+v9Oww==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-73078&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Vim&#39;s netrw plugin fails to sanitize special characters in directory paths when creating GUI menu entries. Browsing or bookmarking a maliciously crafted path in GUI Vim allows attackers to execute arbitrary OS commands as the running user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-08-11T15:41:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-73078 https://bugzilla.redhat.com/show_bug.cgi?id=2514058 https://www.cve.org/CVERecord?id=CVE-2026-73078 https://nvd.nist.gov/vuln/detail/CVE-2026-73078 https://github.com/vim/vim/commit/29c6fd090d4520592f8be7d9ec81190edf25ef69 https://github.com/vim/vim/security/advisories/GHSA-rcr7-f3wr-22r2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73078.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;nS3gw6C5KX889pH0DdnXbQ==&#34;: {&#xA;      &#34;id&#34;: &#34;nS3gw6C5KX889pH0DdnXbQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5121&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T07:44:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5121 https://bugzilla.redhat.com/show_bug.cgi?id=2452945 https://www.cve.org/CVERecord?id=CVE-2026-5121 https://nvd.nist.gov/vuln/detail/CVE-2026-5121 https://github.com/advisories/GHSA-2vwv-vqpv-v8vc https://github.com/libarchive/libarchive/pull/2934 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5121.json https://access.redhat.com/errata/RHSA-2026:8510&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;bsdtar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.3-9.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;nZ2DFaqiaft4/Dqj5SJp4Q==&#34;: {&#xA;      &#34;id&#34;: &#34;nZ2DFaqiaft4/Dqj5SJp4Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69421&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by providing a specially crafted, malformed PKCS#12 file to an application that processes it. The flaw occurs due to a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function when handling the malformed file, leading to an application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69421 https://bugzilla.redhat.com/show_bug.cgi?id=2430387 https://www.cve.org/CVERecord?id=CVE-2025-69421 https://nvd.nist.gov/vuln/detail/CVE-2025-69421 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69421.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;nicOe0HMeoCrfaBInGMpgA==&#34;: {&#xA;      &#34;id&#34;: &#34;nicOe0HMeoCrfaBInGMpgA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-59465&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in NodeJS. A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-59465 https://bugzilla.redhat.com/show_bug.cgi?id=2431349 https://www.cve.org/CVERecord?id=CVE-2025-59465 https://nvd.nist.gov/vuln/detail/CVE-2025-59465 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59465.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;novhorrUhD5n0pl3qmImIw==&#34;: {&#xA;      &#34;id&#34;: &#34;novhorrUhD5n0pl3qmImIw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-default-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;nxtlAyA33msfy3ysIKdYBg==&#34;: {&#xA;      &#34;id&#34;: &#34;nxtlAyA33msfy3ysIKdYBg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-25547&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the brace-expansion component. This denial of service (DoS) vulnerability allows a remote attacker to provide specially crafted input containing repeated numeric brace ranges. This input causes the library to attempt an unbounded expansion, consuming excessive CPU and memory resources. This can lead to a system crash, impacting the availability of the service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-04T21:51:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-25547 https://bugzilla.redhat.com/show_bug.cgi?id=2436942 https://www.cve.org/CVERecord?id=CVE-2026-25547 https://nvd.nist.gov/vuln/detail/CVE-2026-25547 https://github.com/isaacs/brace-expansion/security/advisories/GHSA-7h2j-956f-4vf2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25547.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;o/v8DGswQXGkB45uD8rRUw==&#34;: {&#xA;      &#34;id&#34;: &#34;o/v8DGswQXGkB45uD8rRUw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-15028&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T10:10:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-15028 https://bugzilla.redhat.com/show_bug.cgi?id=2497970 https://www.cve.org/CVERecord?id=CVE-2026-15028 https://nvd.nist.gov/vuln/detail/CVE-2026-15028 https://github.com/libarchive/libarchive/issues/3251 https://github.com/libarchive/libarchive/pull/3253 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15028.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;o16kBwzDyL2DXuhbCPWX9Q==&#34;: {&#xA;      &#34;id&#34;: &#34;o16kBwzDyL2DXuhbCPWX9Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-3572&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-04-24T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-3572 https://bugzilla.redhat.com/show_bug.cgi?id=1962856 https://www.cve.org/CVERecord?id=CVE-2021-3572 https://nvd.nist.gov/vuln/detail/CVE-2021-3572 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-3572.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-pip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;o8O4Ttqnv0lQfm1yyfyVsw==&#34;: {&#xA;      &#34;id&#34;: &#34;o8O4Ttqnv0lQfm1yyfyVsw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-1720&#34;,&#xA;      &#34;description&#34;: &#34;A heap buffer over-read vulnerability was found in Vim&#39;s grab_file_name() function of the src/findfile.c file. This flaw occurs because the function reads after the NULL terminates the line with \&#34;gf\&#34; in Visual block mode. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap buffer over-read vulnerability that causes an application to crash and corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-05-13T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-1720 https://bugzilla.redhat.com/show_bug.cgi?id=2099979 https://www.cve.org/CVERecord?id=CVE-2022-1720 https://nvd.nist.gov/vuln/detail/CVE-2022-1720 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-1720.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;oED190j69/of7CStGTEa5A==&#34;: {&#xA;      &#34;id&#34;: &#34;oED190j69/of7CStGTEa5A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-55654&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-22T23:18:14Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-55654 https://bugzilla.redhat.com/show_bug.cgi?id=2462493 https://www.cve.org/CVERecord?id=CVE-2026-55654 https://nvd.nist.gov/vuln/detail/CVE-2026-55654 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55654.json https://access.redhat.com/errata/RHSA-2026:47756&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-9.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;oGYbR6FNz1KIQ8VJiypCZg==&#34;: {&#xA;      &#34;id&#34;: &#34;oGYbR6FNz1KIQ8VJiypCZg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48930&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. This vulnerability in the TLS (Transport Layer Security) hostname handling allows embedded null characters in hostnames. This can lead to silent authority rebinding, potentially enabling an attacker to redirect network traffic to an unintended server and disclose sensitive information.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:37Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48930 https://bugzilla.redhat.com/show_bug.cgi?id=2493326 https://www.cve.org/CVERecord?id=CVE-2026-48930 https://nvd.nist.gov/vuln/detail/CVE-2026-48930 https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e https://hackerone.com/reports/3656716 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48930.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;oGhsPyoyEtiEHT7/0qF+CQ==&#34;: {&#xA;      &#34;id&#34;: &#34;oGhsPyoyEtiEHT7/0qF+CQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-7545&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. The `copy_section` function in `binutils/objcopy.c` is susceptible to a heap-based buffer overflow due to improper bounds checking during data copying. This flaw allows a local attacker to provide a specially crafted file. This manipulation can lead to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-13T21:44:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-7545 https://bugzilla.redhat.com/show_bug.cgi?id=2379785 https://www.cve.org/CVERecord?id=CVE-2025-7545 https://nvd.nist.gov/vuln/detail/CVE-2025-7545 https://sourceware.org/bugzilla/attachment.cgi?id=16117 https://sourceware.org/bugzilla/show_bug.cgi?id=33049 https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944 https://vuldb.com/?ctiid.316243 https://vuldb.com/?id.316243 https://vuldb.com/?submit.614355 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-7545.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;oIBUxFCAPk4vRXBwpcmtFw==&#34;: {&#xA;      &#34;id&#34;: &#34;oIBUxFCAPk4vRXBwpcmtFw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-44840&#34;,&#xA;      &#34;description&#34;: &#34;A heap-based buffer overflow vulnerability was found in binutils in the find_section_in_set function. This flaw allows an attacker to use a specially crafted payload to trigger a buffer overflow, resulting in issues with availability, confidentiality, and integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-10-30T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-44840 https://bugzilla.redhat.com/show_bug.cgi?id=2234004 https://www.cve.org/CVERecord?id=CVE-2022-44840 https://nvd.nist.gov/vuln/detail/CVE-2022-44840 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-44840.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;oVgcRSL89qnSRkMXpV8N8A==&#34;: {&#xA;      &#34;id&#34;: &#34;oVgcRSL89qnSRkMXpV8N8A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2819&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. The vulnerability occurs due to illegal memory access and leads to a heap buffer overflow vulnerability. This flaw allows an attacker to input a specially crafted file, leading to a crash or code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-15T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2819 https://bugzilla.redhat.com/show_bug.cgi?id=2118594 https://www.cve.org/CVERecord?id=CVE-2022-2819 https://nvd.nist.gov/vuln/detail/CVE-2022-2819 https://huntr.dev/bounties/0a9bd71e-66b8-4eb1-9566-7dfd9b097e59 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2819.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;oeQZicbrugL5hg8G7dVmSw==&#34;: {&#xA;      &#34;id&#34;: &#34;oeQZicbrugL5hg8G7dVmSw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-59465&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in NodeJS. A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-59465 https://bugzilla.redhat.com/show_bug.cgi?id=2431349 https://www.cve.org/CVERecord?id=CVE-2025-59465 https://nvd.nist.gov/vuln/detail/CVE-2025-59465 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59465.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;orI4WDU+1BLBSEG99OS8MA==&#34;: {&#xA;      &#34;id&#34;: &#34;orI4WDU+1BLBSEG99OS8MA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-45446&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. The implementations of AES-SIV (Advanced Encryption Standard - SIV) and AES-GCM-SIV (Advanced Encryption Standard - Galois/Counter Mode - SIV) incorrectly process authentication tags for empty messages. This vulnerability allows a remote attacker to forge empty messages with arbitrary Additional Authenticated Data (AAD) in applications that utilize these specific cipher modes within custom protocols and do not properly handle zero-length ciphertexts. This could lead to unauthorized data manipulation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-45446 https://bugzilla.redhat.com/show_bug.cgi?id=2481897 https://www.cve.org/CVERecord?id=CVE-2026-45446 https://nvd.nist.gov/vuln/detail/CVE-2026-45446 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45446.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;oxSfxLnytv2y2gHjvplCuw==&#34;: {&#xA;      &#34;id&#34;: &#34;oxSfxLnytv2y2gHjvplCuw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59996&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH, a widely used tool for secure remote access. When a user attempts to copy files between two different remote systems using the `scp` command, the file might be incorrectly placed in a directory above the intended destination. This unintended file placement could lead to data integrity issues or, in some cases, unauthorized access to sensitive information if files are stored in an exposed location.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T00:07:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59996 https://bugzilla.redhat.com/show_bug.cgi?id=2497944 https://www.cve.org/CVERecord?id=CVE-2026-59996 https://nvd.nist.gov/vuln/detail/CVE-2026-59996 https://marc.info/?l=openssh-unix-dev\u0026m=178333966933090\u0026w=2 https://www.openssh.org/releasenotes.html#10.4p1 https://www.openwall.com/lists/oss-security/2026/07/06/5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59996.json https://access.redhat.com/errata/RHSA-2026:47756&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-9.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;oyvtOIVUDqm1ruQx8vhRhA==&#34;: {&#xA;      &#34;id&#34;: &#34;oyvtOIVUDqm1ruQx8vhRhA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-22667&#34;,&#xA;      &#34;description&#34;: &#34;A stack-based buffer overflow flaw was found in Vim. The did_set_langmap function in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions. That buffer can be overflown, possibly leading to memory corruption and escalation of privileges.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-02-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-22667 https://bugzilla.redhat.com/show_bug.cgi?id=2262999 https://www.cve.org/CVERecord?id=CVE-2024-22667 https://nvd.nist.gov/vuln/detail/CVE-2024-22667 https://github.com/vim/vim/commit/b39b240c386a5a29241415541f1c99e2e6b8ce47 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-22667.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;p0umWDpPMiOz8HPGPopybw==&#34;: {&#xA;      &#34;id&#34;: &#34;p0umWDpPMiOz8HPGPopybw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11525&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. When undici processes Set-Cookie headers, it incorrectly interprets the SameSite attribute, accepting partial matches instead of exact ones. This allows a malicious server to downgrade a cookie&#39;s SameSite policy to a less secure setting, potentially leading to unintended information disclosure or a weakening of security protections for the user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:31:03Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11525 https://bugzilla.redhat.com/show_bug.cgi?id=2490008 https://www.cve.org/CVERecord?id=CVE-2026-11525 https://nvd.nist.gov/vuln/detail/CVE-2026-11525 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11525.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;p1r6Su9OK5/1nhaGskH+Pw==&#34;: {&#xA;      &#34;id&#34;: &#34;p1r6Su9OK5/1nhaGskH+Pw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4437&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4437 https://bugzilla.redhat.com/show_bug.cgi?id=2449777 https://www.cve.org/CVERecord?id=CVE-2026-4437 https://nvd.nist.gov/vuln/detail/CVE-2026-4437 https://sourceware.org/bugzilla/show_bug.cgi?id=34014 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4437.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-locale-source&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;p8wzfQhvimCzJ24LCz0qSQ==&#34;: {&#xA;      &#34;id&#34;: &#34;p8wzfQhvimCzJ24LCz0qSQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35387&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows the system to use unintended Elliptic Curve Digital Signature Algorithm (ECDSA) algorithms. This occurs because the configuration for accepted public key algorithms is misinterpreted, leading to the use of weaker cryptographic methods than intended. This could potentially allow an attacker to compromise the confidentiality of data.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:52:53Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35387 https://bugzilla.redhat.com/show_bug.cgi?id=2454494 https://www.cve.org/CVERecord?id=CVE-2026-35387 https://nvd.nist.gov/vuln/detail/CVE-2026-35387 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35387.json https://access.redhat.com/errata/RHSA-2026:19219&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;pDJ3Xpebdx7KToS5V5VZDQ==&#34;: {&#xA;      &#34;id&#34;: &#34;pDJ3Xpebdx7KToS5V5VZDQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4438&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4438 https://bugzilla.redhat.com/show_bug.cgi?id=2449783 https://www.cve.org/CVERecord?id=CVE-2026-4438 https://nvd.nist.gov/vuln/detail/CVE-2026-4438 https://sourceware.org/bugzilla/show_bug.cgi?id=34015 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4438.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-gconv-extra&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;pL5xLi7HF+fZxJQ9yVoHHw==&#34;: {&#xA;      &#34;id&#34;: &#34;pL5xLi7HF+fZxJQ9yVoHHw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48933&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48933 https://bugzilla.redhat.com/show_bug.cgi?id=2493331 https://www.cve.org/CVERecord?id=CVE-2026-48933 https://nvd.nist.gov/vuln/detail/CVE-2026-48933 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;pOKoOa+tppgNwBAEgYrxlg==&#34;: {&#xA;      &#34;id&#34;: &#34;pOKoOa+tppgNwBAEgYrxlg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48618&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. This flaw involves a mismatch in how Node.js handles TLS (Transport Layer Security) hostnames and unicode dot separators during authentication. This mismatch can lead to a wildcard-depth authentication bypass. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access and confidentiality impact.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48618 https://bugzilla.redhat.com/show_bug.cgi?id=2493337 https://www.cve.org/CVERecord?id=CVE-2026-48618 https://nvd.nist.gov/vuln/detail/CVE-2026-48618 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;pe4Shj+F17XwL0468/ASsg==&#34;: {&#xA;      &#34;id&#34;: &#34;pe4Shj+F17XwL0468/ASsg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rake&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:13.1.0-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;pgBZKIeBAAyMOCe6qVOUxg==&#34;: {&#xA;      &#34;id&#34;: &#34;pgBZKIeBAAyMOCe6qVOUxg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34182&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL&#39;s Cryptographic Message Services (CMS) AuthEnvelopedData processing. An on-path attacker can exploit insufficient input validation on cipher and tag length fields by sending specially crafted CMS messages. This can lead to the forging of messages or bypassing integrity validation. Consequently, an attacker may achieve key-equivalent functionality for a given CMS recipient.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34182 https://bugzilla.redhat.com/show_bug.cgi?id=2481884 https://www.cve.org/CVERecord?id=CVE-2026-34182 https://nvd.nist.gov/vuln/detail/CVE-2026-34182 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34182.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;po1D239o+AaKFXhspYJxNw==&#34;: {&#xA;      &#34;id&#34;: &#34;po1D239o+AaKFXhspYJxNw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42768&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL&#39;s CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim&#39;s private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application&#39;s error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42768 https://bugzilla.redhat.com/show_bug.cgi?id=2481892 https://www.cve.org/CVERecord?id=CVE-2026-42768 https://nvd.nist.gov/vuln/detail/CVE-2026-42768 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42768.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;poe+ZOEeV2eDvTqSL2bcHA==&#34;: {&#xA;      &#34;id&#34;: &#34;poe+ZOEeV2eDvTqSL2bcHA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-18508&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-31T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-18508 https://bugzilla.redhat.com/show_bug.cgi?id=2509843 https://www.cve.org/CVERecord?id=CVE-2026-18508 https://nvd.nist.gov/vuln/detail/CVE-2026-18508 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18508.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;px8rY0l1xijMh1q/wodpIQ==&#34;: {&#xA;      &#34;id&#34;: &#34;px8rY0l1xijMh1q/wodpIQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-io-console&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.7.1-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;pzONVbRfZmj1lkGaWtUucQ==&#34;: {&#xA;      &#34;id&#34;: &#34;pzONVbRfZmj1lkGaWtUucQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22795&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a Denial of Service (DoS) by tricking a user or application into processing a maliciously crafted PKCS#12 (Personal Information Exchange Syntax Standard) file. The vulnerability leads to an invalid or NULL pointer dereference, resulting in an application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22795 https://bugzilla.redhat.com/show_bug.cgi?id=2430389 https://www.cve.org/CVERecord?id=CVE-2026-22795 https://nvd.nist.gov/vuln/detail/CVE-2026-22795 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22795.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;q0+0u3TKsGvCBRBK4RgVAw==&#34;: {&#xA;      &#34;id&#34;: &#34;q0+0u3TKsGvCBRBK4RgVAw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5928&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:37:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-langpack-en&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-274.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;q59Dz6hmc7o1qITDwl3CCw==&#34;: {&#xA;      &#34;id&#34;: &#34;q59Dz6hmc7o1qITDwl3CCw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1525&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici, a Node.js HTTP/1.1 client. A remote attacker could exploit this vulnerability by sending HTTP/1.1 requests that include duplicate Content-Length headers with different casing (e.g., \&#34;Content-Length\&#34; and \&#34;content-length\&#34;). This can lead to HTTP Request Smuggling, a technique where an attacker sends an ambiguous request that is interpreted differently by a proxy and a backend server. Successful exploitation could result in unauthorized access, cache poisoning, or credential hijacking. It may also cause a Denial of Service (DoS) if strict HTTP parsers reject the malformed requests.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T19:56:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1525 https://bugzilla.redhat.com/show_bug.cgi?id=2447144 https://www.cve.org/CVERecord?id=CVE-2026-1525 https://nvd.nist.gov/vuln/detail/CVE-2026-1525 https://cna.openjsf.org/security-advisories.html https://cwe.mitre.org/data/definitions/444.html https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm https://hackerone.com/reports/3556037 https://www.rfc-editor.org/rfc/rfc9110.html#section-8.6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1525.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;q5joCCZ2cOTa0rXBUtiSpQ==&#34;: {&#xA;      &#34;id&#34;: &#34;q5joCCZ2cOTa0rXBUtiSpQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-11839&#34;,&#xA;      &#34;description&#34;: &#34;An uncheck return value flaw has been discovered in the GNU binutils program. This flaw exists in the `tg_tag_type` function of the file prdbg.c and exploitation of this flaw may lead to a program crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-16T14:02:13Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-11839 https://bugzilla.redhat.com/show_bug.cgi?id=2404439 https://www.cve.org/CVERecord?id=CVE-2025-11839 https://nvd.nist.gov/vuln/detail/CVE-2025-11839 https://sourceware.org/bugzilla/attachment.cgi?id=16344 https://sourceware.org/bugzilla/show_bug.cgi?id=33448 https://vuldb.com/?ctiid.328774 https://vuldb.com/?id.328774 https://vuldb.com/?submit.661279 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11839.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;q7c6mw4iAmau1l6sfNLk8w==&#34;: {&#xA;      &#34;id&#34;: &#34;q7c6mw4iAmau1l6sfNLk8w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42258&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:40:49Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42258 https://bugzilla.redhat.com/show_bug.cgi?id=2468498 https://www.cve.org/CVERecord?id=CVE-2026-42258 https://nvd.nist.gov/vuln/detail/CVE-2026-42258 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-rdoc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:6.6.3.1-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qEhRdzGH44SGjJIcqcIv/g==&#34;: {&#xA;      &#34;id&#34;: &#34;qEhRdzGH44SGjJIcqcIv/g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2344&#34;,&#xA;      &#34;description&#34;: &#34;A heap-based buffer overflow was found in Vim in the ins_compl_add function in the insexpand.c file. This issue occurs due to a read past the end of a buffer when a specially crafted input is processed. This flaw allows an attacker who can trick a user into opening a specially crafted file into triggering the heap-based buffer overflow, causing the application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-07-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2344 https://bugzilla.redhat.com/show_bug.cgi?id=2106787 https://www.cve.org/CVERecord?id=CVE-2022-2344 https://nvd.nist.gov/vuln/detail/CVE-2022-2344 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2344.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qFIYjZJeFnLAVC7lR0n6oQ==&#34;: {&#xA;      &#34;id&#34;: &#34;qFIYjZJeFnLAVC7lR0n6oQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0989&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested \u003cinclude\u003e directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-15T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0989 https://bugzilla.redhat.com/show_bug.cgi?id=2429933 https://www.cve.org/CVERecord?id=CVE-2026-0989 https://nvd.nist.gov/vuln/detail/CVE-2026-0989 https://gitlab.gnome.org/GNOME/libxml2/-/issues/998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0989.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qIUMlexpn07c5Ly85v5AjQ==&#34;: {&#xA;      &#34;id&#34;: &#34;qIUMlexpn07c5Ly85v5AjQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6368&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-08-10T18:40:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6368 https://bugzilla.redhat.com/show_bug.cgi?id=2513608 https://www.cve.org/CVERecord?id=CVE-2026-6368 https://nvd.nist.gov/vuln/detail/CVE-2026-6368 https://sourceware.org/bugzilla/show_bug.cgi?id=34090 https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6368.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qIj6aIlqGJtvbX658qTpDQ==&#34;: {&#xA;      &#34;id&#34;: &#34;qIj6aIlqGJtvbX658qTpDQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bundler&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.5.22-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qN6ac9Xwm6AOaO1fAB7fOQ==&#34;: {&#xA;      &#34;id&#34;: &#34;qN6ac9Xwm6AOaO1fAB7fOQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-33845&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-30T17:28:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-33845 https://bugzilla.redhat.com/show_bug.cgi?id=2450624 https://www.cve.org/CVERecord?id=CVE-2026-33845 https://nvd.nist.gov/vuln/detail/CVE-2026-33845 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33845.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qSRGSB2uV6n5bH1pdu2LUQ==&#34;: {&#xA;      &#34;id&#34;: &#34;qSRGSB2uV6n5bH1pdu2LUQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4424&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4424 https://bugzilla.redhat.com/show_bug.cgi?id=2449006 https://www.cve.org/CVERecord?id=CVE-2026-4424 https://nvd.nist.gov/vuln/detail/CVE-2026-4424 https://github.com/libarchive/libarchive/pull/2898 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4424.json https://access.redhat.com/errata/RHSA-2026:8510&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;bsdtar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.5.3-9.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qWK7H7gz7e8gS19GJSeIIg==&#34;: {&#xA;      &#34;id&#34;: &#34;qWK7H7gz7e8gS19GJSeIIg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2889&#34;,&#xA;      &#34;description&#34;: &#34;A use-after-free vulnerability was found in Vim in the find_var_also_in_script function in the evalvars.c file. This issue occurs because an already freed memory is used when a specially crafted input is processed. This flaw allows an attacker who can trick a user into opening a specially crafted file into triggering the use-after-free, causing the application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-16T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2889 https://bugzilla.redhat.com/show_bug.cgi?id=2119864 https://www.cve.org/CVERecord?id=CVE-2022-2889 https://nvd.nist.gov/vuln/detail/CVE-2022-2889 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2889.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qYORp6v9x0Jy6S8OKerZvw==&#34;: {&#xA;      &#34;id&#34;: &#34;qYORp6v9x0Jy6S8OKerZvw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-4738&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-09-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-4738 https://bugzilla.redhat.com/show_bug.cgi?id=2237176 https://www.cve.org/CVERecord?id=CVE-2023-4738 https://nvd.nist.gov/vuln/detail/CVE-2023-4738 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4738.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qfyF3TC4Vao8jmQ0UiB8kA==&#34;: {&#xA;      &#34;id&#34;: &#34;qfyF3TC4Vao8jmQ0UiB8kA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-64720&#34;,&#xA;      &#34;description&#34;: &#34;A buffer overflow flaw has been discovered in libpng. An out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled. The palette compositing code in png_init_read_transformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-24T23:45:38Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-64720 https://bugzilla.redhat.com/show_bug.cgi?id=2416904 https://www.cve.org/CVERecord?id=CVE-2025-64720 https://nvd.nist.gov/vuln/detail/CVE-2025-64720 https://github.com/pnggroup/libpng/commit/08da33b4c88cfcd36e5a706558a8d7e0e4773643 https://github.com/pnggroup/libpng/issues/686 https://github.com/pnggroup/libpng/pull/751 https://github.com/pnggroup/libpng/security/advisories/GHSA-hfc7-ph9c-wcww https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-64720.json https://access.redhat.com/errata/RHSA-2026:0238&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:1.6.37-12.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qh5gUahI9nge5StfpD2Efg==&#34;: {&#xA;      &#34;id&#34;: &#34;qh5gUahI9nge5StfpD2Efg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42770&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. A malicious peer can exploit this vulnerability by presenting a specially crafted DHX (X9.42) peer key. Due to improper validation of the peer key&#39;s subgroup membership, an attacker can recover the victim&#39;s private key after a small number of key exchange attempts. This information disclosure can lead to unauthorized access or further compromise of affected systems.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42770 https://bugzilla.redhat.com/show_bug.cgi?id=2481894 https://www.cve.org/CVERecord?id=CVE-2026-42770 https://nvd.nist.gov/vuln/detail/CVE-2026-42770 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42770.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qkPjlqaV2EZ52NAHd/IgfQ==&#34;: {&#xA;      &#34;id&#34;: &#34;qkPjlqaV2EZ52NAHd/IgfQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11525&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. When undici processes Set-Cookie headers, it incorrectly interprets the SameSite attribute, accepting partial matches instead of exact ones. This allows a malicious server to downgrade a cookie&#39;s SameSite policy to a less secure setting, potentially leading to unintended information disclosure or a weakening of security protections for the user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T17:31:03Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11525 https://bugzilla.redhat.com/show_bug.cgi?id=2490008 https://www.cve.org/CVERecord?id=CVE-2026-11525 https://nvd.nist.gov/vuln/detail/CVE-2026-11525 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11525.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qn72KaShSoWOaJmw6qKS3Q==&#34;: {&#xA;      &#34;id&#34;: &#34;qn72KaShSoWOaJmw6qKS3Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-irb&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.13.1-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qpxeH+3MOciW1z6wxEwYBw==&#34;: {&#xA;      &#34;id&#34;: &#34;qpxeH+3MOciW1z6wxEwYBw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55131&#34;,&#xA;      &#34;description&#34;: &#34;A memory exposure flaw has been discovered in Node.js. A flaw in Node.js&#39;s buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain leftover data from previous operations, allowing in-process secrets like tokens or passwords to leak or causing data corruption.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55131 https://bugzilla.redhat.com/show_bug.cgi?id=2431350 https://www.cve.org/CVERecord?id=CVE-2025-55131 https://nvd.nist.gov/vuln/detail/CVE-2025-55131 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55131.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;qug1advw8m4TjVAUPEUPiA==&#34;: {&#xA;      &#34;id&#34;: &#34;qug1advw8m4TjVAUPEUPiA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-4751&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-09-03T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-4751 https://bugzilla.redhat.com/show_bug.cgi?id=2237187 https://www.cve.org/CVERecord?id=CVE-2023-4751 https://nvd.nist.gov/vuln/detail/CVE-2023-4751 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4751.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;r2VJfkGmsY6Tx/luoo7BHQ==&#34;: {&#xA;      &#34;id&#34;: &#34;r2VJfkGmsY6Tx/luoo7BHQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0865&#34;,&#xA;      &#34;description&#34;: &#34;Missing newline filtering has been discovered in Python. User-controlled header names and values containing newlines can allow injecting HTTP headers.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:26:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0865 https://bugzilla.redhat.com/show_bug.cgi?id=2431367 https://www.cve.org/CVERecord?id=CVE-2026-0865 https://nvd.nist.gov/vuln/detail/CVE-2026-0865 https://github.com/python/cpython/issues/143916 https://github.com/python/cpython/pull/143917 https://mail.python.org/archives/list/security-announce@python.org/thread/BJ6QPHNSHJTS3A7CFV6IBMCAP2DWRVNT/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0865.json https://access.redhat.com/errata/RHSA-2026:4168&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;r3RLKNYtYvKarBqnnrlrew==&#34;: {&#xA;      &#34;id&#34;: &#34;r3RLKNYtYvKarBqnnrlrew==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-0529&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-01-24T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-0529 https://bugzilla.redhat.com/show_bug.cgi?id=2051402 https://www.cve.org/CVERecord?id=CVE-2022-0529 https://nvd.nist.gov/vuln/detail/CVE-2022-0529 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-0529.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;unzip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;r410Z5X0yojDsVg9YVcNqQ==&#34;: {&#xA;      &#34;id&#34;: &#34;r410Z5X0yojDsVg9YVcNqQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2182&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-23T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2182 https://bugzilla.redhat.com/show_bug.cgi?id=2102153 https://www.cve.org/CVERecord?id=CVE-2022-2182 https://nvd.nist.gov/vuln/detail/CVE-2022-2182 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2182.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;r4Fu2fNYrl5cfm4zX5YpZQ==&#34;: {&#xA;      &#34;id&#34;: &#34;r4Fu2fNYrl5cfm4zX5YpZQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69648&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted ELF binary file containing malformed DWARF .debug_rnglists data with the readelf program can trigger an infinite loop and result in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69648 https://bugzilla.redhat.com/show_bug.cgi?id=2445774 https://www.cve.org/CVERecord?id=CVE-2025-69648 https://nvd.nist.gov/vuln/detail/CVE-2025-69648 https://sourceware.org/bugzilla/show_bug.cgi?id=33641 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69648.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rJljaCTiTdw1uI1lvfy+hw==&#34;: {&#xA;      &#34;id&#34;: &#34;rJljaCTiTdw1uI1lvfy+hw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-1170&#34;,&#xA;      &#34;description&#34;: &#34;A heap-based buffer overflow vulnerability was found in Vim&#39;s utf_ptr2char() function of the src/mbyte.c file. This flaw occurs because there is access to invalid memory with put in visual block mode. An attacker can trick a user into opening a specially crafted file, triggering an out-of-bounds read that causes an application to crash, leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-03-04T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-1170 https://bugzilla.redhat.com/show_bug.cgi?id=2176462 https://www.cve.org/CVERecord?id=CVE-2023-1170 https://nvd.nist.gov/vuln/detail/CVE-2023-1170 https://huntr.dev/bounties/286e0090-e654-46d2-ac60-29f81799d0a4 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1170.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rO5a9fYyaqaIZ4bH0M8fdA==&#34;: {&#xA;      &#34;id&#34;: &#34;rO5a9fYyaqaIZ4bH0M8fdA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2862&#34;,&#xA;      &#34;description&#34;: &#34;Use After Free in GitHub repository vim/vim prior to 9.0.0221.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-17T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2862 https://bugzilla.redhat.com/show_bug.cgi?id=2122139 https://www.cve.org/CVERecord?id=CVE-2022-2862 https://nvd.nist.gov/vuln/detail/CVE-2022-2862 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2862.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rR226S9SV4WbmIVotM0CsQ==&#34;: {&#xA;      &#34;id&#34;: &#34;rR226S9SV4WbmIVotM0CsQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-46246&#34;,&#xA;      &#34;description&#34;: &#34;Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_grow_inner` in in the file `src/alloc.c` at line 748, which is freed in the file `src/ex_docmd.c` in the function `do_cmdline` at line 1010 and then used again in `src/cmdhist.c` at line 759. When using the `:history` command, it&#39;s possible that the provided argument overflows the accepted value. Causing an Integer Overflow and potentially later an use-after-free. This vulnerability has been patched in version 9.0.2068.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-10-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-46246 https://bugzilla.redhat.com/show_bug.cgi?id=2246953 https://www.cve.org/CVERecord?id=CVE-2023-46246 https://nvd.nist.gov/vuln/detail/CVE-2023-46246 https://github.com/vim/vim/security/advisories/GHSA-q22m-h7m2-9mgm https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-46246.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rSxPRb6y8rOV71QNzjYBEA==&#34;: {&#xA;      &#34;id&#34;: &#34;rSxPRb6y8rOV71QNzjYBEA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4437&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4437 https://bugzilla.redhat.com/show_bug.cgi?id=2449777 https://www.cve.org/CVERecord?id=CVE-2026-4437 https://nvd.nist.gov/vuln/detail/CVE-2026-4437 https://sourceware.org/bugzilla/show_bug.cgi?id=34014 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4437.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-gconv-extra&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rT7Zl5hqfT/SFXkQlgRUqg==&#34;: {&#xA;      &#34;id&#34;: &#34;rT7Zl5hqfT/SFXkQlgRUqg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-12151&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-17T16:05:38Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-12151 https://bugzilla.redhat.com/show_bug.cgi?id=2489980 https://www.cve.org/CVERecord?id=CVE-2026-12151 https://nvd.nist.gov/vuln/detail/CVE-2026-12151 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rVRinaBex/zPmHE0cI9QNQ==&#34;: {&#xA;      &#34;id&#34;: &#34;rVRinaBex/zPmHE0cI9QNQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bundler&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.5.22-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rWO0jZdArYZ9zSTLMe8r8w==&#34;: {&#xA;      &#34;id&#34;: &#34;rWO0jZdArYZ9zSTLMe8r8w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-bundler&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.5.22-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rhaCfU7pM1FgApTAw4PpPA==&#34;: {&#xA;      &#34;id&#34;: &#34;rhaCfU7pM1FgApTAw4PpPA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-18739&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-08-03T18:46:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-18739 https://bugzilla.redhat.com/show_bug.cgi?id=2510737 https://www.cve.org/CVERecord?id=CVE-2026-18739 https://nvd.nist.gov/vuln/detail/CVE-2026-18739 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18739.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;popt&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rjcajgsmKA8I5yMLMT8DHg==&#34;: {&#xA;      &#34;id&#34;: &#34;rjcajgsmKA8I5yMLMT8DHg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-55655&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-22T23:22:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-55655 https://bugzilla.redhat.com/show_bug.cgi?id=2462250 https://www.cve.org/CVERecord?id=CVE-2026-55655 https://nvd.nist.gov/vuln/detail/CVE-2026-55655 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55655.json https://access.redhat.com/errata/RHSA-2026:47756&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-9.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rlHsuoluzmy30odv/xIILA==&#34;: {&#xA;      &#34;id&#34;: &#34;rlHsuoluzmy30odv/xIILA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35388&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability allows for a low integrity impact due to the omission of connection multiplexing confirmation for proxy-mode multiplexing sessions. A local user, under specific and complex conditions requiring user interaction, could potentially establish a multiplexed session without explicit confirmation, leading to unintended data handling.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:57:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35388 https://bugzilla.redhat.com/show_bug.cgi?id=2454500 https://www.cve.org/CVERecord?id=CVE-2026-35388 https://nvd.nist.gov/vuln/detail/CVE-2026-35388 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35388.json https://access.redhat.com/errata/RHSA-2026:19219&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rmKqD8ZR5vrHqnZkFulqdg==&#34;: {&#xA;      &#34;id&#34;: &#34;rmKqD8ZR5vrHqnZkFulqdg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-64118&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a Tar utility for Node.js. This vulnerability allows a local attacker to potentially disclose sensitive information. When the .t (or .list) function is used with { sync: true } to read tar entry contents, and the tar file is concurrently modified on disk to a smaller size, the function may return uninitialized memory contents. This could lead to the exposure of arbitrary data.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-30T17:50:20Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-64118 https://bugzilla.redhat.com/show_bug.cgi?id=2407440 https://www.cve.org/CVERecord?id=CVE-2025-64118 https://nvd.nist.gov/vuln/detail/CVE-2025-64118 https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d https://github.com/isaacs/node-tar/issues/445 https://github.com/isaacs/node-tar/pull/446 https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-64118.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;tar&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rqKN8+22i5Wi/U+pG39tNg==&#34;: {&#xA;      &#34;id&#34;: &#34;rqKN8+22i5Wi/U+pG39tNg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-13757&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-23T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-13757 https://bugzilla.redhat.com/show_bug.cgi?id=2494556 https://www.cve.org/CVERecord?id=CVE-2026-13757 https://nvd.nist.gov/vuln/detail/CVE-2026-13757 https://github.com/advisories/GHSA-p2wm-69qx-x25w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13757.json https://access.redhat.com/errata/RHSA-2026:49667&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;p11-kit-trust&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:0.26.4-1.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rwC2lB0lflNzttbo5Agt3g==&#34;: {&#xA;      &#34;id&#34;: &#34;rwC2lB0lflNzttbo5Agt3g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-6845&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-13T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-6845 https://bugzilla.redhat.com/show_bug.cgi?id=2460012 https://www.cve.org/CVERecord?id=CVE-2026-6845 https://nvd.nist.gov/vuln/detail/CVE-2026-6845 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6845.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rxGz0C3kTCQwThekjofucw==&#34;: {&#xA;      &#34;id&#34;: &#34;rxGz0C3kTCQwThekjofucw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-56132&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat, a library used for parsing XML data. An attacker could exploit a heap-based buffer overflow, a type of memory error, by providing specially crafted XML input. This vulnerability occurs when the library mishandles memory reallocation while processing XML, particularly when multiple parsers share data. Successful exploitation could allow the attacker to execute arbitrary code, access sensitive information, or cause the application to crash, leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-19T03:00:42Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-56132 https://bugzilla.redhat.com/show_bug.cgi?id=2490669 https://www.cve.org/CVERecord?id=CVE-2026-56132 https://nvd.nist.gov/vuln/detail/CVE-2026-56132 https://github.com/libexpat/libexpat/pull/1272 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56132.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;rzmoKvIFGvuPP0SzaH7s9w==&#34;: {&#xA;      &#34;id&#34;: &#34;rzmoKvIFGvuPP0SzaH7s9w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;s2uSNGuV+OyVW2eHDGWWKw==&#34;: {&#xA;      &#34;id&#34;: &#34;s2uSNGuV+OyVW2eHDGWWKw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-29768&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim&#39;s zip.vim plugin. This vulnerability allows potential data loss via specially crafted zip files when a user views the archive in Vim and presses &#39;x&#39; on an unusual filename.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-03-13T17:04:56Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-29768 https://bugzilla.redhat.com/show_bug.cgi?id=2352418 https://www.cve.org/CVERecord?id=CVE-2025-29768 https://nvd.nist.gov/vuln/detail/CVE-2025-29768 https://github.com/vim/vim/commit/f209dcd3defb95bae21b2740910e6aa7bb940531 https://github.com/vim/vim/security/advisories/GHSA-693p-m996-3rmf https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-29768.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;s6kt2DqKLHgzYSGciPtGtQ==&#34;: {&#xA;      &#34;id&#34;: &#34;s6kt2DqKLHgzYSGciPtGtQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2021-4166&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim. A possible heap-based buffer overflow could allow an attacker to input a specially crafted file leading to a crash or code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2021-12-25T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2021-4166 https://bugzilla.redhat.com/show_bug.cgi?id=2035928 https://www.cve.org/CVERecord?id=CVE-2021-4166 https://nvd.nist.gov/vuln/detail/CVE-2021-4166 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-4166.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;sAlO/t+jkkm59mLcdOgB9w==&#34;: {&#xA;      &#34;id&#34;: &#34;sAlO/t+jkkm59mLcdOgB9w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-1151&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the ld linker utility of GNU Binutils. A specially-crafted payload may be able to trigger a memory leak, which can lead to an application crash or other undefined behavior.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-10T17:00:10Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-1151 https://bugzilla.redhat.com/show_bug.cgi?id=2344713 https://www.cve.org/CVERecord?id=CVE-2025-1151 https://nvd.nist.gov/vuln/detail/CVE-2025-1151 https://sourceware.org/bugzilla/attachment.cgi?id=15887 https://sourceware.org/bugzilla/show_bug.cgi?id=32576 https://vuldb.com/?ctiid.295055 https://vuldb.com/?id.295055 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1151.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;sJNoOKrtqJYf9M2tWcTlqg==&#34;: {&#xA;      &#34;id&#34;: &#34;sJNoOKrtqJYf9M2tWcTlqg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15281&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T13:22:46Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15281 https://bugzilla.redhat.com/show_bug.cgi?id=2431196 https://www.cve.org/CVERecord?id=CVE-2025-15281 https://nvd.nist.gov/vuln/detail/CVE-2025-15281 https://sourceware.org/bugzilla/show_bug.cgi?id=33814 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15281.json https://access.redhat.com/errata/RHSA-2026:2786&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-231.el9_7.10&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;sROfYAX8Ekl+9at4JgS5Lg==&#34;: {&#xA;      &#34;id&#34;: &#34;sROfYAX8Ekl+9at4JgS5Lg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-irb&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:1.13.1-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;sZ07/WOVHRgnOtPAXhah8Q==&#34;: {&#xA;      &#34;id&#34;: &#34;sZ07/WOVHRgnOtPAXhah8Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-25547&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the brace-expansion component. This denial of service (DoS) vulnerability allows a remote attacker to provide specially crafted input containing repeated numeric brace ranges. This input causes the library to attempt an unbounded expansion, consuming excessive CPU and memory resources. This can lead to a system crash, impacting the availability of the service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-04T21:51:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-25547 https://bugzilla.redhat.com/show_bug.cgi?id=2436942 https://www.cve.org/CVERecord?id=CVE-2026-25547 https://nvd.nist.gov/vuln/detail/CVE-2026-25547 https://github.com/isaacs/brace-expansion/security/advisories/GHSA-7h2j-956f-4vf2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25547.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;siR3bdJZdvZI9snXBeScxA==&#34;: {&#xA;      &#34;id&#34;: &#34;siR3bdJZdvZI9snXBeScxA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-8291&#34;,&#xA;      &#34;description&#34;: &#34;A zip file handling flaw has been discovered in the python standard library `zipfile` module. The &#39;zipfile&#39; module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the &#39;zipfile&#39; module compared to other ZIP implementations.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-10-07T18:10:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-8291 https://bugzilla.redhat.com/show_bug.cgi?id=2402342 https://www.cve.org/CVERecord?id=CVE-2025-8291 https://nvd.nist.gov/vuln/detail/CVE-2025-8291 https://github.com/python/cpython/commit/162997bb70e067668c039700141770687bc8f267 https://github.com/python/cpython/commit/333d4a6f4967d3ace91492a39ededbcf3faa76a6 https://github.com/python/cpython/issues/139700 https://github.com/python/cpython/pull/139702 https://mail.python.org/archives/list/security-announce@python.org/thread/QECOPWMTH4VPPJAXAH2BGTA4XADOP62G/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-8291.json https://access.redhat.com/errata/RHSA-2025:23342&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-2.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;smB1yCGhBb8gDhPAER7odg==&#34;: {&#xA;      &#34;id&#34;: &#34;smB1yCGhBb8gDhPAER7odg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14524&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-07T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14524 https://bugzilla.redhat.com/show_bug.cgi?id=2426407 https://www.cve.org/CVERecord?id=CVE-2025-14524 https://nvd.nist.gov/vuln/detail/CVE-2025-14524 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14524.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;sqtLRwfRzV6y9srK/2QK2Q==&#34;: {&#xA;      &#34;id&#34;: &#34;sqtLRwfRzV6y9srK/2QK2Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-9547&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. When a libcurl-based application uses SCP:// or SFTP:// for transfers and employs the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This occurs if the server&#39;s host key type differs from the one stored in the known_hosts file. The callback mechanism fails to enforce the host key restriction, enabling a connection to an untrusted server and risking a man-in-the-middle attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-03T06:18:44Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-9547 https://bugzilla.redhat.com/show_bug.cgi?id=2496758 https://www.cve.org/CVERecord?id=CVE-2026-9547 https://nvd.nist.gov/vuln/detail/CVE-2026-9547 https://curl.se/docs/CVE-2026-9547.html https://curl.se/docs/CVE-2026-9547.json https://hackerone.com/reports/3751712 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9547.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;su1aceqBKJzyQhYk4DtG5w==&#34;: {&#xA;      &#34;id&#34;: &#34;su1aceqBKJzyQhYk4DtG5w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27904&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in minimatch. A remote attacker could exploit this vulnerability by providing a specially crafted glob expression with nested unbounded quantifiers. This could lead to catastrophic backtracking in the V8 JavaScript engine, causing the application to become unresponsive and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-26T01:07:42Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27904 https://bugzilla.redhat.com/show_bug.cgi?id=2442922 https://www.cve.org/CVERecord?id=CVE-2026-27904 https://nvd.nist.gov/vuln/detail/CVE-2026-27904 https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27904.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;svCt47J2Zwa45xj8gn3U/w==&#34;: {&#xA;      &#34;id&#34;: &#34;svCt47J2Zwa45xj8gn3U/w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1485&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Glib&#39;s content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1485 https://bugzilla.redhat.com/show_bug.cgi?id=2433325 https://www.cve.org/CVERecord?id=CVE-2026-1485 https://nvd.nist.gov/vuln/detail/CVE-2026-1485 https://gitlab.gnome.org/GNOME/glib/-/issues/3871 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1485.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;swCufUgs8xGhLcR4oX101Q==&#34;: {&#xA;      &#34;id&#34;: &#34;swCufUgs8xGhLcR4oX101Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69418&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. When applications directly call the low-level CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions with non-block-aligned lengths in a single call on hardware-accelerated builds, the trailing 1-15 bytes of a message may be exposed in cleartext. These exposed bytes are not covered by the authentication tag, allowing an attacker to read or tamper with them without detection.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69418 https://bugzilla.redhat.com/show_bug.cgi?id=2430381 https://www.cve.org/CVERecord?id=CVE-2025-69418 https://nvd.nist.gov/vuln/detail/CVE-2025-69418 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69418.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;sykv+pGN4TXggZNIwL/H4g==&#34;: {&#xA;      &#34;id&#34;: &#34;sykv+pGN4TXggZNIwL/H4g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-5915&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-05-20T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-5915 https://bugzilla.redhat.com/show_bug.cgi?id=2370865 https://www.cve.org/CVERecord?id=CVE-2025-5915 https://nvd.nist.gov/vuln/detail/CVE-2025-5915 https://github.com/libarchive/libarchive/pull/2599 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5915.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;t/e+iLCKcOMzXEuhRWry6g==&#34;: {&#xA;      &#34;id&#34;: &#34;t/e+iLCKcOMzXEuhRWry6g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22796&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a denial of service (DoS) by providing specially crafted PKCS#7 data to an application that performs signature verification. The vulnerability occurs because the application accesses an ASN1_TYPE union member without proper type validation, leading to an invalid or NULL pointer dereference and a crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22796 https://bugzilla.redhat.com/show_bug.cgi?id=2430390 https://www.cve.org/CVERecord?id=CVE-2026-22796 https://nvd.nist.gov/vuln/detail/CVE-2026-22796 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22796.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;t5kXgaRh+bn2vG112hLo2g==&#34;: {&#xA;      &#34;id&#34;: &#34;t5kXgaRh+bn2vG112hLo2g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4438&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4438 https://bugzilla.redhat.com/show_bug.cgi?id=2449783 https://www.cve.org/CVERecord?id=CVE-2026-4438 https://nvd.nist.gov/vuln/detail/CVE-2026-4438 https://sourceware.org/bugzilla/show_bug.cgi?id=34015 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4438.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-minimal-langpack&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;tLSR0X6hQ7hvyPbBXZslBQ==&#34;: {&#xA;      &#34;id&#34;: &#34;tLSR0X6hQ7hvyPbBXZslBQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2126&#34;,&#xA;      &#34;description&#34;: &#34;Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-06-19T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2126 https://bugzilla.redhat.com/show_bug.cgi?id=2099596 https://www.cve.org/CVERecord?id=CVE-2022-2126 https://nvd.nist.gov/vuln/detail/CVE-2022-2126 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2126.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;tOOsPkEJCdO66XvUUd+xnQ==&#34;: {&#xA;      &#34;id&#34;: &#34;tOOsPkEJCdO66XvUUd+xnQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35385&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. When the `scp` command is used by a root user to download a file with the legacy protocol option (`-O`) and without preserving original file permissions (`-p`), the downloaded file can be installed with elevated privileges (setuid or setgid). This unexpected behavior could allow a malicious file to execute with higher permissions than intended, posing a security risk through potential privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:30:59Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35385 https://bugzilla.redhat.com/show_bug.cgi?id=2454469 https://www.cve.org/CVERecord?id=CVE-2026-35385 https://nvd.nist.gov/vuln/detail/CVE-2026-35385 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35385.json https://access.redhat.com/errata/RHSA-2026:19219&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;tUTc+tWHx1wVpIbeqTmR0w==&#34;: {&#xA;      &#34;id&#34;: &#34;tUTc+tWHx1wVpIbeqTmR0w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59874&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:23:47Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59874 https://bugzilla.redhat.com/show_bug.cgi?id=2498116 https://www.cve.org/CVERecord?id=CVE-2026-59874 https://nvd.nist.gov/vuln/detail/CVE-2026-59874 https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59874.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;tbhLz74i3ShwS72WbIsoOA==&#34;: {&#xA;      &#34;id&#34;: &#34;tbhLz74i3ShwS72WbIsoOA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-50495&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry().&#34;,&#xA;      &#34;issued&#34;: &#34;2023-12-12T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-50495 https://bugzilla.redhat.com/show_bug.cgi?id=2254244 https://www.cve.org/CVERecord?id=CVE-2023-50495 https://nvd.nist.gov/vuln/detail/CVE-2023-50495 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-50495.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ncurses&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;tbkEtEs3aa+p2/YQaD8BfQ==&#34;: {&#xA;      &#34;id&#34;: &#34;tbkEtEs3aa+p2/YQaD8BfQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-1972&#34;,&#xA;      &#34;description&#34;: &#34;A potential heap-based buffer overflow was found in binutils in the _bfd_elf_slurp_version_tables() function in bfd/elf.c. This issue may lead to a loss of availability.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-04-10T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-1972 https://bugzilla.redhat.com/show_bug.cgi?id=2185646 https://www.cve.org/CVERecord?id=CVE-2023-1972 https://nvd.nist.gov/vuln/detail/CVE-2023-1972 https://sourceware.org/bugzilla/show_bug.cgi?id=30285 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1972.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;tuPGTYWKd0OWuEIwEsNtuA==&#34;: {&#xA;      &#34;id&#34;: &#34;tuPGTYWKd0OWuEIwEsNtuA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14087&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14087 https://bugzilla.redhat.com/show_bug.cgi?id=2419093 https://www.cve.org/CVERecord?id=CVE-2025-14087 https://nvd.nist.gov/vuln/detail/CVE-2025-14087 https://gitlab.gnome.org/GNOME/glib/-/issues/3834 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14087.json https://access.redhat.com/errata/RHSA-2026:15971&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-18.el9_7.2&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;tvq/gvjGf6pzxLuMOglBaw==&#34;: {&#xA;      &#34;id&#34;: &#34;tvq/gvjGf6pzxLuMOglBaw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4775&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-24T14:33:35Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4775 https://bugzilla.redhat.com/show_bug.cgi?id=2450768 https://www.cve.org/CVERecord?id=CVE-2026-4775 https://nvd.nist.gov/vuln/detail/CVE-2026-4775 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4775.json https://access.redhat.com/errata/RHSA-2026:12271&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libtiff-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:4.4.0-15.el9_7.3&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;txqyo4HZxt82KZ1LFkOAcA==&#34;: {&#xA;      &#34;id&#34;: &#34;txqyo4HZxt82KZ1LFkOAcA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-13149&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-30T08:30:34Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-13149 https://bugzilla.redhat.com/show_bug.cgi?id=2494813 https://www.cve.org/CVERecord?id=CVE-2026-13149 https://nvd.nist.gov/vuln/detail/CVE-2026-13149 https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754 https://www.npmjs.com/package/brace-expansion https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;u0cs09LPRVEEfen4PHM6gA==&#34;: {&#xA;      &#34;id&#34;: &#34;u0cs09LPRVEEfen4PHM6gA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-0990&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-15T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-0990 https://bugzilla.redhat.com/show_bug.cgi?id=2429959 https://www.cve.org/CVERecord?id=CVE-2026-0990 https://nvd.nist.gov/vuln/detail/CVE-2026-0990 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0990.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;u1caIbS4Tk6y8c7sz8Hvhw==&#34;: {&#xA;      &#34;id&#34;: &#34;u1caIbS4Tk6y8c7sz8Hvhw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-41957&#34;,&#xA;      &#34;description&#34;: &#34;A double-free and use-after-free vulnerability was found in the Vim editor. This flaw exists due to the corresponding tagstack being used twice when closing the window and if the quick fix list belonging to that window is also cleared using the same tagstack data. In this instance, Vim will try to free the memory again, causing a crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-08-01T20:41:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-41957 https://bugzilla.redhat.com/show_bug.cgi?id=2302418 https://www.cve.org/CVERecord?id=CVE-2024-41957 https://nvd.nist.gov/vuln/detail/CVE-2024-41957 https://github.com/vim/vim/commit/8a0bbe7b8aad6f8da28dee218c01bc8a0185a https://github.com/vim/vim/security/advisories/GHSA-f9cr-gv85-hcr4 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-41957.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;uDfc8ZaPfrhTGcFwVaIvAA==&#34;: {&#xA;      &#34;id&#34;: &#34;uDfc8ZaPfrhTGcFwVaIvAA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2023-48706&#34;,&#xA;      &#34;description&#34;: &#34;A heap use-after-free flaw was found in the vim package. When executing a `:s` command for the first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes memory to be freed, which may later then be accessed by the initial `:s` command. This issue may result in Vim crashing.&#34;,&#xA;      &#34;issued&#34;: &#34;2023-11-22T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2023-48706 https://bugzilla.redhat.com/show_bug.cgi?id=2251118 https://www.cve.org/CVERecord?id=CVE-2023-48706 https://nvd.nist.gov/vuln/detail/CVE-2023-48706 http://www.openwall.com/lists/oss-security/2023/11/22/3 https://github.com/vim/vim/security/advisories/GHSA-c8qm-x72m-q53q https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-48706.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;uDqtDPBJb3KaOc2STze05w==&#34;: {&#xA;      &#34;id&#34;: &#34;uDqtDPBJb3KaOc2STze05w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4438&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4438 https://bugzilla.redhat.com/show_bug.cgi?id=2449783 https://www.cve.org/CVERecord?id=CVE-2026-4438 https://nvd.nist.gov/vuln/detail/CVE-2026-4438 https://sourceware.org/bugzilla/show_bug.cgi?id=34015 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4438.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;uEn9qA67O/SoYHOtH/EL2w==&#34;: {&#xA;      &#34;id&#34;: &#34;uEn9qA67O/SoYHOtH/EL2w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-1150&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the ld linker utility of GNU Binutils. A specially-crafted payload may be able to trigger a memory leak, which can lead to an application crash or other undefined behavior.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-10T16:31:07Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-1150 https://bugzilla.redhat.com/show_bug.cgi?id=2344681 https://www.cve.org/CVERecord?id=CVE-2025-1150 https://nvd.nist.gov/vuln/detail/CVE-2025-1150 https://sourceware.org/bugzilla/attachment.cgi?id=15887 https://sourceware.org/bugzilla/show_bug.cgi?id=32576 https://vuldb.com/?ctiid.295054 https://vuldb.com/?id.295054 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1150.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;uJJdxHNbejxspD7yZE5qWA==&#34;: {&#xA;      &#34;id&#34;: &#34;uJJdxHNbejxspD7yZE5qWA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4437&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4437 https://bugzilla.redhat.com/show_bug.cgi?id=2449777 https://www.cve.org/CVERecord?id=CVE-2026-4437 https://nvd.nist.gov/vuln/detail/CVE-2026-4437 https://sourceware.org/bugzilla/show_bug.cgi?id=34014 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4437.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-common&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;uLJc9xWoMs4KcjASTFLV/A==&#34;: {&#xA;      &#34;id&#34;: &#34;uLJc9xWoMs4KcjASTFLV/A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-3497&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the OpenSSH GSSAPI (Generic Security Service Application Program Interface) delta patches, as included in various Linux distributions. A remote attacker could exploit this by sending an unexpected GSSAPI message type during the key exchange process. This occurs because the `sshpkt_disconnect()` function, when called on an error, does not properly terminate the process, leading to the continued execution of the program with uninitialized connection variables. Accessing these uninitialized variables can lead to undefined behavior, potentially resulting in information disclosure or a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T18:27:44Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-3497 https://bugzilla.redhat.com/show_bug.cgi?id=2447085 https://www.cve.org/CVERecord?id=CVE-2026-3497 https://nvd.nist.gov/vuln/detail/CVE-2026-3497 https://ubuntu.com/security/CVE-2026-3497 https://www.openwall.com/lists/oss-security/2026/03/12/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3497.json https://access.redhat.com/errata/RHSA-2026:6462&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-48.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;uMTgzWnvZecD0kujuKPIMw==&#34;: {&#xA;      &#34;id&#34;: &#34;uMTgzWnvZecD0kujuKPIMw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-25547&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the brace-expansion component. This denial of service (DoS) vulnerability allows a remote attacker to provide specially crafted input containing repeated numeric brace ranges. This input causes the library to attempt an unbounded expansion, consuming excessive CPU and memory resources. This can lead to a system crash, impacting the availability of the service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-04T21:51:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-25547 https://bugzilla.redhat.com/show_bug.cgi?id=2436942 https://www.cve.org/CVERecord?id=CVE-2026-25547 https://nvd.nist.gov/vuln/detail/CVE-2026-25547 https://github.com/isaacs/brace-expansion/security/advisories/GHSA-7h2j-956f-4vf2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25547.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;uO3OOEY6W3k9QH/tNVK0LQ==&#34;: {&#xA;      &#34;id&#34;: &#34;uO3OOEY6W3k9QH/tNVK0LQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-1152&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the ld linker utility of GNU Binutils. A specially-crafted payload may be able to trigger a memory leak, which can lead to an application crash or other undefined behavior.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-10T18:00:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-1152 https://bugzilla.redhat.com/show_bug.cgi?id=2344723 https://www.cve.org/CVERecord?id=CVE-2025-1152 https://nvd.nist.gov/vuln/detail/CVE-2025-1152 https://sourceware.org/bugzilla/attachment.cgi?id=15887 https://sourceware.org/bugzilla/show_bug.cgi?id=32576 https://vuldb.com/?ctiid.295056 https://vuldb.com/?id.295056 https://www.gnu.org/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1152.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;uPUnbuUJlh23l0km8iQ2tA==&#34;: {&#xA;      &#34;id&#34;: &#34;uPUnbuUJlh23l0km8iQ2tA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69649&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. Processing a specially crafted ELF binary file containing malformed header fields with the readelf program can trigger a NULL pointer dereference, causing a crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69649 https://bugzilla.redhat.com/show_bug.cgi?id=2445298 https://www.cve.org/CVERecord?id=CVE-2025-69649 https://nvd.nist.gov/vuln/detail/CVE-2025-69649 https://sourceware.org/bugzilla/show_bug.cgi?id=33697 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69649.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;uaetuJImncB6wudykQLpEA==&#34;: {&#xA;      &#34;id&#34;: &#34;uaetuJImncB6wudykQLpEA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-1632&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the bsdunzip utility of libarchive. In affected versions, a specially crafted file may trigger a null pointer dereference. This issue can lead to an application crash or other unexpected behavior. This bug does not compromise the integrity or availability of the base system.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-02-24T13:31:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-1632 https://bugzilla.redhat.com/show_bug.cgi?id=2347309 https://www.cve.org/CVERecord?id=CVE-2025-1632 https://nvd.nist.gov/vuln/detail/CVE-2025-1632 https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc https://vuldb.com/?ctiid.296619 https://vuldb.com/?id.296619 https://vuldb.com/?submit.496460 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1632.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;uu3d3lIlYVCZwOjqoNec3g==&#34;: {&#xA;      &#34;id&#34;: &#34;uu3d3lIlYVCZwOjqoNec3g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14104&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-12-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14104 https://bugzilla.redhat.com/show_bug.cgi?id=2419369 https://www.cve.org/CVERecord?id=CVE-2025-14104 https://nvd.nist.gov/vuln/detail/CVE-2025-14104 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14104.json https://access.redhat.com/errata/RHSA-2026:1913&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libblkid&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.37.4-21.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;v/Rdzpp9xZ3VFXBewTwV0A==&#34;: {&#xA;      &#34;id&#34;: &#34;v/Rdzpp9xZ3VFXBewTwV0A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4437&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4437 https://bugzilla.redhat.com/show_bug.cgi?id=2449777 https://www.cve.org/CVERecord?id=CVE-2026-4437 https://nvd.nist.gov/vuln/detail/CVE-2026-4437 https://sourceware.org/bugzilla/show_bug.cgi?id=34014 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4437.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-minimal-langpack&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;v3PTZuvRGvqZW5kgzYKjFA==&#34;: {&#xA;      &#34;id&#34;: &#34;v3PTZuvRGvqZW5kgzYKjFA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27904&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in minimatch. A remote attacker could exploit this vulnerability by providing a specially crafted glob expression with nested unbounded quantifiers. This could lead to catastrophic backtracking in the V8 JavaScript engine, causing the application to become unresponsive and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-26T01:07:42Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27904 https://bugzilla.redhat.com/show_bug.cgi?id=2442922 https://www.cve.org/CVERecord?id=CVE-2026-27904 https://nvd.nist.gov/vuln/detail/CVE-2026-27904 https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27904.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;v9qMLnWqPbLz+WC1hPhb9g==&#34;: {&#xA;      &#34;id&#34;: &#34;v9qMLnWqPbLz+WC1hPhb9g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-64506&#34;,&#xA;      &#34;description&#34;: &#34;A buffer over read flaw has been discovered in libpng. A heap buffer over-read vulnerability exists in libpng&#39;s png_write_image_8bit function when processing 8-bit images through the simplified write API with convert_to_8bit enabled. The vulnerability affects 8-bit grayscale+alpha, RGB/RGBA, and images with incomplete row data. A conditional guard incorrectly allows 8-bit input to enter code expecting 16-bit input, causing reads up to 2 bytes beyond allocated buffer boundaries.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-24T23:41:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-64506 https://bugzilla.redhat.com/show_bug.cgi?id=2416906 https://www.cve.org/CVERecord?id=CVE-2025-64506 https://nvd.nist.gov/vuln/detail/CVE-2025-64506 https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821 https://github.com/pnggroup/libpng/pull/749 https://github.com/pnggroup/libpng/security/advisories/GHSA-qpr4-xm66-hww6 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-64506.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libpng&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vFpvBSl3ZcIap1nZTTjWsg==&#34;: {&#xA;      &#34;id&#34;: &#34;vFpvBSl3ZcIap1nZTTjWsg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-3833&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-30T17:26:28Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-3833 https://bugzilla.redhat.com/show_bug.cgi?id=2445763 https://www.cve.org/CVERecord?id=CVE-2026-3833 https://nvd.nist.gov/vuln/detail/CVE-2026-3833 https://gitlab.com/gnutls/gnutls/-/issues/1803 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3833.json https://access.redhat.com/errata/RHSA-2026:20612&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.10-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vH+nziLZjIpD4JaIkhx3FA==&#34;: {&#xA;      &#34;id&#34;: &#34;vH+nziLZjIpD4JaIkhx3FA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-51298&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in SQLite. A remote attacker could exploit a use-after-free vulnerability in the JSON extraction function. This occurs when the program attempts to access memory after it has been freed, specifically within the `JsonParse` object. Successful exploitation of this vulnerability can lead to a service crash and a denial of service (DoS) for affected systems.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-51298 https://bugzilla.redhat.com/show_bug.cgi?id=2507556 https://www.cve.org/CVERecord?id=CVE-2026-51298 https://nvd.nist.gov/vuln/detail/CVE-2026-51298 https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51298 https://github.com/sqlite/sqlite/blob/master/src/json.c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-51298.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;sqlite&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vKhY2603rcUieT1TILr6/g==&#34;: {&#xA;      &#34;id&#34;: &#34;vKhY2603rcUieT1TILr6/g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41316&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T02:35:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41316 https://bugzilla.redhat.com/show_bug.cgi?id=2461369 https://www.cve.org/CVERecord?id=CVE-2026-41316 https://nvd.nist.gov/vuln/detail/CVE-2026-41316 https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json https://access.redhat.com/errata/RHSA-2026:18030&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-psych&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:5.1.2-6.module+el9.7.0+24248+66578cbb&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vMgggE6Cjv/N2Jk4Dk6FYw==&#34;: {&#xA;      &#34;id&#34;: &#34;vMgggE6Cjv/N2Jk4Dk6FYw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11856&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. When `libcurl` performs a transfer to an HTTP origin using Digest authentication and then reuses the same connection handle for a subsequent transfer to a different origin, it may incorrectly send the authentication header intended for the first origin to the second. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-03T06:13:31Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11856 https://bugzilla.redhat.com/show_bug.cgi?id=2496767 https://www.cve.org/CVERecord?id=CVE-2026-11856 https://nvd.nist.gov/vuln/detail/CVE-2026-11856 https://curl.se/docs/CVE-2026-11856.html https://curl.se/docs/CVE-2026-11856.json https://hackerone.com/reports/3793260 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11856.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vSLFgRYoehmDve19rxyjcw==&#34;: {&#xA;      &#34;id&#34;: &#34;vSLFgRYoehmDve19rxyjcw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27171&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in zlib. An attacker providing specially crafted input to the `crc32_combine64` or `crc32_combine_gen64` functions could trigger an infinite loop within the `x2nmodp` function. This leads to excessive CPU consumption, which can result in a Denial of Service (DoS) for the affected system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-02-18T02:36:19Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27171 https://bugzilla.redhat.com/show_bug.cgi?id=2440530 https://www.cve.org/CVERecord?id=CVE-2026-27171 https://nvd.nist.gov/vuln/detail/CVE-2026-27171 https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/ https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf https://github.com/madler/zlib/issues/904 https://github.com/madler/zlib/releases/tag/v1.3.2 https://ostif.org/zlib-audit-complete/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27171.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rsync&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vTajNh0ysqaO8NuTMU//uw==&#34;: {&#xA;      &#34;id&#34;: &#34;vTajNh0ysqaO8NuTMU//uw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2845&#34;,&#xA;      &#34;description&#34;: &#34;Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-17T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2845 https://bugzilla.redhat.com/show_bug.cgi?id=2119844 https://www.cve.org/CVERecord?id=CVE-2022-2845 https://nvd.nist.gov/vuln/detail/CVE-2022-2845 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2845.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vZIHu7rsNO8R8If5mjyTiw==&#34;: {&#xA;      &#34;id&#34;: &#34;vZIHu7rsNO8R8If5mjyTiw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-69644&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in binutils. A local attacker can exploit a logic flaw in the handling of DWARF (Debugging With Attributed Record Formats) location list headers within the objdump utility. By supplying a crafted binary with malformed debug information, the attacker can cause objdump to enter an unbounded loop, leading to excessive resource consumption and a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-06T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-69644 https://bugzilla.redhat.com/show_bug.cgi?id=2445263 https://www.cve.org/CVERecord?id=CVE-2025-69644 https://nvd.nist.gov/vuln/detail/CVE-2025-69644 https://sourceware.org/bugzilla/show_bug.cgi?id=33639 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69644.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;binutils&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vkypiN/HZjIiT/S9k2qxvA==&#34;: {&#xA;      &#34;id&#34;: &#34;vkypiN/HZjIiT/S9k2qxvA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35385&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. When the `scp` command is used by a root user to download a file with the legacy protocol option (`-O`) and without preserving original file permissions (`-p`), the downloaded file can be installed with elevated privileges (setuid or setgid). This unexpected behavior could allow a malicious file to execute with higher permissions than intended, posing a security risk through potential privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:30:59Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35385 https://bugzilla.redhat.com/show_bug.cgi?id=2454469 https://www.cve.org/CVERecord?id=CVE-2026-35385 https://nvd.nist.gov/vuln/detail/CVE-2026-35385 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35385.json https://access.redhat.com/errata/RHSA-2026:13381&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-49.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vlyMilfR3CdKSdc7LxNzEQ==&#34;: {&#xA;      &#34;id&#34;: &#34;vlyMilfR3CdKSdc7LxNzEQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-54369&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the `acl` package, specifically within its `libacl` pathname-based functions. A local attacker could exploit this vulnerability by using a symbolic link to replace a pathname component. This could allow the attacker to redirect access control list (ACL) read or write operations to arbitrary files or directories, leading to unauthorized manipulation of ACLs and ultimately local privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-29T13:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-54369 https://bugzilla.redhat.com/show_bug.cgi?id=2490277 https://www.cve.org/CVERecord?id=CVE-2026-54369 https://nvd.nist.gov/vuln/detail/CVE-2026-54369 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json https://access.redhat.com/errata/RHSA-2026:42736&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libacl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.4.0-1.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vnI8VBZMnSK/Spr6qFIUOA==&#34;: {&#xA;      &#34;id&#34;: &#34;vnI8VBZMnSK/Spr6qFIUOA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4873&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass the TLS requirement, leading to the transmission of sensitive information in cleartext. This vulnerability, categorized as Cleartext Transmission of Sensitive Information (CWE-319), results in information disclosure.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-29T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4873 https://bugzilla.redhat.com/show_bug.cgi?id=2461200 https://www.cve.org/CVERecord?id=CVE-2026-4873 https://nvd.nist.gov/vuln/detail/CVE-2026-4873 https://curl.se/docs/CVE-2026-4873.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4873.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;vyw54XHJNXkWpKNGLbf2jQ==&#34;: {&#xA;      &#34;id&#34;: &#34;vyw54XHJNXkWpKNGLbf2jQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24294&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw was found in resolv ruby gem. This flaw allows an attacker to craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses this packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-12T03:30:40Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24294 https://bugzilla.redhat.com/show_bug.cgi?id=2379684 https://www.cve.org/CVERecord?id=CVE-2025-24294 https://nvd.nist.gov/vuln/detail/CVE-2025-24294 https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24294.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-bundled-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;w1094TrprBpG+5TZJus6FA==&#34;: {&#xA;      &#34;id&#34;: &#34;w1094TrprBpG+5TZJus6FA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-1674&#34;,&#xA;      &#34;description&#34;: &#34;A NULL pointer dereference flaw was found in vim&#39;s vim_regexec_string() function in regexp.c file. The issue occurs when the function tries to match the buffer with an invalid pattern. This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a NULL pointer dereference that causes an application to crash, leading to a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-05-12T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-1674 https://bugzilla.redhat.com/show_bug.cgi?id=2085393 https://www.cve.org/CVERecord?id=CVE-2022-1674 https://nvd.nist.gov/vuln/detail/CVE-2022-1674 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-1674.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;w4jLCE7e/XkliXylkG5u7w==&#34;: {&#xA;      &#34;id&#34;: &#34;w4jLCE7e/XkliXylkG5u7w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48935&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. The Permission API allows a local user to modify file metadata on paths that have been explicitly set as read-only. This can lead to unauthorized changes in file properties, impacting the integrity of the file system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48935 https://bugzilla.redhat.com/show_bug.cgi?id=2493329 https://www.cve.org/CVERecord?id=CVE-2026-48935 https://nvd.nist.gov/vuln/detail/CVE-2026-48935 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48935.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;w8af/LTYrBLWhYkZBSi2Lg==&#34;: {&#xA;      &#34;id&#34;: &#34;w8af/LTYrBLWhYkZBSi2Lg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-4141&#34;,&#xA;      &#34;description&#34;: &#34;A heap-based buffer overflow vulnerability was found in Vim due to invalid memory access. This issue could allow an attacker to trick a user into opening a specially crafted file, triggering an out-of-bounds write that causes an application to crash, possibly executing code and corrupting memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-11-25T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-4141 https://bugzilla.redhat.com/show_bug.cgi?id=2148991 https://www.cve.org/CVERecord?id=CVE-2022-4141 https://nvd.nist.gov/vuln/detail/CVE-2022-4141 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-4141.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;w8vuCHS+4au/MfXahCBARA==&#34;: {&#xA;      &#34;id&#34;: &#34;w8vuCHS+4au/MfXahCBARA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-13601&#34;,&#xA;      &#34;description&#34;: &#34;A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-24T13:00:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-13601 https://bugzilla.redhat.com/show_bug.cgi?id=2416741 https://www.cve.org/CVERecord?id=CVE-2025-13601 https://nvd.nist.gov/vuln/detail/CVE-2025-13601 https://gitlab.gnome.org/GNOME/glib/-/issues/3827 https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4914 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13601.json https://access.redhat.com/errata/RHSA-2026:0936&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.68.4-18.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;wM3p6vKgVqUkJtSPSQjDlw==&#34;: {&#xA;      &#34;id&#34;: &#34;wM3p6vKgVqUkJtSPSQjDlw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-55655&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-22T23:22:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-55655 https://bugzilla.redhat.com/show_bug.cgi?id=2462250 https://www.cve.org/CVERecord?id=CVE-2026-55655 https://nvd.nist.gov/vuln/detail/CVE-2026-55655 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55655.json https://access.redhat.com/errata/RHSA-2026:47756&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-9.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;wOf+QLuqfByteGwfULI8YA==&#34;: {&#xA;      &#34;id&#34;: &#34;wOf+QLuqfByteGwfULI8YA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1526&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A remote attacker can exploit this vulnerability by sending a specially crafted compressed frame, known as a \&#34;decompression bomb,\&#34; during permessage-deflate decompression. The undici WebSocket client does not properly limit the size of decompressed data, leading to unbounded memory consumption. This can cause the Node.js process to exhaust available memory, resulting in a denial of service (DoS) where the process crashes or becomes unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:08:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1526 https://bugzilla.redhat.com/show_bug.cgi?id=2447142 https://www.cve.org/CVERecord?id=CVE-2026-1526 https://nvd.nist.gov/vuln/detail/CVE-2026-1526 https://cna.openjsf.org/security-advisories.html https://datatracker.ietf.org/doc/html/rfc7692 https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q https://hackerone.com/reports/3481206 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1526.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;wp75ZuWMdeSuJ4xUhgowQA==&#34;: {&#xA;      &#34;id&#34;: &#34;wp75ZuWMdeSuJ4xUhgowQA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42245&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMAP) client functionality. A hostile server can exploit a quadratic time complexity issue in the `Net::IMAP::ResponseReader` when processing large responses containing numerous string literals. This can lead to the client&#39;s CPU being exhausted, resulting in a denial of service (DoS) attack.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:37:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42245 https://bugzilla.redhat.com/show_bug.cgi?id=2468495 https://www.cve.org/CVERecord?id=CVE-2026-42245 https://nvd.nist.gov/vuln/detail/CVE-2026-42245 https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96 https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/releases/tag/v0.6.4 https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42245.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby-bundled-gems&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;wvmpOuM/1L8oJ5qbX5rvJA==&#34;: {&#xA;      &#34;id&#34;: &#34;wvmpOuM/1L8oJ5qbX5rvJA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48934&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48934 https://bugzilla.redhat.com/show_bug.cgi?id=2493332 https://www.cve.org/CVERecord?id=CVE-2026-48934 https://nvd.nist.gov/vuln/detail/CVE-2026-48934 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48934.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;x0MBdOYdUOYndbRBnoiEzw==&#34;: {&#xA;      &#34;id&#34;: &#34;x0MBdOYdUOYndbRBnoiEzw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4438&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc&#39;s DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-20T19:59:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4438 https://bugzilla.redhat.com/show_bug.cgi?id=2449783 https://www.cve.org/CVERecord?id=CVE-2026-4438 https://nvd.nist.gov/vuln/detail/CVE-2026-4438 https://sourceware.org/bugzilla/show_bug.cgi?id=34015 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4438.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-langpack-en&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;xC8Y7thfNSAfn5daCQFvgQ==&#34;: {&#xA;      &#34;id&#34;: &#34;xC8Y7thfNSAfn5daCQFvgQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-7168&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-13T08:29:08Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-7168 https://bugzilla.redhat.com/show_bug.cgi?id=2476979 https://www.cve.org/CVERecord?id=CVE-2026-7168 https://nvd.nist.gov/vuln/detail/CVE-2026-7168 http://www.openwall.com/lists/oss-security/2026/04/29/14 https://curl.se/docs/CVE-2026-7168.html https://curl.se/docs/CVE-2026-7168.json https://hackerone.com/reports/3697719 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7168.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;xQ6R88+x8IssPvOAavmZXw==&#34;: {&#xA;      &#34;id&#34;: &#34;xQ6R88+x8IssPvOAavmZXw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-0530&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Unzip. The vulnerability occurs during the conversion of a UTF-8 string to a local string that leads to a segmentation fault. This flaw allows an attacker to input a specially crafted zip file, leading to a crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-01-31T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-0530 https://bugzilla.redhat.com/show_bug.cgi?id=2051395 https://www.cve.org/CVERecord?id=CVE-2022-0530 https://nvd.nist.gov/vuln/detail/CVE-2022-0530 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-0530.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;unzip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;xRDJz3P8IApYf+UqTsFimg==&#34;: {&#xA;      &#34;id&#34;: &#34;xRDJz3P8IApYf+UqTsFimg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-60001&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH&#39;s SSH daemon (sshd). A remote attacker could exploit this vulnerability by repeatedly attempting authentication. The flaw allows the attacker to bypass the intended minimum authentication delay, which can facilitate brute-force attacks. This makes it easier for an attacker to guess valid credentials, potentially leading to unauthorized access or a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T00:16:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-60001 https://bugzilla.redhat.com/show_bug.cgi?id=2497938 https://www.cve.org/CVERecord?id=CVE-2026-60001 https://nvd.nist.gov/vuln/detail/CVE-2026-60001 https://marc.info/?l=openssh-unix-dev\u0026m=178333966933090\u0026w=2 https://www.openssh.org/releasenotes.html#10.4p1 https://www.openwall.com/lists/oss-security/2026/07/06/5 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-60001.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;xWYQ4aF7Ip3LaKJQzDwx1A==&#34;: {&#xA;      &#34;id&#34;: &#34;xWYQ4aF7Ip3LaKJQzDwx1A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-48935&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Node.js. The Permission API allows a local user to modify file metadata on paths that have been explicitly set as read-only. This can lead to unauthorized changes in file properties, impacting the integrity of the file system.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-26T01:14:36Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-48935 https://bugzilla.redhat.com/show_bug.cgi?id=2493329 https://www.cve.org/CVERecord?id=CVE-2026-48935 https://nvd.nist.gov/vuln/detail/CVE-2026-48935 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48935.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;xh8zszQflFXgahc/vYUUWQ==&#34;: {&#xA;      &#34;id&#34;: &#34;xh8zszQflFXgahc/vYUUWQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-32777&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted Document Type Definition (DTD) content. This could lead to an infinite loop during parsing, resulting in a Denial of Service (DoS) for the application using libexpat.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-16T06:58:06Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-32777 https://bugzilla.redhat.com/show_bug.cgi?id=2447890 https://www.cve.org/CVERecord?id=CVE-2026-32777 https://nvd.nist.gov/vuln/detail/CVE-2026-32777 https://github.com/libexpat/libexpat/issues/1161 https://github.com/libexpat/libexpat/pull/1159 https://github.com/libexpat/libexpat/pull/1162 https://issues.oss-fuzz.com/issues/486993411 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32777.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;expat&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;xpncb/4iGS4E4GyJA4P7Vg==&#34;: {&#xA;      &#34;id&#34;: &#34;xpncb/4iGS4E4GyJA4P7Vg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-34181&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This vulnerability allows a remote attacker to forge PKCS#12 (Public-Key Cryptography Standards #12) files that use Password-Based Message Authentication Code 1 (PBMAC1) with short HMAC (Hash-based Message Authentication Code) keys. This can lead to a service accepting attacker-controlled certificates and private keys with a 1 in 256 probability, potentially enabling impersonation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-09T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-34181 https://bugzilla.redhat.com/show_bug.cgi?id=2481882 https://www.cve.org/CVERecord?id=CVE-2026-34181 https://nvd.nist.gov/vuln/detail/CVE-2026-34181 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34181.json https://access.redhat.com/errata/RHSA-2026:25239&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.5-4.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;xvCKE5h7HgdGkBMwA/kPeg==&#34;: {&#xA;      &#34;id&#34;: &#34;xvCKE5h7HgdGkBMwA/kPeg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42338&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user&#39;s browser.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-12T19:43:16Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42338 https://bugzilla.redhat.com/show_bug.cgi?id=2476810 https://www.cve.org/CVERecord?id=CVE-2026-42338 https://nvd.nist.gov/vuln/detail/CVE-2026-42338 https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json https://access.redhat.com/errata/RHSA-2026:35892&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-1.module+el9.8.0+24457+996af7aa&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;xxrOMZzPk7ETmnvrIjBo0A==&#34;: {&#xA;      &#34;id&#34;: &#34;xxrOMZzPk7ETmnvrIjBo0A==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-60753&#34;,&#xA;      &#34;description&#34;: &#34;A vulnerability in apply_substitution() function in libarchive&#39;s bsdtar allows crafted -s substitution rules to repeatedly match a zero-length substring and append replacements without advancing the input pointer. When the rule uses the global /g flag (or an explicitly empty pattern), this leads to unbounded output allocation and eventual process OOM (Denial of Service). Upgrade to libarchive 3.8.1 or apply a patch that prevents zero-length match loops or rejects empty patterns.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-05T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-60753 https://bugzilla.redhat.com/show_bug.cgi?id=2412648 https://www.cve.org/CVERecord?id=CVE-2025-60753 https://nvd.nist.gov/vuln/detail/CVE-2025-60753 https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753 https://github.com/libarchive/libarchive/issues/2725 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-60753.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libarchive&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;y/3qWQj3xOUQpm2CUr+ftg==&#34;: {&#xA;      &#34;id&#34;: &#34;y/3qWQj3xOUQpm2CUr+ftg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-9820&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-11-18T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-9820 https://bugzilla.redhat.com/show_bug.cgi?id=2392528 https://www.cve.org/CVERecord?id=CVE-2025-9820 https://nvd.nist.gov/vuln/detail/CVE-2025-9820 https://gitlab.com/gnutls/gnutls/-/commit/1d56f96f6ab5034d677136b9d50b5a75dff0faf5 https://gitlab.com/gnutls/gnutls/-/issues/1732 https://www.gnutls.org/security-new.html#GNUTLS-SA-2025-11-18 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9820.json https://access.redhat.com/errata/RHSA-2026:4188&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;gnutls&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.8.3-10.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;y/vNaOETNDNWhjGaBLNhRA==&#34;: {&#xA;      &#34;id&#34;: &#34;y/vNaOETNDNWhjGaBLNhRA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1502&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Python. This vulnerability allows for the injection of extra information into HTTP communication. Specifically, the system does not properly prevent special characters (carriage return and line feed) from being included in HTTP client proxy tunnel headers or host fields.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-10T17:54:44Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1502 https://bugzilla.redhat.com/show_bug.cgi?id=2457409 https://www.cve.org/CVERecord?id=CVE-2026-1502 https://nvd.nist.gov/vuln/detail/CVE-2026-1502 https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69 https://github.com/python/cpython/issues/146211 https://github.com/python/cpython/pull/146212 https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1502.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3.9&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;y6oEGtDp1H5C2csZKAF6bQ==&#34;: {&#xA;      &#34;id&#34;: &#34;y6oEGtDp1H5C2csZKAF6bQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-11979&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in libxml2, specifically within the xmlcatalog utility when operating in shell mode. An attacker can exploit multiple stack-based buffer overflows by providing an excessively long input line. This leads to memory corruption, which may cause the application to crash or potentially allow the attacker to execute arbitrary code within the context of the xmlcatalog process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-06-29T13:21:42Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-11979 https://bugzilla.redhat.com/show_bug.cgi?id=2494191 https://www.cve.org/CVERecord?id=CVE-2026-11979 https://nvd.nist.gov/vuln/detail/CVE-2026-11979 https://cert.pl/en/posts/2026/06/CVE-2026-11979 https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11979.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;y7I268PAr74OoToX85XE8w==&#34;: {&#xA;      &#34;id&#34;: &#34;y7I268PAr74OoToX85XE8w==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-22795&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a Denial of Service (DoS) by tricking a user or application into processing a maliciously crafted PKCS#12 (Personal Information Exchange Syntax Standard) file. The vulnerability leads to an invalid or NULL pointer dereference, resulting in an application crash.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-27T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-22795 https://bugzilla.redhat.com/show_bug.cgi?id=2430389 https://www.cve.org/CVERecord?id=CVE-2026-22795 https://nvd.nist.gov/vuln/detail/CVE-2026-22795 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22795.json https://access.redhat.com/errata/RHSA-2026:1473&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssl-libs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:3.5.1-7.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;yNrm+PctJj5AEVwT8bDpBg==&#34;: {&#xA;      &#34;id&#34;: &#34;yNrm+PctJj5AEVwT8bDpBg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35385&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. When the `scp` command is used by a root user to download a file with the legacy protocol option (`-O`) and without preserving original file permissions (`-p`), the downloaded file can be installed with elevated privileges (setuid or setgid). This unexpected behavior could allow a malicious file to execute with higher permissions than intended, posing a security risk through potential privilege escalation.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T16:30:59Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35385 https://bugzilla.redhat.com/show_bug.cgi?id=2454469 https://www.cve.org/CVERecord?id=CVE-2026-35385 https://nvd.nist.gov/vuln/detail/CVE-2026-35385 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35385.json https://access.redhat.com/errata/RHSA-2026:19219&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:9.9p1-7.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ySo9uDHfIeTwH0aLjgaN9g==&#34;: {&#xA;      &#34;id&#34;: &#34;ySo9uDHfIeTwH0aLjgaN9g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-4046&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-30T17:16:11Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-4046 https://bugzilla.redhat.com/show_bug.cgi?id=2453117 https://www.cve.org/CVERecord?id=CVE-2026-4046 https://nvd.nist.gov/vuln/detail/CVE-2026-4046 https://packages.fedoraproject.org/pkgs/glibc/glibc-gconv-extra/ https://sourceware.org/bugzilla/show_bug.cgi?id=33980 https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4046.json https://access.redhat.com/errata/RHSA-2026:20597&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-minimal-langpack&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-270.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;yTSOiGJiuQRZ1n0kXjMC8g==&#34;: {&#xA;      &#34;id&#34;: &#34;yTSOiGJiuQRZ1n0kXjMC8g==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2024-34459&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the xmllint program distributed by the libxml2 package. A buffer over-read in the xmlHTMLPrintFileContext function in the xmllint.c file may be triggered when a crafted file is processed with the xmllint program using the `--htmlout` command line option, causing an application crash and resulting in a denial of service.&#34;,&#xA;      &#34;issued&#34;: &#34;2024-05-08T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2024-34459 https://bugzilla.redhat.com/show_bug.cgi?id=2280532 https://www.cve.org/CVERecord?id=CVE-2024-34459 https://nvd.nist.gov/vuln/detail/CVE-2024-34459 https://gitlab.gnome.org/GNOME/libxml2/-/issues/720 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-34459.json https://access.redhat.com/errata/RHSA-2026:28254&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libxml2-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.9.13-14.el9_8.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;yXjhPZPggtyVHOPFjmeHOg==&#34;: {&#xA;      &#34;id&#34;: &#34;yXjhPZPggtyVHOPFjmeHOg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-29111&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-23T21:03:56Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-29111 https://bugzilla.redhat.com/show_bug.cgi?id=2450505 https://www.cve.org/CVERecord?id=CVE-2026-29111 https://nvd.nist.gov/vuln/detail/CVE-2026-29111 https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6 https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8 https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29111.json https://access.redhat.com/errata/RHSA-2026:13677&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;systemd-rpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:252-55.el9_7.9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;yeUq/7JaeNz2SDn0gWjVQw==&#34;: {&#xA;      &#34;id&#34;: &#34;yeUq/7JaeNz2SDn0gWjVQw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-27135&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 frame, leading to an assertion failure and a denial of service (DoS).&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-18T17:59:02Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-27135 https://bugzilla.redhat.com/show_bug.cgi?id=2448754 https://www.cve.org/CVERecord?id=CVE-2026-27135 https://nvd.nist.gov/vuln/detail/CVE-2026-27135 https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1 https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ylg3k+AtgUcIl3hJiXNMlw==&#34;: {&#xA;      &#34;id&#34;: &#34;ylg3k+AtgUcIl3hJiXNMlw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-2946&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim, where it is vulnerable to a use-after-free in the vim_vsnprintf_typval function. This flaw allows a specially crafted file to crash a program, use unexpected values, or execute code.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-08-23T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-2946 https://bugzilla.redhat.com/show_bug.cgi?id=2120993 https://www.cve.org/CVERecord?id=CVE-2022-2946 https://nvd.nist.gov/vuln/detail/CVE-2022-2946 https://huntr.dev/bounties/5d389a18-5026-47df-a5d0-1548a9b555d5 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-2946.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ymKqobod4xPivmLT/iq9oQ==&#34;: {&#xA;      &#34;id&#34;: &#34;ymKqobod4xPivmLT/iq9oQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41990&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Libgcrypt. During Dilithium signing operations, the library fails to perform a bounds check when writing to a static array. While the data involved is not directly controlled by an attacker, this vulnerability could lead to memory corruption, potentially resulting in a denial of service (DoS) or affecting data integrity.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-23T04:39:04Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41990 https://bugzilla.redhat.com/show_bug.cgi?id=2461068 https://www.cve.org/CVERecord?id=CVE-2026-41990 https://nvd.nist.gov/vuln/detail/CVE-2026-41990 https://dev.gnupg.org/T8208 https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html https://www.openwall.com/lists/oss-security/2026/04/21/1 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41990.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;libgcrypt&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ymZOc8rtV2bmln3PExOD3Q==&#34;: {&#xA;      &#34;id&#34;: &#34;ymZOc8rtV2bmln3PExOD3Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-59874&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-08T15:23:47Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-59874 https://bugzilla.redhat.com/show_bug.cgi?id=2498116 https://www.cve.org/CVERecord?id=CVE-2026-59874 https://nvd.nist.gov/vuln/detail/CVE-2026-59874 https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59874.json https://access.redhat.com/errata/RHSA-2026:47058&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-docs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.23.1-2.module+el9.8.0+24538+3f176d52&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;yyVb0QTi/Vc4LSIxOEuhqA==&#34;: {&#xA;      &#34;id&#34;: &#34;yyVb0QTi/Vc4LSIxOEuhqA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-42246&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the Ruby net-imap library. When upgrading a cleartext IMAP connection to TLS using the Net::IMAP#starttls method, the library improperly handles certain responses received during STARTTLS negotiation. A man-in-the-middle (MITM) attacker can inject a predicted tagged OK response before the client completes the STARTTLS command, causing the operation to appear successful without establishing a TLS session. As a result, the connection may continue to transmit sensitive information in cleartext and enable modification of data exchanged over the affected connection, while the application incorrectly believes that encryption has been enabled.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-05-09T19:33:17Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-42246 https://bugzilla.redhat.com/show_bug.cgi?id=2468499 https://www.cve.org/CVERecord?id=CVE-2026-42246 https://nvd.nist.gov/vuln/detail/CVE-2026-42246 https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da https://github.com/ruby/net-imap/releases/tag/v0.3.10 https://github.com/ruby/net-imap/releases/tag/v0.4.24 https://github.com/ruby/net-imap/releases/tag/v0.5.14 https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json https://access.redhat.com/errata/RHSA-2026:33576&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;rubygem-psych&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:5.1.2-7.module+el9.8.0+24406+8975e57f&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;yzZzF1vLZmeTiLJMgY7W0Q==&#34;: {&#xA;      &#34;id&#34;: &#34;yzZzF1vLZmeTiLJMgY7W0Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-7039&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-07-02T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-7039 https://bugzilla.redhat.com/show_bug.cgi?id=2392423 https://www.cve.org/CVERecord?id=CVE-2025-7039 https://nvd.nist.gov/vuln/detail/CVE-2025-7039 https://gitlab.gnome.org/GNOME/glib/-/issues/3716 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-7039.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glib2&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;z6EnRvmkq3BmM0fg3cIFAQ==&#34;: {&#xA;      &#34;id&#34;: &#34;z6EnRvmkq3BmM0fg3cIFAQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-55131&#34;,&#xA;      &#34;description&#34;: &#34;A memory exposure flaw has been discovered in Node.js. A flaw in Node.js&#39;s buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain leftover data from previous operations, allowing in-process secrets like tokens or passwords to leak or causing data corruption.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-55131 https://bugzilla.redhat.com/show_bug.cgi?id=2431350 https://www.cve.org/CVERecord?id=CVE-2025-55131 https://nvd.nist.gov/vuln/detail/CVE-2025-55131 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55131.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs-full-i18n&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.0-1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zAQhwfD+1kpXY0CwZC6HxA==&#34;: {&#xA;      &#34;id&#34;: &#34;zAQhwfD+1kpXY0CwZC6HxA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-24014&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim. In silent Ex mode (-s -e), Vim typically doesn&#39;t show a screen and operates silently in batch mode, however, it is possible to trigger the function that handles the scrolling of a GUI version of Vim via binary characters. The function that handles the scrolling may trigger a redraw, which will access the ScreenLines pointer and can cause a segmentation fault condition. This may lead to an application crash or other undefined behavior.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-01-20T22:53:14Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-24014 https://bugzilla.redhat.com/show_bug.cgi?id=2339074 https://www.cve.org/CVERecord?id=CVE-2025-24014 https://nvd.nist.gov/vuln/detail/CVE-2025-24014 https://github.com/vim/vim/commit/9d1bed5eccdbb46a26b8a484f5e9163c40e63919 https://github.com/vim/vim/security/advisories/GHSA-j3g9-wg22-v955 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24014.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zDmU3WG0c3AQYw7NFebUCQ==&#34;: {&#xA;      &#34;id&#34;: &#34;zDmU3WG0c3AQYw7NFebUCQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-3234&#34;,&#xA;      &#34;description&#34;: &#34;Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-09-18T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-3234 https://bugzilla.redhat.com/show_bug.cgi?id=2129370 https://www.cve.org/CVERecord?id=CVE-2022-3234 https://nvd.nist.gov/vuln/detail/CVE-2022-3234 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3234.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zE3cPdw4Ma9jQQUVeE/hdg==&#34;: {&#xA;      &#34;id&#34;: &#34;zE3cPdw4Ma9jQQUVeE/hdg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-35414&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in OpenSSH. This vulnerability arises from the incorrect handling of the authorized_keys principals option in uncommon scenarios. Specifically, when a principals list is used with a Certificate Authority that includes comma characters, OpenSSH may misinterpret the input. This could lead to security bypasses, potentially allowing unintended access or information disclosure in specific authentication contexts.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-02T17:08:15Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-35414 https://bugzilla.redhat.com/show_bug.cgi?id=2454490 https://www.cve.org/CVERecord?id=CVE-2026-35414 https://nvd.nist.gov/vuln/detail/CVE-2026-35414 https://marc.info/?l=openssh-unix-dev\u0026m=177513443901484\u0026w=2 https://www.openssh.org/releasenotes.html#10.3p1 https://www.openwall.com/lists/oss-security/2026/04/02/3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35414.json https://access.redhat.com/errata/RHSA-2026:13381&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;openssh-clients&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:8.7p1-49.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zHSqcJBwH0Go6UqHQ1Fu/Q==&#34;: {&#xA;      &#34;id&#34;: &#34;zHSqcJBwH0Go6UqHQ1Fu/Q==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-13346&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in pip. When processing doubly-encoded package URLs from malicious package indexes, pip incorrectly handles the file paths. A remote attacker could exploit this by convincing a user to download or install a package from such an index. This could allow for files to be installed to arbitrary locations on the system, potentially leading to system compromise. This vulnerability primarily affects users utilizing the `pip download` command with the `--only-binary` option.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-07-29T18:33:50Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-13346 https://bugzilla.redhat.com/show_bug.cgi?id=2508514 https://www.cve.org/CVERecord?id=CVE-2026-13346 https://nvd.nist.gov/vuln/detail/CVE-2026-13346 https://github.com/pypa/pip/pull/14110 https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13346.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python-pip&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zL8cYwtASK3csnxhG4umrQ==&#34;: {&#xA;      &#34;id&#34;: &#34;zL8cYwtASK3csnxhG4umrQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-1528&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a specially crafted WebSocket frame with an extremely large 64-bit length. This causes undici&#39;s ByteParser to overflow its internal calculations, leading to an invalid state and a fatal TypeError. The primary consequence is a Denial of Service (DoS), which terminates the process.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-12T20:21:57Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-1528 https://bugzilla.redhat.com/show_bug.cgi?id=2447145 https://www.cve.org/CVERecord?id=CVE-2026-1528 https://nvd.nist.gov/vuln/detail/CVE-2026-1528 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj https://hackerone.com/reports/3537648 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1528.json https://access.redhat.com/errata/RHSA-2026:7302&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;nodejs&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:22.22.2-1.module+el9.7.0+24157+8ddb2461&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zXyE3S2RgbWC3bSm5zxzpw==&#34;: {&#xA;      &#34;id&#34;: &#34;zXyE3S2RgbWC3bSm5zxzpw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-58767&#34;,&#xA;      &#34;description&#34;: &#34;A denial of service flaw has been discovered in the rubygem REXML. Certain input can cause excess cpu usage and given sufficiently large input this can affect program performance.&#34;,&#xA;      &#34;issued&#34;: &#34;2025-09-17T17:45:58Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-58767 https://bugzilla.redhat.com/show_bug.cgi?id=2396186 https://www.cve.org/CVERecord?id=CVE-2025-58767 https://nvd.nist.gov/vuln/detail/CVE-2025-58767 https://github.com/ruby/rexml/commit/5859bdeac792687eaf93d8e8f0b7e3c1e2ed5c23 https://github.com/ruby/rexml/security/advisories/GHSA-c2f4-jgmc-q2r5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-58767.json https://access.redhat.com/errata/RHSA-2025:23063&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;ruby&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;ruby:3.3&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|src|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.3.10-5.module+el9.7.0+23651+15dc1615&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zY/8tgCkQEbX9yVIGbkTFQ==&#34;: {&#xA;      &#34;id&#34;: &#34;zY/8tgCkQEbX9yVIGbkTFQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-5450&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-20T20:55:41Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;glibc-devel&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:2.34-272.el9_8&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zY7J45b8Kt4bFIMHib/PGQ==&#34;: {&#xA;      &#34;id&#34;: &#34;zY7J45b8Kt4bFIMHib/PGQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-21637&#34;,&#xA;      &#34;description&#34;: &#34;A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T20:41:55Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-21637 https://bugzilla.redhat.com/show_bug.cgi?id=2431340 https://www.cve.org/CVERecord?id=CVE-2026-21637 https://nvd.nist.gov/vuln/detail/CVE-2026-21637 https://nodejs.org/en/blog/vulnerability/december-2025-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21637.json https://access.redhat.com/errata/RHSA-2026:2782&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;npm&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;module&#34;: &#34;nodejs:22&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;1:10.9.4-1.22.22.0.1.module+el9.7.0+23896+b5802de9&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zYQmqjwBNORHvvIZjBy6jg==&#34;: {&#xA;      &#34;id&#34;: &#34;zYQmqjwBNORHvvIZjBy6jg==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-25679&#34;,&#xA;      &#34;description&#34;: &#34;The Go standard library function net/url.Parse insufficiently validated the host/authority component and accepted some invalid URLs by effectively treating garbage before an IP-literal as ignorable. The function should have rejected this as invalid.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-03-06T21:28:14Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-25679 https://bugzilla.redhat.com/show_bug.cgi?id=2445356 https://www.cve.org/CVERecord?id=CVE-2026-25679 https://nvd.nist.gov/vuln/detail/CVE-2026-25679 https://go.dev/cl/752180 https://go.dev/issue/77578 https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk https://pkg.go.dev/vuln/GO-2026-4601 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json https://access.redhat.com/errata/RHSA-2026:8841&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;High&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;go-srpm-macros&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;noarch&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.6.0-14.el9_7&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zec/1Gm7Idd0fQLOCpU8jA==&#34;: {&#xA;      &#34;id&#34;: &#34;zec/1Gm7Idd0fQLOCpU8jA==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-15367&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in the poplib module in the Python standard library. The poplib module does not reject control characters, such as newlines, in user-controlled input passed to POP3 commands. This issue allows an attacker to inject additional commands to be executed in the POP3 server.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-20T21:47:09Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-15367 https://bugzilla.redhat.com/show_bug.cgi?id=2431373 https://www.cve.org/CVERecord?id=CVE-2025-15367 https://nvd.nist.gov/vuln/detail/CVE-2025-15367 https://github.com/python/cpython/issues/143923 https://github.com/python/cpython/pull/143924 https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15367.json https://access.redhat.com/errata/RHSA-2026:4168&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;python3&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|i686|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;0:3.9.25-3.el9_7.1&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zqGJegkbTlVqcHBa6HtRTQ==&#34;: {&#xA;      &#34;id&#34;: &#34;zqGJegkbTlVqcHBa6HtRTQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2025-14017&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in curl. When performing multi-threaded LDAPS (Lightweight Directory Access Protocol Secure) transfers, changes to Transport Layer Security (TLS) options in one thread could inadvertently apply globally, affecting other concurrent transfers. This could lead to unintended security posture changes, such as disabling certificate verification for other threads. This vulnerability can result in a security bypass, where expected security checks are not performed.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-01-08T10:07:05Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2025-14017 https://bugzilla.redhat.com/show_bug.cgi?id=2427870 https://www.cve.org/CVERecord?id=CVE-2025-14017 https://nvd.nist.gov/vuln/detail/CVE-2025-14017 https://curl.se/docs/CVE-2025-14017.html https://curl.se/docs/CVE-2025-14017.json https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14017.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;curl&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;ztB6Kn+K/mTyhZBUwqsoDw==&#34;: {&#xA;      &#34;id&#34;: &#34;ztB6Kn+K/mTyhZBUwqsoDw==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2026-41411&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in Vim, an open-source command-line text editor. This command injection vulnerability occurs during tag file processing. A local user could craft a malicious tags file containing backtick syntax in the filename field. When Vim resolves a tag from this file, it executes the embedded command via the system shell, leading to arbitrary code execution with the privileges of the running user.&#34;,&#xA;      &#34;issued&#34;: &#34;2026-04-24T16:51:39Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2026-41411 https://bugzilla.redhat.com/show_bug.cgi?id=2461614 https://www.cve.org/CVERecord?id=CVE-2026-41411 https://nvd.nist.gov/vuln/detail/CVE-2026-41411 https://github.com/vim/vim/commit/c78194e41d5a0b05b0ddf383b6679b1503f977fb https://github.com/vim/vim/releases/tag/v9.2.0357 https://github.com/vim/vim/security/advisories/GHSA-cwgx-gcj7-6qh8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41411.json https://access.redhat.com/errata/RHSA-2026:28209&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Medium&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim-minimal&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;binary&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;aarch64|ppc64le|s390x|amd64|x86_64&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;2:8.2.2637-26.el9_8.6&#34;,&#xA;      &#34;arch_op&#34;: &#34;pattern match&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    },&#xA;    &#34;zx97OaxgXH8j+mFWesQySQ==&#34;: {&#xA;      &#34;id&#34;: &#34;zx97OaxgXH8j+mFWesQySQ==&#34;,&#xA;      &#34;updater&#34;: &#34;rhel-vex&#34;,&#xA;      &#34;name&#34;: &#34;CVE-2022-1620&#34;,&#xA;      &#34;description&#34;: &#34;A flaw was found in vim, which is vulnerable to a NULL pointer dereference in vim_regexec_string() of the regexp.c function. This flaw allows a specially crafted file to crash software when opened in vim.&#34;,&#xA;      &#34;issued&#34;: &#34;2022-05-08T00:00:00Z&#34;,&#xA;      &#34;links&#34;: &#34;https://access.redhat.com/security/cve/CVE-2022-1620 https://bugzilla.redhat.com/show_bug.cgi?id=2083029 https://www.cve.org/CVERecord?id=CVE-2022-1620 https://nvd.nist.gov/vuln/detail/CVE-2022-1620 https://huntr.dev/bounties/7a4c59f3-fcc0-4496-995d-5ca6acd2da51/ https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-1620.json&#34;,&#xA;      &#34;severity&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;      &#34;normalized_severity&#34;: &#34;Low&#34;,&#xA;      &#34;package&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;vim&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;kind&#34;: &#34;source&#34;,&#xA;        &#34;normalized_version&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;detector&#34;: null&#xA;      },&#xA;      &#34;distribution&#34;: {&#xA;        &#34;id&#34;: &#34;&#34;,&#xA;        &#34;did&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;,&#xA;        &#34;version&#34;: &#34;&#34;,&#xA;        &#34;version_code_name&#34;: &#34;&#34;,&#xA;        &#34;version_id&#34;: &#34;&#34;,&#xA;        &#34;arch&#34;: &#34;&#34;,&#xA;        &#34;cpe&#34;: &#34;&#34;,&#xA;        &#34;pretty_name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;repository&#34;: {&#xA;        &#34;name&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;,&#xA;        &#34;key&#34;: &#34;rhel-cpe-repository&#34;,&#xA;        &#34;cpe&#34;: &#34;cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*&#34;&#xA;      },&#xA;      &#34;fixed_in_version&#34;: &#34;&#34;,&#xA;      &#34;Self&#34;: {&#xA;        &#34;space&#34;: &#34;&#34;,&#xA;        &#34;name&#34;: &#34;&#34;&#xA;      },&#xA;      &#34;Aliases&#34;: null,&#xA;      &#34;Invert&#34;: false&#xA;    }&#xA;  },&#xA;  &#34;package_vulnerabilities&#34;: {&#xA;    &#34;+8b2rLdXTkZ4Ylx7vWU2tQ==&#34;: [&#xA;      &#34;DrIVK8+yvV91OzF2CS9o5A==&#34;,&#xA;      &#34;gg6QYPBlPoN8zpwNyr7x6w==&#34;,&#xA;      &#34;+mMVfpx9oV/yykDKHrEHwQ==&#34;,&#xA;      &#34;QskDoDnTSvrQeDXklM4YOw==&#34;&#xA;    ],&#xA;    &#34;+bwl6UbMaWOBWdHNekJsEw==&#34;: [&#xA;      &#34;LiIvRwi7+1nAVErMH0hoaQ==&#34;,&#xA;      &#34;T1g7X8ESyY5xnqSayytC4w==&#34;,&#xA;      &#34;7KIsr/dNSaeE3wdgBYfrgQ==&#34;&#xA;    ],&#xA;    &#34;+kdviPHeaPmwEsPQK85KjQ==&#34;: [&#xA;      &#34;2TDjlt2gAEWsLyBBPigFYw==&#34;,&#xA;      &#34;5BksN0izCeDRrtFMsNCyvg==&#34;,&#xA;      &#34;6hAQW3vY9ZA/8datv1rY4g==&#34;,&#xA;      &#34;0E1VjQWdmolR9lr9ElIZZQ==&#34;,&#xA;      &#34;M293c+QguJ/aaYP3cMwfyQ==&#34;,&#xA;      &#34;mZCCwO//htsOIXazj/SeOw==&#34;,&#xA;      &#34;41OUTxSbBLQGne4TzJuTQg==&#34;,&#xA;      &#34;Y3fno6fRSl46BTZQlReNKg==&#34;,&#xA;      &#34;AF4l+pfrs0Si/0Bf3toHtA==&#34;,&#xA;      &#34;BXYBFOm74zXwzmdOdyNhzA==&#34;,&#xA;      &#34;VHPIyM/Zt8Ma4iUgT7UsMw==&#34;,&#xA;      &#34;5pY8wChj1DLVETzEMa22Ig==&#34;,&#xA;      &#34;DW2DUdu8ljrldYoM7Mprtg==&#34;,&#xA;      &#34;Teb2ue8GsbLkJUoUyGyGsA==&#34;,&#xA;      &#34;b9vpp7YMXEAHYnt8gPj4PA==&#34;,&#xA;      &#34;Xnj4Kpl+tPifTh/+xOnglw==&#34;,&#xA;      &#34;+20onLS/dWLg9saGZqMvvA==&#34;,&#xA;      &#34;5mdxwKcXZHEqEguvWMJQ3w==&#34;,&#xA;      &#34;DsZp+BRVz/OTV0jFXHylmA==&#34;,&#xA;      &#34;2Apbu80O6R41VOd2ICqODw==&#34;,&#xA;      &#34;swCufUgs8xGhLcR4oX101Q==&#34;,&#xA;      &#34;7tbcfIdYm3nwAiNQR5eK/Q==&#34;,&#xA;      &#34;TvusqX9NwPqfJWjNoF5ThA==&#34;,&#xA;      &#34;JYnbFl5uln18531ZOk6t8g==&#34;,&#xA;      &#34;6+K4D2mkqcFFftanju984w==&#34;,&#xA;      &#34;mgY0OXX1J12mJy1iNllE3A==&#34;,&#xA;      &#34;bQ1N5xPGM/wU59iAjdfQ6A==&#34;,&#xA;      &#34;40wPd5q9E1sRluf3JeA8hw==&#34;,&#xA;      &#34;hbenTywo0l7anle5/bJQBw==&#34;,&#xA;      &#34;t/e+iLCKcOMzXEuhRWry6g==&#34;,&#xA;      &#34;nZ2DFaqiaft4/Dqj5SJp4Q==&#34;,&#xA;      &#34;7d4YdteAff532bV2Gg5lmw==&#34;,&#xA;      &#34;+fYUom03o4taYF0LdBwDsg==&#34;,&#xA;      &#34;TFhgbPsd17URo8rNJh9SWQ==&#34;,&#xA;      &#34;EGiW9TUcKA6dU0wY//GJ7w==&#34;,&#xA;      &#34;EmYlXCkWzU0dM5AZphsDzw==&#34;&#xA;    ],&#xA;    &#34;/Bb6eVO+je9kbuIGTvt6Ww==&#34;: [&#xA;      &#34;tbhLz74i3ShwS72WbIsoOA==&#34;&#xA;    ],&#xA;    &#34;/L1kFEoHZTukrNTCQLypFQ==&#34;: [&#xA;      &#34;aOUfuyvyyWEe7Z1IZT+fGw==&#34;&#xA;    ],&#xA;    &#34;/XUXPfxfCal3j0ldx+af3A==&#34;: [&#xA;      &#34;5VGw1oph7DgrzGqxDXSJIA==&#34;&#xA;    ],&#xA;    &#34;/h/TBQhfoSMCmey5oN87jA==&#34;: [&#xA;      &#34;922No9XwoInf4IDk2/SEuA==&#34;,&#xA;      &#34;VJENPcmZwV+YJWnk88f2ug==&#34;,&#xA;      &#34;0q4mJ3RDNOZ/qRqKXOz7Tg==&#34;&#xA;    ],&#xA;    &#34;/ub7EE8Da46T0x7lRdlVJg==&#34;: [&#xA;      &#34;T+jfDhqJcXwVQ38oWEz/6g==&#34;,&#xA;      &#34;e0/Fzu8wfMZp9zX32i9rMQ==&#34;,&#xA;      &#34;7CfySs4FmTkWgJPjEar4eg==&#34;&#xA;    ],&#xA;    &#34;1p1wTPVFlokLdC9/X3ksGg==&#34;: [&#xA;      &#34;KHHIjt6Egtc7csaIbQ3mbw==&#34;,&#xA;      &#34;xh8zszQflFXgahc/vYUUWQ==&#34;,&#xA;      &#34;1geoBO6lBMXVRM+dfApwgw==&#34;,&#xA;      &#34;iYahLjRBvYk4Zq4Nz9JtHg==&#34;,&#xA;      &#34;4o31bbgKJ2cSqPGCPyFjLQ==&#34;,&#xA;      &#34;Hg9hK3dp3A/kFUiUwl8AoQ==&#34;,&#xA;      &#34;Hoba3nMTEuYEZMkGsuPdgg==&#34;,&#xA;      &#34;Hk8k4qPIhaJI1mipqA9iiw==&#34;,&#xA;      &#34;UL/j2Mi69IC+SfjF07J7rg==&#34;,&#xA;      &#34;Uk5o/hpaP3fKN3OvrwIC+w==&#34;,&#xA;      &#34;BaEDBo8YJd5pwSQNkGzAFg==&#34;,&#xA;      &#34;SQcVquEPU3fE4fDQPb3bLQ==&#34;,&#xA;      &#34;D/8pir/aXD8E2iIv4dA/Pg==&#34;,&#xA;      &#34;rxGz0C3kTCQwThekjofucw==&#34;,&#xA;      &#34;3285RkL43CGSYbmius5+sg==&#34;&#xA;    ],&#xA;    &#34;20ttMIcZDyeRDwHLGLpY5g==&#34;: [&#xA;      &#34;ZhTLRTlcbZumWmiritxOAw==&#34;,&#xA;      &#34;1NSoxvCfCFl4ic84FsWulA==&#34;,&#xA;      &#34;hUsu+oNx2zrpqDVbukPejw==&#34;,&#xA;      &#34;/eHyvb2Yvu/vFkWHODEbfw==&#34;,&#xA;      &#34;Fw+ArhlgBhD30C7D93vYhg==&#34;,&#xA;      &#34;VwRZMkFc1pqkTIff/cjZtQ==&#34;,&#xA;      &#34;4TbG63vud59mo+N/aCOqpg==&#34;,&#xA;      &#34;B+E5cjNC599y+nmprS3J2Q==&#34;,&#xA;      &#34;SfJy5i/9nh3s5fpZxZDQCg==&#34;,&#xA;      &#34;Vt9MtkEoE3rKa0ninTNTkg==&#34;,&#xA;      &#34;TT6ujth4uzblGI4VcnKBOw==&#34;,&#xA;      &#34;2Yo5V5wVVXhJ0VU+H57P9g==&#34;,&#xA;      &#34;Lr5d+BjmGHyC+AWnFQJRTA==&#34;,&#xA;      &#34;4W4pMj/8K/7jCdYTXT5uEg==&#34;,&#xA;      &#34;Dif/+rLLCWjJt5Bzau2zsA==&#34;,&#xA;      &#34;4H2TsDPy1XcHidTqNqeZpg==&#34;,&#xA;      &#34;4w9ia49tOv0+yiq1lgkH0w==&#34;,&#xA;      &#34;YXlS56JkLiuXwjbDNwkvdw==&#34;,&#xA;      &#34;Rrms4yDDctk9MqbL4wHXYA==&#34;,&#xA;      &#34;eM2mlJEyKuGpc2sJMlq4xA==&#34;,&#xA;      &#34;OaLF1hM9BwMPMfYWn9kNEA==&#34;,&#xA;      &#34;Ds5dBDqvRggZONNskvuAwg==&#34;,&#xA;      &#34;mZC3gBcn6x1aC7q9hXUpKg==&#34;,&#xA;      &#34;y/vNaOETNDNWhjGaBLNhRA==&#34;,&#xA;      &#34;EFXoHkta9v8NXWXURLTCBw==&#34;,&#xA;      &#34;lCc1jyHfsFJK2HfULjN8pA==&#34;,&#xA;      &#34;FW+E40XkknH5Jv24oip5Ow==&#34;,&#xA;      &#34;GW37uYQxwwgJBIDtA/dT2g==&#34;,&#xA;      &#34;d9oy2JiAKtie2N1lu2J6ew==&#34;,&#xA;      &#34;m/cpX9gyFETv4B87S/qRxw==&#34;,&#xA;      &#34;V2/vsNJeH5BxrzuVis91/A==&#34;,&#xA;      &#34;VuDrFzex6yJBFISXUtfUGQ==&#34;,&#xA;      &#34;V8tjixCGBsaAWvQP5Hvn+A==&#34;,&#xA;      &#34;fuOmX+MQWgJjrWZ2kXbtlQ==&#34;,&#xA;      &#34;IPiVFeI45MBrWEz4KZcdQQ==&#34;,&#xA;      &#34;ZuhhG1bpyIKZ8+BvJQvoUQ==&#34;,&#xA;      &#34;RxiYxX3H5lL8cc7k0ac/mQ==&#34;,&#xA;      &#34;4Ir8FDWM4WPrO3dybbfnYQ==&#34;&#xA;    ],&#xA;    &#34;2QUKRSh7NN4cTp6+OOEm8w==&#34;: [&#xA;      &#34;DcyOxGZU+Qt6lxShaMXeig==&#34;,&#xA;      &#34;2fxlvvJDIsNRRQuBzDD4oA==&#34;,&#xA;      &#34;+ihXD4KFgwxouHTRyQ5EbA==&#34;,&#xA;      &#34;1WaijHYxan9df8+fB0SQJQ==&#34;,&#xA;      &#34;vSLFgRYoehmDve19rxyjcw==&#34;,&#xA;      &#34;czyzjx8xL/qpVEGcPiV7Og==&#34;,&#xA;      &#34;SdlHZBjfHlAbNa/I1YXwQA==&#34;,&#xA;      &#34;/km0PGGx5jgJEo1YpWisAQ==&#34;,&#xA;      &#34;K3SBN066vVckR2wFFfybNw==&#34;,&#xA;      &#34;RNhf6Q4lLrEWcaxYFUvj7A==&#34;&#xA;    ],&#xA;    &#34;2gCbp4kt+cF44NF/LqukDg==&#34;: [&#xA;      &#34;S5Dzz9cigoJDCj8s5UcT0g==&#34;&#xA;    ],&#xA;    &#34;2tnKv76FL7fQoypGU9dvWQ==&#34;: [&#xA;      &#34;eiMh0pZiJlWSr3FHHfVKhg==&#34;,&#xA;      &#34;FroZeKbNhNx69+bj8o0OqQ==&#34;,&#xA;      &#34;vZIHu7rsNO8R8If5mjyTiw==&#34;,&#xA;      &#34;tbkEtEs3aa+p2/YQaD8BfQ==&#34;,&#xA;      &#34;dcH4AHY4X+K0bO3O9nqJrQ==&#34;,&#xA;      &#34;I3+uP7bb+nPtzRYHH2UUgw==&#34;,&#xA;      &#34;d+D4c9x4GMdq33+dJrszxQ==&#34;,&#xA;      &#34;IeTK1HBLKpS1+gfVSPrpvg==&#34;,&#xA;      &#34;ElE6r7xQZAfd5MScs95BXQ==&#34;,&#xA;      &#34;lJ8RTw7m+AgAnWW6upSntA==&#34;,&#xA;      &#34;lWdVDKK0NI1ECjrQyrQZhA==&#34;,&#xA;      &#34;guG+lyS5JQIDSZS6MEfIow==&#34;,&#xA;      &#34;/MgFHW097IAGIZkNc/Fltw==&#34;,&#xA;      &#34;RRtBD+EuTLmzasgAaBJyZw==&#34;,&#xA;      &#34;5kIWJ0hrLSTGTMvu/m2VBg==&#34;,&#xA;      &#34;sAlO/t+jkkm59mLcdOgB9w==&#34;,&#xA;      &#34;1w+glHHFE32ql3XJuIAYWQ==&#34;,&#xA;      &#34;4wegIDtvEZ75QrQWM65auQ==&#34;,&#xA;      &#34;MIaYLvbJRWXm7UR3+CJ1PA==&#34;,&#xA;      &#34;MMLwOzBcCET4jaa3dPuTwQ==&#34;,&#xA;      &#34;q5joCCZ2cOTa0rXBUtiSpQ==&#34;,&#xA;      &#34;QaKFgrY/cUPl6Ls/xAwlFQ==&#34;,&#xA;      &#34;5C8DQrs9fwpmV8rRYlvfCQ==&#34;,&#xA;      &#34;mmFI4mA7exd6BfbwTUwJfQ==&#34;,&#xA;      &#34;r4Fu2fNYrl5cfm4zX5YpZQ==&#34;,&#xA;      &#34;1CCABRgs/s9xxQcDgxw00A==&#34;,&#xA;      &#34;e/bnYsWq3UNe4TO8qzzb8A==&#34;,&#xA;      &#34;knUP7wXG3O435cJDvu9Thw==&#34;,&#xA;      &#34;rwC2lB0lflNzttbo5Agt3g==&#34;,&#xA;      &#34;gNGv6C2nj/tHk2ntVJUOWw==&#34;,&#xA;      &#34;4WgtH2AC4w3jDaPCHFqEaw==&#34;,&#xA;      &#34;RoQvxPrgcpXyTej834bT2Q==&#34;,&#xA;      &#34;oIBUxFCAPk4vRXBwpcmtFw==&#34;,&#xA;      &#34;cly/G/AvUZQM2J1YMymkpQ==&#34;,&#xA;      &#34;uO3OOEY6W3k9QH/tNVK0LQ==&#34;,&#xA;      &#34;4LZWGm07jnOHHBGX2FzAwg==&#34;,&#xA;      &#34;oGhsPyoyEtiEHT7/0qF+CQ==&#34;,&#xA;      &#34;CQPV/OxtJ+DwYc6C4gniNQ==&#34;,&#xA;      &#34;PqOWZHQu7W9hh0UlnMkHAQ==&#34;,&#xA;      &#34;Bu9dxnhmsLXDd3x0oRPHfA==&#34;,&#xA;      &#34;k9jtJIr2beiO7DTwypDNWw==&#34;,&#xA;      &#34;uPUnbuUJlh23l0km8iQ2tA==&#34;,&#xA;      &#34;Kr2KcyJfYQ8J1RDorzTofQ==&#34;,&#xA;      &#34;8XLKalkulxeAh8qfecmGlA==&#34;,&#xA;      &#34;hUC86VV8kD262xFcev0ZiA==&#34;,&#xA;      &#34;i2CsObRdsFCFCIvnyVzw5g==&#34;,&#xA;      &#34;uEn9qA67O/SoYHOtH/EL2w==&#34;&#xA;    ],&#xA;    &#34;35MvZs/A5NUjD+xZ1Vlnyw==&#34;: [&#xA;      &#34;j7yoSCks+i8LevHtgFwCwQ==&#34;&#xA;    ],&#xA;    &#34;38FdUixzs3eDg/NPZRiJIA==&#34;: [&#xA;      &#34;glhykijCt1euysZQdgNP+A==&#34;,&#xA;      &#34;WywM/OB6w5X8T3BuZ5B9Ow==&#34;,&#xA;      &#34;2BvFtePbGxsdaSFZvYiVWQ==&#34;,&#xA;      &#34;jLwTZ1iGPDmq13+JErDhGQ==&#34;,&#xA;      &#34;0+lfA724ypJdmbNfIKjiog==&#34;,&#xA;      &#34;q0+0u3TKsGvCBRBK4RgVAw==&#34;,&#xA;      &#34;x0MBdOYdUOYndbRBnoiEzw==&#34;,&#xA;      &#34;qIUMlexpn07c5Ly85v5AjQ==&#34;,&#xA;      &#34;kGY3woMWc1W36Wi2YstJ0Q==&#34;&#xA;    ],&#xA;    &#34;3nZGfOwzhExfw1oIgyJNUg==&#34;: [&#xA;      &#34;Qmv/HFfBCKuu6eMPjatnfw==&#34;,&#xA;      &#34;e0/Fzu8wfMZp9zX32i9rMQ==&#34;,&#xA;      &#34;7CfySs4FmTkWgJPjEar4eg==&#34;&#xA;    ],&#xA;    &#34;4DALE9qlRQsocTmGTN3jhg==&#34;: [&#xA;      &#34;+yuesL9NY5Qpvu7wv7kHHA==&#34;,&#xA;      &#34;UivJsSMDjJ5Fv8zzjiEyGg==&#34;,&#xA;      &#34;dzniYI3/1uomz0XJinM4FA==&#34;,&#xA;      &#34;LI6QdIyga6/I93JFZfZG6g==&#34;,&#xA;      &#34;p1r6Su9OK5/1nhaGskH+Pw==&#34;,&#xA;      &#34;OZs5l4RWFkhsw7PWdRXzZg==&#34;,&#xA;      &#34;RPAl+kgiy/xyZ/LXXbemyw==&#34;&#xA;    ],&#xA;    &#34;5+tHFkkNi+1rUDSrmgYdkw==&#34;: [&#xA;      &#34;rqKN8+22i5Wi/U+pG39tNg==&#34;,&#xA;      &#34;jVOV80BPiMF1EYk2uq9ohg==&#34;&#xA;    ],&#xA;    &#34;5JAFUJWmy04+T6x2oJw2jg==&#34;: [&#xA;      &#34;qFIYjZJeFnLAVC7lR0n6oQ==&#34;,&#xA;      &#34;DTApvRZh1HJD5XbbpU3ahw==&#34;,&#xA;      &#34;/Q70+j219nLwNP4Phg4sag==&#34;,&#xA;      &#34;8kndQj/aRn+NNJdGVP9v4g==&#34;,&#xA;      &#34;u0cs09LPRVEEfen4PHM6gA==&#34;,&#xA;      &#34;jiVVTQmOtKqVixv7agF/Hg==&#34;,&#xA;      &#34;y6oEGtDp1H5C2csZKAF6bQ==&#34;,&#xA;      &#34;RHShqbO2hqcBNPYbKDg/3A==&#34;,&#xA;      &#34;8ZCpE1M7eqNdy615aO2gLQ==&#34;,&#xA;      &#34;br+ShorUFea/O+vyZNDWZQ==&#34;,&#xA;      &#34;SGRK/IsCkjX097oRuDhiEQ==&#34;&#xA;    ],&#xA;    &#34;6HUC1/dPziZpbtWEymw0nQ==&#34;: [&#xA;      &#34;AzESlP5N9z0ume0UnpGELg==&#34;&#xA;    ],&#xA;    &#34;7mDaaxs3ev+uNEDYC97U3Q==&#34;: [&#xA;      &#34;1npmxgSnoYj2MyAhQMaE7g==&#34;&#xA;    ],&#xA;    &#34;7oPP0/pHHdyRIJK6pYsCbQ==&#34;: [&#xA;      &#34;H6ZekKRHFt5pG1Ua5PfWzw==&#34;,&#xA;      &#34;AwiZctxQMpOexVhl+RZ/eQ==&#34;,&#xA;      &#34;g7YHFtZ3mWRLeNfv7s6g4w==&#34;,&#xA;      &#34;r2VJfkGmsY6Tx/luoo7BHQ==&#34;,&#xA;      &#34;aWSD4ccAhJBO5Heyt5mTxQ==&#34;,&#xA;      &#34;J9gq9t3ASg6Sp5n2QRemEA==&#34;,&#xA;      &#34;zec/1Gm7Idd0fQLOCpU8jA==&#34;,&#xA;      &#34;XL+Z1BeLmN8Pi7RZ6D6z/w==&#34;,&#xA;      &#34;58xLQ2pjmhkIctIR/pZ5pw==&#34;,&#xA;      &#34;aKS5Pwr8YswsXS77DXcixA==&#34;,&#xA;      &#34;A/L5cxR0pUN6sSD1UL7wlw==&#34;,&#xA;      &#34;2Cyt+PunG/cjJJ5UZqrqrg==&#34;,&#xA;      &#34;siR3bdJZdvZI9snXBeScxA==&#34;,&#xA;      &#34;Kso3mzUHoYi+5+CqbHmG2w==&#34;,&#xA;      &#34;dOcg60kDi70nJl9Km2ugWQ==&#34;,&#xA;      &#34;Rd6dUUcujScJTEeiIRkyqw==&#34;,&#xA;      &#34;hLNqQASPtA3T5zDQurOMBA==&#34;,&#xA;      &#34;Y7j+Hhv6OMvu2cmEQkev4Q==&#34;,&#xA;      &#34;Rrms4yDDctk9MqbL4wHXYA==&#34;,&#xA;      &#34;eM2mlJEyKuGpc2sJMlq4xA==&#34;,&#xA;      &#34;OaLF1hM9BwMPMfYWn9kNEA==&#34;,&#xA;      &#34;Ds5dBDqvRggZONNskvuAwg==&#34;,&#xA;      &#34;mZC3gBcn6x1aC7q9hXUpKg==&#34;,&#xA;      &#34;y/vNaOETNDNWhjGaBLNhRA==&#34;,&#xA;      &#34;EFXoHkta9v8NXWXURLTCBw==&#34;,&#xA;      &#34;lCc1jyHfsFJK2HfULjN8pA==&#34;,&#xA;      &#34;FW+E40XkknH5Jv24oip5Ow==&#34;,&#xA;      &#34;GW37uYQxwwgJBIDtA/dT2g==&#34;,&#xA;      &#34;d9oy2JiAKtie2N1lu2J6ew==&#34;,&#xA;      &#34;m/cpX9gyFETv4B87S/qRxw==&#34;,&#xA;      &#34;V2/vsNJeH5BxrzuVis91/A==&#34;,&#xA;      &#34;VuDrFzex6yJBFISXUtfUGQ==&#34;,&#xA;      &#34;V8tjixCGBsaAWvQP5Hvn+A==&#34;,&#xA;      &#34;fuOmX+MQWgJjrWZ2kXbtlQ==&#34;,&#xA;      &#34;IPiVFeI45MBrWEz4KZcdQQ==&#34;,&#xA;      &#34;ZuhhG1bpyIKZ8+BvJQvoUQ==&#34;,&#xA;      &#34;RxiYxX3H5lL8cc7k0ac/mQ==&#34;,&#xA;      &#34;4Ir8FDWM4WPrO3dybbfnYQ==&#34;&#xA;    ],&#xA;    &#34;7qAMBOvJ2FYxpK9n05pI7Q==&#34;: [&#xA;      &#34;GMnASWjZHihDlhJdlv57Iw==&#34;,&#xA;      &#34;Xms/F5NRiyBcCNuPxw8aoA==&#34;,&#xA;      &#34;v9qMLnWqPbLz+WC1hPhb9g==&#34;,&#xA;      &#34;4os+HU28VQ7buZvoEKQ/kg==&#34;,&#xA;      &#34;QG/MLFKQxQOk84kYcs5X4A==&#34;,&#xA;      &#34;6QirCtH9GCLBepYrxwQRIg==&#34;,&#xA;      &#34;qfyF3TC4Vao8jmQ0UiB8kA==&#34;,&#xA;      &#34;dXN2fYt7gJPawfay7UcWxA==&#34;,&#xA;      &#34;dNLHuLPIX/j9HB0bv6uBww==&#34;,&#xA;      &#34;M29Ot9TqS/JJH7ICJCbCog==&#34;,&#xA;      &#34;1PA9NgR35/MRqgXqIHuktA==&#34;,&#xA;      &#34;KqyZJW2L6JQ2vf0yVMm6jg==&#34;,&#xA;      &#34;DNT7Ncyac0R7hltidKFOsA==&#34;,&#xA;      &#34;QpRZEOKvwJh9R+ZiKkkeqQ==&#34;&#xA;    ],&#xA;    &#34;7ra56f21gLrcSpBD8a9+NQ==&#34;: [&#xA;      &#34;TccjTp2Y8sTyWrjrm24IKA==&#34;,&#xA;      &#34;e0/Fzu8wfMZp9zX32i9rMQ==&#34;,&#xA;      &#34;7CfySs4FmTkWgJPjEar4eg==&#34;&#xA;    ],&#xA;    &#34;8/+OIixLXu+fX/6UoQwl/g==&#34;: [&#xA;      &#34;NHJdq5G883S5W8foR85U2A==&#34;,&#xA;      &#34;zYQmqjwBNORHvvIZjBy6jg==&#34;&#xA;    ],&#xA;    &#34;87VUAbsTn2cSvq70x9SIKw==&#34;: [&#xA;      &#34;px8rY0l1xijMh1q/wodpIQ==&#34;,&#xA;      &#34;/Zbh/oTVYOn4fLQqcvLFNw==&#34;,&#xA;      &#34;Xvp9bEwIvwUrD61DySkWgA==&#34;,&#xA;      &#34;4IJCXmCxOCf3t6/rsnea/A==&#34;,&#xA;      &#34;VvaHtDrsl/vKtefhsm7IUA==&#34;,&#xA;      &#34;AKiLQ/xfYs8rccBZaw62bQ==&#34;&#xA;    ],&#xA;    &#34;8OE8ax/E0UXByEoVMTfkbA==&#34;: [&#xA;      &#34;dDPwWBP+ziJTbpE/idIe+w==&#34;,&#xA;      &#34;4u3exWl+MPcCOYOgbQLM+A==&#34;,&#xA;      &#34;AGwkok3hPLMsQFqdif59+w==&#34;,&#xA;      &#34;/s8Q0HsneAZhk9Mgclm/OA==&#34;,&#xA;      &#34;eWiVyh/zommMEkP0Gx9Oow==&#34;,&#xA;      &#34;HwrQV7Eq97lmWod0H+Mywg==&#34;,&#xA;      &#34;L1NHjBKVcGa4hqzsfSCCQg==&#34;,&#xA;      &#34;/jvSCV2RwJ6c/Llx9z8uvA==&#34;,&#xA;      &#34;e/EuZlSZUQTHCSl8kHuFag==&#34;,&#xA;      &#34;/9MMSCBwxCiKjJobh+tDpw==&#34;,&#xA;      &#34;NF/ewEROjeKYjnb1lHH2iw==&#34;,&#xA;      &#34;2fFhV4f06vNDz4aMbkPOZA==&#34;,&#xA;      &#34;D4G1BWjcvupPxJokCdnHGA==&#34;,&#xA;      &#34;j/vFtwZCr4ow5q2VPKgR9g==&#34;,&#xA;      &#34;D7U85Qc3CYAscEzhSfT76A==&#34;,&#xA;      &#34;qh5gUahI9nge5StfpD2Efg==&#34;,&#xA;      &#34;GoTAJ6nke0a3zoxJ8lkaAg==&#34;,&#xA;      &#34;GWKQvGJTKzyU9GiQECoFhg==&#34;,&#xA;      &#34;XPfYdQhyLnN89+qpSA6LWg==&#34;,&#xA;      &#34;bjyLMZdYnkrpUxDySiQ34Q==&#34;,&#xA;      &#34;ffV5WUu4x4B5YykIdxqFhA==&#34;,&#xA;      &#34;Ep1W9j+OJARAHSERuL7J7Q==&#34;,&#xA;      &#34;Jrkns8qeStFRPhcitcuZ4w==&#34;,&#xA;      &#34;ixD2h349uZz3eCy55KxIlw==&#34;,&#xA;      &#34;y7I268PAr74OoToX85XE8w==&#34;,&#xA;      &#34;5amguv6OT1njd8r+RXMCQQ==&#34;,&#xA;      &#34;mINycH+x60PTfgPLuT1gJw==&#34;,&#xA;      &#34;+U7CyAHaY71mhNm2Xnq2uw==&#34;,&#xA;      &#34;IDIT7Gfu8E9A+NfUxEcAbQ==&#34;,&#xA;      &#34;2TDjlt2gAEWsLyBBPigFYw==&#34;,&#xA;      &#34;5BksN0izCeDRrtFMsNCyvg==&#34;,&#xA;      &#34;6hAQW3vY9ZA/8datv1rY4g==&#34;,&#xA;      &#34;0E1VjQWdmolR9lr9ElIZZQ==&#34;,&#xA;      &#34;M293c+QguJ/aaYP3cMwfyQ==&#34;,&#xA;      &#34;mZCCwO//htsOIXazj/SeOw==&#34;,&#xA;      &#34;41OUTxSbBLQGne4TzJuTQg==&#34;&#xA;    ],&#xA;    &#34;8dKij0lKhp8eGM5ynaMPfg==&#34;: [&#xA;      &#34;ySo9uDHfIeTwH0aLjgaN9g==&#34;,&#xA;      &#34;TwbA7fBttKRHAyCkVC4IDQ==&#34;,&#xA;      &#34;EUdYVqG8WVFrguzTJcoB9w==&#34;,&#xA;      &#34;mNXETDKAQUXFDVp1hgY7fQ==&#34;,&#xA;      &#34;v/Rdzpp9xZ3VFXBewTwV0A==&#34;,&#xA;      &#34;07xwapz2PAAGV6vMF10zQw==&#34;,&#xA;      &#34;t5kXgaRh+bn2vG112hLo2g==&#34;,&#xA;      &#34;qIUMlexpn07c5Ly85v5AjQ==&#34;,&#xA;      &#34;kGY3woMWc1W36Wi2YstJ0Q==&#34;&#xA;    ],&#xA;    &#34;8n6bVUPPsV3vtnz+vLHqKQ==&#34;: [&#xA;      &#34;PAegHDN7lb4f5q+9sjv8sQ==&#34;,&#xA;      &#34;WHfk9C+FqONS5L1MuNtP+g==&#34;&#xA;    ],&#xA;    &#34;8uME+PFu6p/OAD7q+ZTVLw==&#34;: [&#xA;      &#34;ChVC4WOnGJkEsPC5QHmS4Q==&#34;,&#xA;      &#34;A2s8gCjK3uaWI7+q7M5Aog==&#34;&#xA;    ],&#xA;    &#34;A5zg77FwqyQ7YbgSi5bkFw==&#34;: [&#xA;      &#34;Bh96oSV9q0619slTJCaM0Q==&#34;,&#xA;      &#34;J7eLc/Mh7BobYrDH+tpguA==&#34;&#xA;    ],&#xA;    &#34;AUjudWCWcMUZtLYqynIMkg==&#34;: [&#xA;      &#34;iSzOvPxPGZr2PfJTBTQBCQ==&#34;&#xA;    ],&#xA;    &#34;At9otkYcx2c7gDG/+qxMog==&#34;: [&#xA;      &#34;yTSOiGJiuQRZ1n0kXjMC8g==&#34;,&#xA;      &#34;ExqOQ5ldBNUvCH4EdaOK5w==&#34;&#xA;    ],&#xA;    &#34;BUmLEOIviku9guiDM/J5qA==&#34;: [&#xA;      &#34;l1pK1ezh6e0g8I+Dp2iK7w==&#34;,&#xA;      &#34;sqtLRwfRzV6y9srK/2QK2Q==&#34;,&#xA;      &#34;IFUwSX5dX69QHRHfvOeQDg==&#34;,&#xA;      &#34;X7DmUVoCri5i6vdYVBBgXg==&#34;,&#xA;      &#34;l6IrI73Pg+lrisEtcgX+0Q==&#34;,&#xA;      &#34;mllkaOQAaJYNZpdIF7Bkbw==&#34;,&#xA;      &#34;FQwXyPZ+oHyxQZ9RBQXbpw==&#34;,&#xA;      &#34;Cpn7PI6CgTg1FJ1Ijp4TIQ==&#34;,&#xA;      &#34;vMgggE6Cjv/N2Jk4Dk6FYw==&#34;,&#xA;      &#34;6rEIsdyQtCC456AuGwgsDQ==&#34;,&#xA;      &#34;+TrS27bZKgEeir9pISurnQ==&#34;,&#xA;      &#34;3UNcgW64Eji4iyY2ZDB1cg==&#34;,&#xA;      &#34;ctALzLE36TiW3KdxIlF4Mw==&#34;,&#xA;      &#34;8MfvwX+dRI6Qt2H+x71rZg==&#34;,&#xA;      &#34;d0nPfXoEZybRuV9TMDY3YQ==&#34;,&#xA;      &#34;xC8Y7thfNSAfn5daCQFvgQ==&#34;,&#xA;      &#34;X4Ym25zfqcH7/samBN+yPw==&#34;,&#xA;      &#34;zqGJegkbTlVqcHBa6HtRTQ==&#34;,&#xA;      &#34;/rrV/dLSeVDaHUnAvPeh7A==&#34;,&#xA;      &#34;6+rn6nrQrafYloJtAeJ2Bg==&#34;,&#xA;      &#34;smB1yCGhBb8gDhPAER7odg==&#34;,&#xA;      &#34;S0PFhlHzk3DOoPuq+7jmPA==&#34;,&#xA;      &#34;H1wshPoazj8pmzsnWAztZA==&#34;,&#xA;      &#34;Pza9Y2xtH9MChVMkZwgw2A==&#34;,&#xA;      &#34;vnI8VBZMnSK/Spr6qFIUOA==&#34;,&#xA;      &#34;kDNo+1U3zj32TNGC/5DIKw==&#34;&#xA;    ],&#xA;    &#34;Cn4UOizx3r/8sEEZ0cgGfw==&#34;: [&#xA;      &#34;cXB5uJOI3UJ7dOyNiQwFDg==&#34;,&#xA;      &#34;XPUXyp+BOEJyEGOgXafi8Q==&#34;&#xA;    ],&#xA;    &#34;CpfomSYboaXPZ9yn9NgGgw==&#34;: [&#xA;      &#34;IGF/2G1+7Y+pT7nmmFHvPw==&#34;,&#xA;      &#34;e+FXR06J5tPREKXnCKeZWg==&#34;,&#xA;      &#34;ajT6YifLzju5PlaUiX+EvA==&#34;&#xA;    ],&#xA;    &#34;DVWG3mWD7odZzCgFCUPZPw==&#34;: [&#xA;      &#34;j7yoSCks+i8LevHtgFwCwQ==&#34;&#xA;    ],&#xA;    &#34;DXPX19bdN5nJbVwnxKFlOA==&#34;: [&#xA;      &#34;JknhMYFxtGMAisBMILMboQ==&#34;&#xA;    ],&#xA;    &#34;EhaFwS5l8+kj0ips0KX28g==&#34;: [&#xA;      &#34;j2qyk9XQmGp7ssMhZKM8jg==&#34;,&#xA;      &#34;CQNzMQJa1wEomWRr1m5WUQ==&#34;,&#xA;      &#34;/wEypZTr5run3SLjfJxcSA==&#34;,&#xA;      &#34;ztB6Kn+K/mTyhZBUwqsoDw==&#34;,&#xA;      &#34;XkiVaSOj/tcz5wNKnglN4w==&#34;,&#xA;      &#34;mXoGTWRL/KLyEYWh5uyvXQ==&#34;,&#xA;      &#34;RATpPhLUqjEbe+XxyYxOOw==&#34;,&#xA;      &#34;08ogBuWXS+d72R0TAjgJaQ==&#34;,&#xA;      &#34;vTajNh0ysqaO8NuTMU//uw==&#34;,&#xA;      &#34;JtGggrfMckWn0xvfWBMJJQ==&#34;,&#xA;      &#34;1WQ/LJu/kefEuHRv58l0Lw==&#34;,&#xA;      &#34;6LOgJE44rXWziB7/OMO/ig==&#34;,&#xA;      &#34;Ob+LJ5zYHnbjt14Yf8W7UA==&#34;,&#xA;      &#34;jVeIQzIm92EdkbCIlGT1qA==&#34;,&#xA;      &#34;GnBCRP9H+R6do428z3nOkQ==&#34;,&#xA;      &#34;2RZ3u6UmceVG9iB/xb73SA==&#34;,&#xA;      &#34;0YVxD0vSH+0MhijemP/Jmg==&#34;,&#xA;      &#34;6asSIEJz7ggo9QEXpbSOYg==&#34;,&#xA;      &#34;HSaKorahiaNwGqqE2DJSaw==&#34;,&#xA;      &#34;JmKf//IQj2eMVJFTB1Feyw==&#34;,&#xA;      &#34;oVgcRSL89qnSRkMXpV8N8A==&#34;,&#xA;      &#34;3WRC4Vl08/leTJ1MFHuCEg==&#34;,&#xA;      &#34;+PjI2yN4wCMPyf1oygeT5Q==&#34;,&#xA;      &#34;rJljaCTiTdw1uI1lvfy+hw==&#34;,&#xA;      &#34;Y6TEBwH0+CoZ50j5sQV23w==&#34;,&#xA;      &#34;+uMSPU5jbqI0+jsP/eX6PA==&#34;,&#xA;      &#34;Q6H4f5u2pbj98wlSQQLoGg==&#34;,&#xA;      &#34;aQGx6Am8fU9TZmcyiMNL4A==&#34;,&#xA;      &#34;HlOu0EmTxHkjzmJeJEuJmw==&#34;,&#xA;      &#34;5D5WFK01Su4Lrj4hhwDYGQ==&#34;,&#xA;      &#34;UBzPfwycyyJOBETwdSTG/w==&#34;,&#xA;      &#34;LkJjju2s50oKpBRyBT8s0A==&#34;,&#xA;      &#34;r410Z5X0yojDsVg9YVcNqQ==&#34;,&#xA;      &#34;rO5a9fYyaqaIZ4bH0M8fdA==&#34;,&#xA;      &#34;0v5F4x1W0RxkklLvRs6NKQ==&#34;,&#xA;      &#34;nNAYHDwpTrgu1xKD+v9Oww==&#34;,&#xA;      &#34;s6kt2DqKLHgzYSGciPtGtQ==&#34;,&#xA;      &#34;KsboTEAsiwsdLEKIDivkyA==&#34;,&#xA;      &#34;2luu38jiVQvy6qOXHFgpAg==&#34;,&#xA;      &#34;QX9gQ7esz1e73iQHmwojXA==&#34;,&#xA;      &#34;Q0D37bmhhLGtYILIAMgFXg==&#34;,&#xA;      &#34;XQDeROSRzMSiFTbbLCST/A==&#34;,&#xA;      &#34;cMY+6QfPqyOZE380Mf5rIQ==&#34;,&#xA;      &#34;w8af/LTYrBLWhYkZBSi2Lg==&#34;,&#xA;      &#34;cjoCrbQlAeGxtTPUlcMPuA==&#34;,&#xA;      &#34;GXMpRf2go/wGEbwpp9BPPQ==&#34;,&#xA;      &#34;AwUdH/KSEhHnx1nx0tagUQ==&#34;,&#xA;      &#34;JD0llI0bGUOG/VBz+9LeVQ==&#34;,&#xA;      &#34;X10PEbhI2yv6KYFUPacecg==&#34;,&#xA;      &#34;BS5Qx6nN3HmM64VVoKmayw==&#34;,&#xA;      &#34;Ah03jmj/7fQOqUbg05PtZg==&#34;,&#xA;      &#34;DNd0sdbW83acQbIl3FDaPw==&#34;,&#xA;      &#34;s2uSNGuV+OyVW2eHDGWWKw==&#34;,&#xA;      &#34;2UHqEqfMIIn53NkDlDEppQ==&#34;,&#xA;      &#34;zAQhwfD+1kpXY0CwZC6HxA==&#34;,&#xA;      &#34;g6spFzT6DoopzuQCE0pjRg==&#34;,&#xA;      &#34;3Lvdmj//2sze9S8I3n8yrw==&#34;,&#xA;      &#34;cxMZ2TEnkk6RdtuU9fDThg==&#34;,&#xA;      &#34;o8O4Ttqnv0lQfm1yyfyVsw==&#34;,&#xA;      &#34;6MW1lRUdNNc4s+6uD2JNvw==&#34;,&#xA;      &#34;qWK7H7gz7e8gS19GJSeIIg==&#34;,&#xA;      &#34;zx97OaxgXH8j+mFWesQySQ==&#34;,&#xA;      &#34;qYORp6v9x0Jy6S8OKerZvw==&#34;,&#xA;      &#34;QgRg8usqYLpC2SzTmhUKsQ==&#34;,&#xA;      &#34;lz6O0nYiDpis8SScmTUuSg==&#34;,&#xA;      &#34;Rd2hVVbUws+mcvoC7DaoiQ==&#34;,&#xA;      &#34;qEhRdzGH44SGjJIcqcIv/g==&#34;,&#xA;      &#34;YUwZZ9Cg1FloxBZV60vOCg==&#34;,&#xA;      &#34;eekbTUpqIafepE8Hfmhn6g==&#34;,&#xA;      &#34;TIcWaTRsDD52irGN4xUQyA==&#34;,&#xA;      &#34;KB8w2g8b8sP5A8+iqhqw8A==&#34;,&#xA;      &#34;kaUbMItvWrS1leJMEsAk9A==&#34;,&#xA;      &#34;7AoZZiCMmvqX9d9WD62FnQ==&#34;,&#xA;      &#34;OXr+UvfSDAQbLGP4xOBSMw==&#34;,&#xA;      &#34;tLSR0X6hQ7hvyPbBXZslBQ==&#34;,&#xA;      &#34;/YcdipQjiqJUDpddwhDiIw==&#34;,&#xA;      &#34;0bK7Vo3x9SXQYvDvMmgzXA==&#34;,&#xA;      &#34;rR226S9SV4WbmIVotM0CsQ==&#34;,&#xA;      &#34;QbgvVzhz2dr5BDvAUM6wFQ==&#34;,&#xA;      &#34;oyvtOIVUDqm1ruQx8vhRhA==&#34;,&#xA;      &#34;6dwQWrojfQ/1hgTT2PQckg==&#34;,&#xA;      &#34;uDfc8ZaPfrhTGcFwVaIvAA==&#34;,&#xA;      &#34;BfDjqoaYrd0NKCGGxtokTg==&#34;,&#xA;      &#34;6o8ui0RxMttDzkyqTDO5tg==&#34;,&#xA;      &#34;SvhQ7tNvl6ANrVnaJ4cBNw==&#34;,&#xA;      &#34;I3vwwgMxzxWo15otCOgvAw==&#34;,&#xA;      &#34;6LazNwUBgu5kQGKPCQnaOw==&#34;,&#xA;      &#34;zDmU3WG0c3AQYw7NFebUCQ==&#34;,&#xA;      &#34;8efBqSZ3OYqd+nT8a21FNA==&#34;,&#xA;      &#34;bh7RRRlNP555+LOFASdB0w==&#34;,&#xA;      &#34;2sm08sXcjWtT2Gtu3CdSug==&#34;,&#xA;      &#34;93O9BjbBwz1jYmTNCzgkUw==&#34;,&#xA;      &#34;b2xf65/2S45gOxG8Grxy0g==&#34;,&#xA;      &#34;BTToHfvg0weSXCH9D0acFA==&#34;,&#xA;      &#34;qug1advw8m4TjVAUPEUPiA==&#34;,&#xA;      &#34;00cDk2w3qfvdzMbO27c/+w==&#34;,&#xA;      &#34;XuMP4XKeqFlYH9jgvFKXXw==&#34;,&#xA;      &#34;W0TAw6aTfwXOMlJwloDkZA==&#34;,&#xA;      &#34;2I/0B+uXhxpPJWXGwNGlLw==&#34;,&#xA;      &#34;HHBOKYlzeD2Busv7btyBAA==&#34;,&#xA;      &#34;lHLNxD93t7uUJfmDhNwvCQ==&#34;,&#xA;      &#34;dO/rj/SVo/ZlfJAB2ajOEQ==&#34;,&#xA;      &#34;SGI/AkdUGrhS5bQBrDpzJg==&#34;,&#xA;      &#34;RCLRHWzoL8kWcamW6v1E6w==&#34;,&#xA;      &#34;7sGexlbSpX41SOBbWHg8BQ==&#34;,&#xA;      &#34;m9ROycwLgAur/M8HFSigEw==&#34;,&#xA;      &#34;+hBhqk1qKnkU+nqn6a96qg==&#34;,&#xA;      &#34;e7h3lwyDkLbzwbeza9/TWw==&#34;,&#xA;      &#34;w1094TrprBpG+5TZJus6FA==&#34;,&#xA;      &#34;ylg3k+AtgUcIl3hJiXNMlw==&#34;,&#xA;      &#34;MLyBE3p9/9+LMOMl2JBi6w==&#34;,&#xA;      &#34;Qe1reyLPtQVZ5wKqKa9jQA==&#34;,&#xA;      &#34;Y/6FiFNJ+h2jXNTlPOzrnQ==&#34;,&#xA;      &#34;XL1Nv8y45q8aiA92A99YyA==&#34;,&#xA;      &#34;GfPY5zBbHJQI4ZGaDcJj2A==&#34;,&#xA;      &#34;u1caIbS4Tk6y8c7sz8Hvhw==&#34;,&#xA;      &#34;KYv6PwzjV6/5I33cZ9LUmQ==&#34;,&#xA;      &#34;kTyfGInwWoCVv7gGPYCF5g==&#34;,&#xA;      &#34;Q2616MMrHflQbREkbaxMFg==&#34;,&#xA;      &#34;hxluEp8Si16NQcfaJDWcLg==&#34;,&#xA;      &#34;8563iLEht/ghMGItALTFUw==&#34;,&#xA;      &#34;19Kvl4LS7MCiBo2cRD5fxQ==&#34;,&#xA;      &#34;bcO+GuPgyR+iGLy6+mF2Cg==&#34;,&#xA;      &#34;NeZAaBfGrzLvaMKrJL7WlA==&#34;,&#xA;      &#34;T5Nghm4crNWWnUrYvZZItg==&#34;,&#xA;      &#34;gGrGej/Pj6/poAgebFb+dg==&#34;,&#xA;      &#34;bACUKZThWu3kcO82NfO4eg==&#34;,&#xA;      &#34;h+nOQU6khNxAH7kkGqVqkQ==&#34;,&#xA;      &#34;AIlN8RmMOvhBveVuVAyHQQ==&#34;&#xA;    ],&#xA;    &#34;Esfj4A6yCPG0aR5IhgHmUg==&#34;: [&#xA;      &#34;cXB5uJOI3UJ7dOyNiQwFDg==&#34;,&#xA;      &#34;XPUXyp+BOEJyEGOgXafi8Q==&#34;&#xA;    ],&#xA;    &#34;F5S3/GN2uyb/+Q/5rj2gBA==&#34;: [&#xA;      &#34;gBKPfFUBWkIoh/DpIktgJA==&#34;,&#xA;      &#34;CO6FDlFyRSUjPhv7/gdAAA==&#34;,&#xA;      &#34;novhorrUhD5n0pl3qmImIw==&#34;,&#xA;      &#34;JLoYxSe6sUCueA3LPfbTLA==&#34;,&#xA;      &#34;NxJdA8sdmOpi2KE8EaPazA==&#34;,&#xA;      &#34;+CgZKiM2jpLyW2jlIXneLw==&#34;&#xA;    ],&#xA;    &#34;F6sWmqQXkobYs1E0otG8/A==&#34;: [&#xA;      &#34;UG+yX6nADJgJWegetH+HQg==&#34;,&#xA;      &#34;xRDJz3P8IApYf+UqTsFimg==&#34;,&#xA;      &#34;LUQxjpYcQwxSDC7CX78VUw==&#34;,&#xA;      &#34;bf41zTvm6HAv6xdiXpwGWQ==&#34;,&#xA;      &#34;EOFhzMVjLzNyQsRKP/y6ag==&#34;,&#xA;      &#34;SH2AP7i0ZzGmFbD1kuJsew==&#34;,&#xA;      &#34;G/nM9FqgWuICAFy4kMmJlA==&#34;,&#xA;      &#34;bpwdCug2xQZhmaazCqwIew==&#34;,&#xA;      &#34;j71n+HvL+1UIm3Tw+EUHpw==&#34;,&#xA;      &#34;PvgbBaq86gnOp8hffKEHhQ==&#34;,&#xA;      &#34;yNrm+PctJj5AEVwT8bDpBg==&#34;,&#xA;      &#34;3KVKKCxdWl+iCbo/o6cUCw==&#34;,&#xA;      &#34;Ur6VVwVyUIHSLLbySiZhfA==&#34;,&#xA;      &#34;oED190j69/of7CStGTEa5A==&#34;,&#xA;      &#34;YgehfkOilPM31dosmRXxDA==&#34;,&#xA;      &#34;OwBRDeukhCJw3hE9ZsCdCg==&#34;,&#xA;      &#34;lNSOU9e0rQLWWUuG6KmS+w==&#34;,&#xA;      &#34;Vm1exr1mz0tcpwIoZQ3ySQ==&#34;,&#xA;      &#34;BtU7U8JaAB8UA19RIrHuHQ==&#34;,&#xA;      &#34;wM3p6vKgVqUkJtSPSQjDlw==&#34;,&#xA;      &#34;uLJc9xWoMs4KcjASTFLV/A==&#34;,&#xA;      &#34;aK9Mq6KdK8L3Pl0r1rTwYA==&#34;,&#xA;      &#34;dtQx2uUyC6Kj72i0o1bELQ==&#34;,&#xA;      &#34;kxWAVe7EWU20jParQphcRA==&#34;,&#xA;      &#34;3R40oInfBrzPyywU8VZGOA==&#34;,&#xA;      &#34;JAlZO0sgdy1FBW5F7Zj+Pg==&#34;,&#xA;      &#34;ZCLP8N4soyt53A9I5VdxcA==&#34;&#xA;    ],&#xA;    &#34;FDdpwYO23GZzR/6AZCdQZA==&#34;: [&#xA;      &#34;HveCNT+j0lknlUOFTaqgtg==&#34;&#xA;    ],&#xA;    &#34;FEW4+DY0GhovHIdRCyqYhg==&#34;: [&#xA;      &#34;QZ8ts+eZBnwTfp8wZbfpwg==&#34;,&#xA;      &#34;vFpvBSl3ZcIap1nZTTjWsg==&#34;,&#xA;      &#34;AvmIxq5EDqjW4mtnnlw9lA==&#34;,&#xA;      &#34;G1BYG6YufGP4p88wdWeAgg==&#34;,&#xA;      &#34;6pxKX6FKH4aTek+6noKFjQ==&#34;,&#xA;      &#34;Go9bB5Mq4W4FHPvmZKBhCg==&#34;,&#xA;      &#34;RARCK1i4HMZsevzlwavFtw==&#34;,&#xA;      &#34;LXM9CbBE9eK3grkTD73h+g==&#34;,&#xA;      &#34;y/3qWQj3xOUQpm2CUr+ftg==&#34;,&#xA;      &#34;4Ocx5vfc88FjutK1oBwpCQ==&#34;,&#xA;      &#34;qN6ac9Xwm6AOaO1fAB7fOQ==&#34;,&#xA;      &#34;5ZeuGlt87r+CNRRQDhU5uw==&#34;,&#xA;      &#34;W+GZex0uR6OUn0BnVKDRXQ==&#34;,&#xA;      &#34;f6oGdnhZomBa/bs3snB3kA==&#34;,&#xA;      &#34;EJqYggmJ1CPHdE/+zAY7WA==&#34;&#xA;    ],&#xA;    &#34;Gfvf4LQKHStcGqbzaAe/lA==&#34;: [&#xA;      &#34;1cpz1Hzz2hsR9fx5YrxP3g==&#34;&#xA;    ],&#xA;    &#34;GrPCC9ybwOy98qwLdeCX6A==&#34;: [&#xA;      &#34;YQGeiQ1baJrwVuNrCjd79A==&#34;,&#xA;      &#34;nicOe0HMeoCrfaBInGMpgA==&#34;,&#xA;      &#34;mwfwMX3+sIJWibPk7jkY/Q==&#34;,&#xA;      &#34;N5EbMRV7FNySo/Sn3CmU+w==&#34;,&#xA;      &#34;SC1Dy3taETcbAxJ5m5vXqQ==&#34;,&#xA;      &#34;zL8cYwtASK3csnxhG4umrQ==&#34;,&#xA;      &#34;oGYbR6FNz1KIQ8VJiypCZg==&#34;,&#xA;      &#34;txqyo4HZxt82KZ1LFkOAcA==&#34;,&#xA;      &#34;cQ4uQyL9nbrYK9Ka1PjEaQ==&#34;,&#xA;      &#34;VgtQ3XmdoIWt3qbuW7WZzQ==&#34;,&#xA;      &#34;cI+dz7I9kKgyQoTuHBA+4Q==&#34;,&#xA;      &#34;xvCKE5h7HgdGkBMwA/kPeg==&#34;,&#xA;      &#34;SIuaHC7QSLhT9Coo7Xm2hA==&#34;,&#xA;      &#34;J/M93jueASHywmph2g+HMg==&#34;,&#xA;      &#34;9DXLRStQLAgyQnNJqYTJEA==&#34;,&#xA;      &#34;4kuxrTpUDtZ3uFOEEztq9g==&#34;,&#xA;      &#34;NfiEOtFyxMslIq3QwoTtjQ==&#34;,&#xA;      &#34;mXtaaJBTQTZ/zl5a00GqaA==&#34;,&#xA;      &#34;EOZFP6ki76xUja7Br+mpEw==&#34;,&#xA;      &#34;q59Dz6hmc7o1qITDwl3CCw==&#34;,&#xA;      &#34;cQHSxL+ZfKCYmJnTVIzcRw==&#34;,&#xA;      &#34;OXJFeTFLsi8lSYgzBz58BA==&#34;,&#xA;      &#34;uMTgzWnvZecD0kujuKPIMw==&#34;,&#xA;      &#34;jJU1rFjbneT5RWmoUr6uxw==&#34;,&#xA;      &#34;NrATYvL+2i2gY4ol+szT+g==&#34;,&#xA;      &#34;2d2KejA0Nrz6tVNnB1dB5A==&#34;,&#xA;      &#34;xWYQ4aF7Ip3LaKJQzDwx1A==&#34;,&#xA;      &#34;qpxeH+3MOciW1z6wxEwYBw==&#34;,&#xA;      &#34;N6zpVUumTTQTvmCVOXvHPQ==&#34;,&#xA;      &#34;Tp2zZ0uvWY7vBbgviQPk7w==&#34;,&#xA;      &#34;Y1YZsYV7ls1vsluhREpXlw==&#34;&#xA;    ],&#xA;    &#34;HF0BuzgGNjLOUKqVyjw0oA==&#34;: [&#xA;      &#34;6G2lzRj8p7v2QJ3GPO3i9Q==&#34;,&#xA;      &#34;JpVSLeyNGU9aXWuvL1lvmw==&#34;,&#xA;      &#34;sROfYAX8Ekl+9at4JgS5Lg==&#34;,&#xA;      &#34;bCZjE4S4e+JRkpJeCZ485w==&#34;,&#xA;      &#34;bbylqjYpcbE9/Bm4AdduVQ==&#34;,&#xA;      &#34;qn72KaShSoWOaJmw6qKS3Q==&#34;&#xA;    ],&#xA;    &#34;HKlRsQZtXaa3HoNDv500tg==&#34;: [&#xA;      &#34;2w9brA/+oZ5OEdpav+Dkzw==&#34;,&#xA;      &#34;+R/6bpHEFR4SpBeguCorTQ==&#34;&#xA;    ],&#xA;    &#34;HQLCuUiHA+476ax5LmI78Q==&#34;: [&#xA;      &#34;PX5l1wv6H6/jl5nGaxFp+w==&#34;,&#xA;      &#34;haEbUAG+u1TE1V7073rUjA==&#34;,&#xA;      &#34;4ardx/cPJA31l/GjZ5ssvw==&#34;,&#xA;      &#34;mCbTv5P9L2CaDsmaEWknNw==&#34;,&#xA;      &#34;ALEb7ClqbpU4flidf9/9Vg==&#34;,&#xA;      &#34;Ly8YGlWm8+S4CYtF8Y/Htw==&#34;&#xA;    ],&#xA;    &#34;HyWYXl8ZaOY6wtr4mKF7qA==&#34;: [&#xA;      &#34;fSeU4QTAs+fY+ihLpgdM9A==&#34;,&#xA;      &#34;XW4X9/W6MfETfE/VICA4Jw==&#34;,&#xA;      &#34;n39YhRffL6tFFAy/S18A8Q==&#34;,&#xA;      &#34;R1x4adkbkgVhxc9hzgUZcA==&#34;&#xA;    ],&#xA;    &#34;HyjfzS7o9NZj6mKbOA36wA==&#34;: [&#xA;      &#34;+JlLlfOobk7OBriIdQRELQ==&#34;,&#xA;      &#34;FAhn0w8CyRA5pQLzx0KOLg==&#34;,&#xA;      &#34;ZRSF+MayCxLJlIAPWIqUVA==&#34;,&#xA;      &#34;RbYTnX5KpMQtsQJE/xjcFA==&#34;,&#xA;      &#34;5snUlx7ztOquC9N7WioMbg==&#34;,&#xA;      &#34;MqEiWiJF+vNoM9tbeG6KSw==&#34;&#xA;    ],&#xA;    &#34;I4xeNeKgfXcsAYIlRhjPiQ==&#34;: [&#xA;      &#34;gET5R3f4XDkfL+cBxb3pJQ==&#34;,&#xA;      &#34;zY/8tgCkQEbX9yVIGbkTFQ==&#34;,&#xA;      &#34;9PkDHwckTpMGddf70S7UIA==&#34;,&#xA;      &#34;DSX8U+5pHixx0pf+XijnCw==&#34;,&#xA;      &#34;MS/0MdicPKEzcrADakYBYA==&#34;,&#xA;      &#34;MrkZWekwMOpCZnSllV83tw==&#34;,&#xA;      &#34;doax1FtBT8uwFLYDyWb1Bg==&#34;&#xA;    ],&#xA;    &#34;IG/inuDbgBm/XuY2u/Aumw==&#34;: [&#xA;      &#34;mEw7dcF5jpuxJvu2G3JEew==&#34;,&#xA;      &#34;RATpPhLUqjEbe+XxyYxOOw==&#34;,&#xA;      &#34;08ogBuWXS+d72R0TAjgJaQ==&#34;,&#xA;      &#34;vTajNh0ysqaO8NuTMU//uw==&#34;,&#xA;      &#34;JtGggrfMckWn0xvfWBMJJQ==&#34;,&#xA;      &#34;1WQ/LJu/kefEuHRv58l0Lw==&#34;,&#xA;      &#34;6LOgJE44rXWziB7/OMO/ig==&#34;,&#xA;      &#34;Ob+LJ5zYHnbjt14Yf8W7UA==&#34;,&#xA;      &#34;jVeIQzIm92EdkbCIlGT1qA==&#34;,&#xA;      &#34;GnBCRP9H+R6do428z3nOkQ==&#34;,&#xA;      &#34;2RZ3u6UmceVG9iB/xb73SA==&#34;,&#xA;      &#34;0YVxD0vSH+0MhijemP/Jmg==&#34;,&#xA;      &#34;6asSIEJz7ggo9QEXpbSOYg==&#34;,&#xA;      &#34;HSaKorahiaNwGqqE2DJSaw==&#34;,&#xA;      &#34;JmKf//IQj2eMVJFTB1Feyw==&#34;,&#xA;      &#34;oVgcRSL89qnSRkMXpV8N8A==&#34;,&#xA;      &#34;3WRC4Vl08/leTJ1MFHuCEg==&#34;,&#xA;      &#34;+PjI2yN4wCMPyf1oygeT5Q==&#34;,&#xA;      &#34;rJljaCTiTdw1uI1lvfy+hw==&#34;,&#xA;      &#34;Y6TEBwH0+CoZ50j5sQV23w==&#34;,&#xA;      &#34;+uMSPU5jbqI0+jsP/eX6PA==&#34;,&#xA;      &#34;Q6H4f5u2pbj98wlSQQLoGg==&#34;,&#xA;      &#34;aQGx6Am8fU9TZmcyiMNL4A==&#34;,&#xA;      &#34;HlOu0EmTxHkjzmJeJEuJmw==&#34;,&#xA;      &#34;5D5WFK01Su4Lrj4hhwDYGQ==&#34;,&#xA;      &#34;UBzPfwycyyJOBETwdSTG/w==&#34;,&#xA;      &#34;LkJjju2s50oKpBRyBT8s0A==&#34;,&#xA;      &#34;r410Z5X0yojDsVg9YVcNqQ==&#34;,&#xA;      &#34;rO5a9fYyaqaIZ4bH0M8fdA==&#34;,&#xA;      &#34;0v5F4x1W0RxkklLvRs6NKQ==&#34;,&#xA;      &#34;nNAYHDwpTrgu1xKD+v9Oww==&#34;,&#xA;      &#34;s6kt2DqKLHgzYSGciPtGtQ==&#34;,&#xA;      &#34;KsboTEAsiwsdLEKIDivkyA==&#34;,&#xA;      &#34;2luu38jiVQvy6qOXHFgpAg==&#34;,&#xA;      &#34;QX9gQ7esz1e73iQHmwojXA==&#34;,&#xA;      &#34;Q0D37bmhhLGtYILIAMgFXg==&#34;,&#xA;      &#34;XQDeROSRzMSiFTbbLCST/A==&#34;,&#xA;      &#34;cMY+6QfPqyOZE380Mf5rIQ==&#34;,&#xA;      &#34;w8af/LTYrBLWhYkZBSi2Lg==&#34;,&#xA;      &#34;cjoCrbQlAeGxtTPUlcMPuA==&#34;,&#xA;      &#34;GXMpRf2go/wGEbwpp9BPPQ==&#34;,&#xA;      &#34;AwUdH/KSEhHnx1nx0tagUQ==&#34;,&#xA;      &#34;JD0llI0bGUOG/VBz+9LeVQ==&#34;,&#xA;      &#34;X10PEbhI2yv6KYFUPacecg==&#34;,&#xA;      &#34;BS5Qx6nN3HmM64VVoKmayw==&#34;,&#xA;      &#34;Ah03jmj/7fQOqUbg05PtZg==&#34;,&#xA;      &#34;DNd0sdbW83acQbIl3FDaPw==&#34;,&#xA;      &#34;s2uSNGuV+OyVW2eHDGWWKw==&#34;,&#xA;      &#34;2UHqEqfMIIn53NkDlDEppQ==&#34;,&#xA;      &#34;zAQhwfD+1kpXY0CwZC6HxA==&#34;,&#xA;      &#34;g6spFzT6DoopzuQCE0pjRg==&#34;,&#xA;      &#34;3Lvdmj//2sze9S8I3n8yrw==&#34;,&#xA;      &#34;cxMZ2TEnkk6RdtuU9fDThg==&#34;,&#xA;      &#34;o8O4Ttqnv0lQfm1yyfyVsw==&#34;,&#xA;      &#34;6MW1lRUdNNc4s+6uD2JNvw==&#34;,&#xA;      &#34;qWK7H7gz7e8gS19GJSeIIg==&#34;,&#xA;      &#34;zx97OaxgXH8j+mFWesQySQ==&#34;,&#xA;      &#34;qYORp6v9x0Jy6S8OKerZvw==&#34;,&#xA;      &#34;QgRg8usqYLpC2SzTmhUKsQ==&#34;,&#xA;      &#34;lz6O0nYiDpis8SScmTUuSg==&#34;,&#xA;      &#34;Rd2hVVbUws+mcvoC7DaoiQ==&#34;,&#xA;      &#34;qEhRdzGH44SGjJIcqcIv/g==&#34;,&#xA;      &#34;YUwZZ9Cg1FloxBZV60vOCg==&#34;,&#xA;      &#34;eekbTUpqIafepE8Hfmhn6g==&#34;,&#xA;      &#34;TIcWaTRsDD52irGN4xUQyA==&#34;,&#xA;      &#34;KB8w2g8b8sP5A8+iqhqw8A==&#34;,&#xA;      &#34;kaUbMItvWrS1leJMEsAk9A==&#34;,&#xA;      &#34;7AoZZiCMmvqX9d9WD62FnQ==&#34;,&#xA;      &#34;OXr+UvfSDAQbLGP4xOBSMw==&#34;,&#xA;      &#34;tLSR0X6hQ7hvyPbBXZslBQ==&#34;,&#xA;      &#34;/YcdipQjiqJUDpddwhDiIw==&#34;,&#xA;      &#34;0bK7Vo3x9SXQYvDvMmgzXA==&#34;,&#xA;      &#34;rR226S9SV4WbmIVotM0CsQ==&#34;,&#xA;      &#34;QbgvVzhz2dr5BDvAUM6wFQ==&#34;,&#xA;      &#34;oyvtOIVUDqm1ruQx8vhRhA==&#34;,&#xA;      &#34;6dwQWrojfQ/1hgTT2PQckg==&#34;,&#xA;      &#34;uDfc8ZaPfrhTGcFwVaIvAA==&#34;,&#xA;      &#34;BfDjqoaYrd0NKCGGxtokTg==&#34;,&#xA;      &#34;6o8ui0RxMttDzkyqTDO5tg==&#34;,&#xA;      &#34;SvhQ7tNvl6ANrVnaJ4cBNw==&#34;,&#xA;      &#34;I3vwwgMxzxWo15otCOgvAw==&#34;,&#xA;      &#34;6LazNwUBgu5kQGKPCQnaOw==&#34;,&#xA;      &#34;zDmU3WG0c3AQYw7NFebUCQ==&#34;,&#xA;      &#34;8efBqSZ3OYqd+nT8a21FNA==&#34;,&#xA;      &#34;bh7RRRlNP555+LOFASdB0w==&#34;,&#xA;      &#34;2sm08sXcjWtT2Gtu3CdSug==&#34;,&#xA;      &#34;93O9BjbBwz1jYmTNCzgkUw==&#34;,&#xA;      &#34;b2xf65/2S45gOxG8Grxy0g==&#34;,&#xA;      &#34;BTToHfvg0weSXCH9D0acFA==&#34;,&#xA;      &#34;qug1advw8m4TjVAUPEUPiA==&#34;,&#xA;      &#34;00cDk2w3qfvdzMbO27c/+w==&#34;,&#xA;      &#34;XuMP4XKeqFlYH9jgvFKXXw==&#34;,&#xA;      &#34;W0TAw6aTfwXOMlJwloDkZA==&#34;,&#xA;      &#34;2I/0B+uXhxpPJWXGwNGlLw==&#34;,&#xA;      &#34;HHBOKYlzeD2Busv7btyBAA==&#34;,&#xA;      &#34;lHLNxD93t7uUJfmDhNwvCQ==&#34;,&#xA;      &#34;dO/rj/SVo/ZlfJAB2ajOEQ==&#34;,&#xA;      &#34;SGI/AkdUGrhS5bQBrDpzJg==&#34;,&#xA;      &#34;RCLRHWzoL8kWcamW6v1E6w==&#34;,&#xA;      &#34;7sGexlbSpX41SOBbWHg8BQ==&#34;,&#xA;      &#34;m9ROycwLgAur/M8HFSigEw==&#34;,&#xA;      &#34;+hBhqk1qKnkU+nqn6a96qg==&#34;,&#xA;      &#34;e7h3lwyDkLbzwbeza9/TWw==&#34;,&#xA;      &#34;w1094TrprBpG+5TZJus6FA==&#34;,&#xA;      &#34;ylg3k+AtgUcIl3hJiXNMlw==&#34;,&#xA;      &#34;MLyBE3p9/9+LMOMl2JBi6w==&#34;,&#xA;      &#34;Qe1reyLPtQVZ5wKqKa9jQA==&#34;,&#xA;      &#34;Y/6FiFNJ+h2jXNTlPOzrnQ==&#34;,&#xA;      &#34;XL1Nv8y45q8aiA92A99YyA==&#34;,&#xA;      &#34;GfPY5zBbHJQI4ZGaDcJj2A==&#34;,&#xA;      &#34;u1caIbS4Tk6y8c7sz8Hvhw==&#34;,&#xA;      &#34;KYv6PwzjV6/5I33cZ9LUmQ==&#34;,&#xA;      &#34;kTyfGInwWoCVv7gGPYCF5g==&#34;,&#xA;      &#34;Q2616MMrHflQbREkbaxMFg==&#34;,&#xA;      &#34;hxluEp8Si16NQcfaJDWcLg==&#34;,&#xA;      &#34;8563iLEht/ghMGItALTFUw==&#34;,&#xA;      &#34;19Kvl4LS7MCiBo2cRD5fxQ==&#34;,&#xA;      &#34;bcO+GuPgyR+iGLy6+mF2Cg==&#34;,&#xA;      &#34;NeZAaBfGrzLvaMKrJL7WlA==&#34;,&#xA;      &#34;T5Nghm4crNWWnUrYvZZItg==&#34;,&#xA;      &#34;gGrGej/Pj6/poAgebFb+dg==&#34;,&#xA;      &#34;bACUKZThWu3kcO82NfO4eg==&#34;,&#xA;      &#34;h+nOQU6khNxAH7kkGqVqkQ==&#34;,&#xA;      &#34;AIlN8RmMOvhBveVuVAyHQQ==&#34;&#xA;    ],&#xA;    &#34;IZ65O3ZOapykHwhaOX1/YA==&#34;: [&#xA;      &#34;d3Z1riL6AkoWkk27zYoWCw==&#34;,&#xA;      &#34;hHDtCxiuvJ9VSCSwnEG0Fw==&#34;&#xA;    ],&#xA;    &#34;J9Ac2zSOxpvD4YQ2MZMs6w==&#34;: [&#xA;      &#34;bHbadSMaYCdCzwHNWG3fzw==&#34;,&#xA;      &#34;oeQZicbrugL5hg8G7dVmSw==&#34;,&#xA;      &#34;TZnGp6lc5MuTXKrvF6Ln8Q==&#34;,&#xA;      &#34;mZpS2ltu6/QRC8uFk/t2ag==&#34;,&#xA;      &#34;su1aceqBKJzyQhYk4DtG5w==&#34;,&#xA;      &#34;P8nRZINGxkoETGXvn0vWdQ==&#34;,&#xA;      &#34;38nk80Avdc96iwBjm0zdqA==&#34;,&#xA;      &#34;VL0JOGDvBKQkxcjlKcpvoA==&#34;,&#xA;      &#34;KWRSi8vxblrZIdlqIEG3zA==&#34;,&#xA;      &#34;Gv9SmnUKqHUi+G3vQah9BA==&#34;,&#xA;      &#34;ENmG+VyULoyY7sa0jIk/uw==&#34;,&#xA;      &#34;IF/pusRwq2cM2AL083HZhw==&#34;,&#xA;      &#34;A1ZQfTMMpQF7G100W1c/Rg==&#34;,&#xA;      &#34;PInmzCd2elAZed8XII2H3A==&#34;,&#xA;      &#34;LIhAM4tPNTZzvy57RdTFgQ==&#34;,&#xA;      &#34;pL5xLi7HF+fZxJQ9yVoHHw==&#34;,&#xA;      &#34;ymZOc8rtV2bmln3PExOD3Q==&#34;,&#xA;      &#34;hxsQAGbTfRAveju4VaX/RA==&#34;,&#xA;      &#34;gRH01HjqQn159522OfR71A==&#34;,&#xA;      &#34;XIh88yJoOK2Ff8cGZL7F+g==&#34;,&#xA;      &#34;hMMTiPhU7F2ErldK8mMkDQ==&#34;,&#xA;      &#34;Q2JaEcNprQzczHwEGMbXgA==&#34;,&#xA;      &#34;F2zbkAiOFT3iZ5Dx0+MHfA==&#34;,&#xA;      &#34;WiJ6DYPst5oap7CBdVnD1A==&#34;,&#xA;      &#34;wvmpOuM/1L8oJ5qbX5rvJA==&#34;,&#xA;      &#34;iCq8lbTZO3yBSlU4d4JPMQ==&#34;,&#xA;      &#34;UIYVfnZoS2Er3ahTNsELrg==&#34;,&#xA;      &#34;GdB2cJ8S1OqnHKM7G6grQA==&#34;,&#xA;      &#34;RiAwHTFYpWhzZETb+CSE0Q==&#34;,&#xA;      &#34;+ba3qhqho8lfMXJQtKiMwQ==&#34;,&#xA;      &#34;5Wx/BMcr6FkgwAbn3tdwLA==&#34;&#xA;    ],&#xA;    &#34;JFKff4xqwvXPuYTu9WPwUQ==&#34;: [&#xA;      &#34;FroZeKbNhNx69+bj8o0OqQ==&#34;,&#xA;      &#34;vZIHu7rsNO8R8If5mjyTiw==&#34;,&#xA;      &#34;tbkEtEs3aa+p2/YQaD8BfQ==&#34;,&#xA;      &#34;dcH4AHY4X+K0bO3O9nqJrQ==&#34;,&#xA;      &#34;I3+uP7bb+nPtzRYHH2UUgw==&#34;,&#xA;      &#34;d+D4c9x4GMdq33+dJrszxQ==&#34;,&#xA;      &#34;IeTK1HBLKpS1+gfVSPrpvg==&#34;,&#xA;      &#34;ElE6r7xQZAfd5MScs95BXQ==&#34;,&#xA;      &#34;lJ8RTw7m+AgAnWW6upSntA==&#34;,&#xA;      &#34;lWdVDKK0NI1ECjrQyrQZhA==&#34;,&#xA;      &#34;guG+lyS5JQIDSZS6MEfIow==&#34;,&#xA;      &#34;/MgFHW097IAGIZkNc/Fltw==&#34;,&#xA;      &#34;RRtBD+EuTLmzasgAaBJyZw==&#34;,&#xA;      &#34;5kIWJ0hrLSTGTMvu/m2VBg==&#34;,&#xA;      &#34;sAlO/t+jkkm59mLcdOgB9w==&#34;,&#xA;      &#34;1w+glHHFE32ql3XJuIAYWQ==&#34;,&#xA;      &#34;4wegIDtvEZ75QrQWM65auQ==&#34;,&#xA;      &#34;MIaYLvbJRWXm7UR3+CJ1PA==&#34;,&#xA;      &#34;MMLwOzBcCET4jaa3dPuTwQ==&#34;,&#xA;      &#34;q5joCCZ2cOTa0rXBUtiSpQ==&#34;,&#xA;      &#34;QaKFgrY/cUPl6Ls/xAwlFQ==&#34;,&#xA;      &#34;5C8DQrs9fwpmV8rRYlvfCQ==&#34;,&#xA;      &#34;mmFI4mA7exd6BfbwTUwJfQ==&#34;,&#xA;      &#34;r4Fu2fNYrl5cfm4zX5YpZQ==&#34;,&#xA;      &#34;1CCABRgs/s9xxQcDgxw00A==&#34;,&#xA;      &#34;e/bnYsWq3UNe4TO8qzzb8A==&#34;,&#xA;      &#34;knUP7wXG3O435cJDvu9Thw==&#34;,&#xA;      &#34;rwC2lB0lflNzttbo5Agt3g==&#34;,&#xA;      &#34;gNGv6C2nj/tHk2ntVJUOWw==&#34;,&#xA;      &#34;4WgtH2AC4w3jDaPCHFqEaw==&#34;,&#xA;      &#34;RoQvxPrgcpXyTej834bT2Q==&#34;,&#xA;      &#34;oIBUxFCAPk4vRXBwpcmtFw==&#34;,&#xA;      &#34;cly/G/AvUZQM2J1YMymkpQ==&#34;,&#xA;      &#34;uO3OOEY6W3k9QH/tNVK0LQ==&#34;,&#xA;      &#34;4LZWGm07jnOHHBGX2FzAwg==&#34;,&#xA;      &#34;oGhsPyoyEtiEHT7/0qF+CQ==&#34;,&#xA;      &#34;CQPV/OxtJ+DwYc6C4gniNQ==&#34;,&#xA;      &#34;PqOWZHQu7W9hh0UlnMkHAQ==&#34;,&#xA;      &#34;Bu9dxnhmsLXDd3x0oRPHfA==&#34;,&#xA;      &#34;k9jtJIr2beiO7DTwypDNWw==&#34;,&#xA;      &#34;uPUnbuUJlh23l0km8iQ2tA==&#34;,&#xA;      &#34;Kr2KcyJfYQ8J1RDorzTofQ==&#34;,&#xA;      &#34;8XLKalkulxeAh8qfecmGlA==&#34;,&#xA;      &#34;hUC86VV8kD262xFcev0ZiA==&#34;,&#xA;      &#34;i2CsObRdsFCFCIvnyVzw5g==&#34;,&#xA;      &#34;uEn9qA67O/SoYHOtH/EL2w==&#34;,&#xA;      &#34;ZNpRshLHRo06/00CGV605Q==&#34;&#xA;    ],&#xA;    &#34;KS0gfrpBqK77mtupKmitjw==&#34;: [&#xA;      &#34;qIUMlexpn07c5Ly85v5AjQ==&#34;,&#xA;      &#34;kGY3woMWc1W36Wi2YstJ0Q==&#34;,&#xA;      &#34;aMOKwSAvMIKqreq1+gZ2ow==&#34;,&#xA;      &#34;sJNoOKrtqJYf9M2tWcTlqg==&#34;,&#xA;      &#34;IrRjtVOpf04EO7iAKFAznQ==&#34;,&#xA;      &#34;8gSzZr+GPWdWrD28SEc1Pg==&#34;,&#xA;      &#34;/pEYCNwBz8VXiXwXl+mS3w==&#34;,&#xA;      &#34;eaoaQZQXOAlAomwMnyNLSQ==&#34;,&#xA;      &#34;+UOyQgpOAnrWS+mVMK5k1Q==&#34;,&#xA;      &#34;Iv6wxIYqSLEjaMJTKmJ+Pw==&#34;,&#xA;      &#34;ZMqtUXBs3IUyb3eHhTEM+Q==&#34;,&#xA;      &#34;uDqtDPBJb3KaOc2STze05w==&#34;&#xA;    ],&#xA;    &#34;L2RUW2Fm5EOgoqwyitY3bg==&#34;: [&#xA;      &#34;9uC93Z+i1x3p9QMz1A1vlA==&#34;&#xA;    ],&#xA;    &#34;LW/iN16rWtvIqrNuZRqrvA==&#34;: [&#xA;      &#34;NKSXZUie8BGH5nwjKc1B6A==&#34;,&#xA;      &#34;PAKBAYCAtIg8PKEYWQkTzQ==&#34;,&#xA;      &#34;edQImQW6OalMt0U0nrXR2Q==&#34;,&#xA;      &#34;qkPjlqaV2EZ52NAHd/IgfQ==&#34;,&#xA;      &#34;kHJ1B6H/qaZ/vmirvtTenQ==&#34;,&#xA;      &#34;KRZBmtp/oO0gwwF8PmGh2g==&#34;,&#xA;      &#34;+p1B+LZP5hvhPeU88puOfg==&#34;,&#xA;      &#34;HVxGZgwvlrVpgAxKx4gRlA==&#34;,&#xA;      &#34;TSYnGqVe9WLIg9cR9McW7A==&#34;,&#xA;      &#34;b1aMkFsUYzQ15fp9A4JV2w==&#34;,&#xA;      &#34;4BI9AbtF5Vb7puMudQmp2w==&#34;,&#xA;      &#34;RI2wKrfD1EyE3/UfHBEmcA==&#34;,&#xA;      &#34;c76DQiDMr2npmMChLqBaow==&#34;,&#xA;      &#34;MEeKHFVdv0EwpaMPKCy3Sw==&#34;,&#xA;      &#34;egAiHhCEkMFVMFqpyh1hdw==&#34;,&#xA;      &#34;Bl8VfXimE6raefu05cOS8w==&#34;,&#xA;      &#34;iFdXYPdbzmitrrthD7u8yA==&#34;,&#xA;      &#34;zY7J45b8Kt4bFIMHib/PGQ==&#34;,&#xA;      &#34;T76LK9MUa3lwsxSAw540ZA==&#34;,&#xA;      &#34;a8Muru+syePTNtU2/rVrUg==&#34;,&#xA;      &#34;4aJ6IaFsuGhRpz+mkfUGqQ==&#34;,&#xA;      &#34;rT7Zl5hqfT/SFXkQlgRUqg==&#34;,&#xA;      &#34;sZ07/WOVHRgnOtPAXhah8Q==&#34;,&#xA;      &#34;yeUq/7JaeNz2SDn0gWjVQw==&#34;,&#xA;      &#34;Nh6DgKTo1EEcTUg+VgZK9Q==&#34;,&#xA;      &#34;1cSKTg9cjDeVqfRjC+3dyA==&#34;,&#xA;      &#34;F8lGQFeTGfg63gSPRvjBBA==&#34;,&#xA;      &#34;K2GE6n8fwvl9qlLu7U38Fg==&#34;,&#xA;      &#34;QOF3F7DIkILMx0gIrkLxgw==&#34;,&#xA;      &#34;Qvh4esOhPMDkhhNZaEzAtg==&#34;,&#xA;      &#34;pOKoOa+tppgNwBAEgYrxlg==&#34;&#xA;    ],&#xA;    &#34;Lwqn0aweLQLZmo12VvYcog==&#34;: [&#xA;      &#34;Rk5ia3x816rxtSUtbpOMnw==&#34;,&#xA;      &#34;rhaCfU7pM1FgApTAw4PpPA==&#34;&#xA;    ],&#xA;    &#34;MvInuV8lMA+9LBSzIEvv5g==&#34;: [&#xA;      &#34;YoLm41YhtgLxKYJ1/exB9g==&#34;,&#xA;      &#34;A+Jv9uRM/keGEYgIGq4WhQ==&#34;,&#xA;      &#34;YR9IlxlHBBSlj3ZLdc6/eQ==&#34;,&#xA;      &#34;RBuf8b62KyhEUrkIKRG/3A==&#34;,&#xA;      &#34;9k9GsZftBlKIenK0IOSwoQ==&#34;,&#xA;      &#34;Pml3cIw2PYIOjBurBs3LFQ==&#34;&#xA;    ],&#xA;    &#34;NSiprMdkK5/5pxuNNJOh2A==&#34;: [&#xA;      &#34;+R/6bpHEFR4SpBeguCorTQ==&#34;,&#xA;      &#34;2eh/JThmMghcGbhP7jHOJw==&#34;&#xA;    ],&#xA;    &#34;O6NCE8KkqNnnBGJrWxfPwA==&#34;: [&#xA;      &#34;cXB5uJOI3UJ7dOyNiQwFDg==&#34;,&#xA;      &#34;XPUXyp+BOEJyEGOgXafi8Q==&#34;&#xA;    ],&#xA;    &#34;OCIjbR16ktOEiFK36r0WNw==&#34;: [&#xA;      &#34;AzUHhCngmr5YuLLD/fQQEA==&#34;&#xA;    ],&#xA;    &#34;Ol1YWxU11Z64v1nA/zb/5w==&#34;: [&#xA;      &#34;j7yoSCks+i8LevHtgFwCwQ==&#34;&#xA;    ],&#xA;    &#34;OvOSK0YS4U6j2gyFBATNXg==&#34;: [&#xA;      &#34;aOUfuyvyyWEe7Z1IZT+fGw==&#34;&#xA;    ],&#xA;    &#34;P5Om9zCJ/QZ+hnrEvj6fGw==&#34;: [&#xA;      &#34;ymKqobod4xPivmLT/iq9oQ==&#34;,&#xA;      &#34;lzB4zyDZ+L/0TgHu+34IeA==&#34;&#xA;    ],&#xA;    &#34;PIk2BBAWexCFofMi5q03RA==&#34;: [&#xA;      &#34;S5Dzz9cigoJDCj8s5UcT0g==&#34;&#xA;    ],&#xA;    &#34;QG9+UTOvnb8kW+im/fjlJQ==&#34;: [&#xA;      &#34;+Jox86Lr4olzZZpeF2W5Cg==&#34;,&#xA;      &#34;0rfFR2EPlCkjUqAxx57NoA==&#34;&#xA;    ],&#xA;    &#34;QbZd82FdnCLBtn8fUkWn0A==&#34;: [&#xA;      &#34;kR9Bs/gd2Qm09J0HnMmVzg==&#34;,&#xA;      &#34;lFfYg6015iTLGI5pZVMU7w==&#34;,&#xA;      &#34;WjQCog+GPmCa3VQIGXKhRg==&#34;,&#xA;      &#34;U6rJ6LmaVlYRjI8Lq/aM/A==&#34;,&#xA;      &#34;fPh6cJ7fj6ecJeD/S/iyJg==&#34;,&#xA;      &#34;dz5oxhJicudEulHfFUUHJw==&#34;,&#xA;      &#34;svCt47J2Zwa45xj8gn3U/w==&#34;,&#xA;      &#34;NrTzMmbWyM5UeSvnQVNLOg==&#34;,&#xA;      &#34;5JPRWlHhzvwdgcYt2OnpZg==&#34;,&#xA;      &#34;+DR5Qfe30tw0byM4w3zykQ==&#34;,&#xA;      &#34;ixc06f0H9vqMfsbwQSwwvA==&#34;,&#xA;      &#34;VYGbkY0i6P3tRJd9mM1wNg==&#34;,&#xA;      &#34;yzZzF1vLZmeTiLJMgY7W0Q==&#34;,&#xA;      &#34;UwZunDPz4Z/GxKWN3p1+/Q==&#34;,&#xA;      &#34;klH60uFrR0WkawaSlcOEKg==&#34;,&#xA;      &#34;9ANhoIvfhYS2Fj0QOQtcOg==&#34;,&#xA;      &#34;HZ0OAEgNf1utcoh9whd4EA==&#34;,&#xA;      &#34;C5z0AxIvQN3JdMLvMYB+qg==&#34;,&#xA;      &#34;49x+aBSIi92s9+9k0YBLsA==&#34;,&#xA;      &#34;Eh3WlvVSpgyvj1kaA5So7g==&#34;,&#xA;      &#34;YSP3jWIJP4TspvpKDx/wvA==&#34;&#xA;    ],&#xA;    &#34;S8p9UGak1oycptcpYp/1eg==&#34;: [&#xA;      &#34;d/522T+B/ARMNSG+3QfAWA==&#34;&#xA;    ],&#xA;    &#34;SjQtW3gQmgt+Qj8JlnY4Mg==&#34;: [&#xA;      &#34;uu3d3lIlYVCZwOjqoNec3g==&#34;,&#xA;      &#34;e0/Fzu8wfMZp9zX32i9rMQ==&#34;,&#xA;      &#34;7CfySs4FmTkWgJPjEar4eg==&#34;&#xA;    ],&#xA;    &#34;Su8bfW9ijc0V5CiAum2V1g==&#34;: [&#xA;      &#34;5VGw1oph7DgrzGqxDXSJIA==&#34;&#xA;    ],&#xA;    &#34;ULrmZHuHE64atjgQOV1lWQ==&#34;: [&#xA;      &#34;axpLUf/WfpliDV7UixDwiQ==&#34;,&#xA;      &#34;f0N8ZEj6GTGaAo1R6vDhMw==&#34;,&#xA;      &#34;fKu2JVqQCl/zwzvO3uUkJw==&#34;,&#xA;      &#34;p0umWDpPMiOz8HPGPopybw==&#34;,&#xA;      &#34;v3PTZuvRGvqZW5kgzYKjFA==&#34;,&#xA;      &#34;3khZTPo1sdTxnkTY+5ATQg==&#34;,&#xA;      &#34;aJsQ4a3gp8/jsNBVC56QHw==&#34;,&#xA;      &#34;jyKmIhGp11jpJBCY83RPQA==&#34;,&#xA;      &#34;0hc+Z9xWtVy4dEgLyf7GUQ==&#34;,&#xA;      &#34;RzrQmVvfhyaExSlpoLqDzg==&#34;,&#xA;      &#34;3mM/O83kCBM7c1h3oioXHw==&#34;,&#xA;      &#34;QmXO38HGjUD9lc3XwducGg==&#34;,&#xA;      &#34;T7eVCD5Gwe0DXPZP59mQUQ==&#34;,&#xA;      &#34;TL19l7Dr/wLwmp6malQ4FQ==&#34;,&#xA;      &#34;Qi/s8gqjz2kgI+pAtQ5t9w==&#34;,&#xA;      &#34;MciappbjqbiRE2dg7PbMSg==&#34;,&#xA;      &#34;tUTc+tWHx1wVpIbeqTmR0w==&#34;,&#xA;      &#34;Z/nuiLo/kSAcxolOXcSWYw==&#34;,&#xA;      &#34;O912x64ev1faikrIaaOp6w==&#34;,&#xA;      &#34;NXO5f9Vv38zu/sOzuqBB9Q==&#34;,&#xA;      &#34;J1e16b0P6Tp2x5sVgsqutQ==&#34;,&#xA;      &#34;71C1Nt6KoL1+Dpr0rTxWwA==&#34;,&#xA;      &#34;gjKjRZqPuBXFD+3YZ4GvNg==&#34;,&#xA;      &#34;Hd38sct1pK5WIzmx83J/eA==&#34;,&#xA;      &#34;MDVosfib/bnNAm4m647vLA==&#34;,&#xA;      &#34;LdeUngez6mnzZ7ugJzuAmQ==&#34;,&#xA;      &#34;w4jLCE7e/XkliXylkG5u7w==&#34;,&#xA;      &#34;gFKfr+coMvRSD0OxrJHXPQ==&#34;,&#xA;      &#34;5QvPKgPa787NiewytO5Aqg==&#34;,&#xA;      &#34;0RDuhfilAG8dJEO2Fvk46w==&#34;,&#xA;      &#34;+Kc8jbRzLLDVqPaeFngWtQ==&#34;&#xA;    ],&#xA;    &#34;VPMvwiwbrTXjPkPpxmP3sw==&#34;: [&#xA;      &#34;WwAqpmlCgSYKoG1knafv5A==&#34;&#xA;    ],&#xA;    &#34;Vk7Abr1qzxUEVjteKWWX5g==&#34;: [&#xA;      &#34;/DjJHQ4LUqD/kDDEZQnGMQ==&#34;,&#xA;      &#34;E9ztZ/MyJW/b90Qruzzb/A==&#34;,&#xA;      &#34;+81WHs4+NlxNNP8OWMLJ2g==&#34;,&#xA;      &#34;3xFSeDOxGkdisnqW9w6B+Q==&#34;,&#xA;      &#34;Ywdulqdw8k75jjL2qb8gPg==&#34;,&#xA;      &#34;poe+ZOEeV2eDvTqSL2bcHA==&#34;,&#xA;      &#34;dKzgwwkG/spsYd8PVvrk6A==&#34;,&#xA;      &#34;rmKqD8ZR5vrHqnZkFulqdg==&#34;,&#xA;      &#34;BrupyHHgUisGe91mdtTkog==&#34;,&#xA;      &#34;55p6NGxCWjOVcUCBGiCPzw==&#34;&#xA;    ],&#xA;    &#34;W7uBqJb8l9AhSXjNg1JZQg==&#34;: [&#xA;      &#34;tbhLz74i3ShwS72WbIsoOA==&#34;&#xA;    ],&#xA;    &#34;WCQtqHWXoTXna7IAIUuLVg==&#34;: [&#xA;      &#34;4g6F/e8mwPh04jP3QYJj0w==&#34;,&#xA;      &#34;boWBDvSNZPI7kiGalqeu1g==&#34;,&#xA;      &#34;f6JDKuVN2cqa3h32gmRjXA==&#34;,&#xA;      &#34;6Mz5HTJNfyHd+tBxi8A32w==&#34;,&#xA;      &#34;N6nQdxnBzns6IrsJM+Xsuw==&#34;,&#xA;      &#34;lFQcTCheSGIjEbZVivulnA==&#34;&#xA;    ],&#xA;    &#34;WKbv3dOPjWYMO8/3E5KlHQ==&#34;: [&#xA;      &#34;b+WKHvVRvScXQjTpsI/dQA==&#34;&#xA;    ],&#xA;    &#34;WzYxymAFFZiduGsTG/o8gA==&#34;: [&#xA;      &#34;kGC5RaOJSDDnqCSoiLqrIA==&#34;&#xA;    ],&#xA;    &#34;XG5+bW8np2NedSy/od6z8Q==&#34;: [&#xA;      &#34;vlyMilfR3CdKSdc7LxNzEQ==&#34;&#xA;    ],&#xA;    &#34;XIcr6HdP94Dud7DtFrfMZg==&#34;: [&#xA;      &#34;DXoWfwXPN9ZCvCU/obObKQ==&#34;,&#xA;      &#34;+vYcckG24NBhOrHM/LGq8A==&#34;&#xA;    ],&#xA;    &#34;XTnX2VddNvCYpYt/meLgYA==&#34;: [&#xA;      &#34;i6aHe7Qjo768bvS9xSorFw==&#34;,&#xA;      &#34;N9dwh+Df2etJCiT3zY4CJw==&#34;&#xA;    ],&#xA;    &#34;YMB2ro5tOcEm81D0RjHxXA==&#34;: [&#xA;      &#34;2EHc3aND0ui/TYRnIdJ/WA==&#34;,&#xA;      &#34;Kpg8AKRn9eUVlQlRye20Tg==&#34;,&#xA;      &#34;yyVb0QTi/Vc4LSIxOEuhqA==&#34;,&#xA;      &#34;vKhY2603rcUieT1TILr6/g==&#34;,&#xA;      &#34;DVhbZtpHlSM2ukk3QurV1w==&#34;,&#xA;      &#34;jw+r2jbroWxBcAHcFZs/eg==&#34;&#xA;    ],&#xA;    &#34;YwobqP8raRKIH+wXi7ZS4g==&#34;: [&#xA;      &#34;Lhc4n2a9ma6eRDB/RCRmLQ==&#34;,&#xA;      &#34;sqtLRwfRzV6y9srK/2QK2Q==&#34;,&#xA;      &#34;IFUwSX5dX69QHRHfvOeQDg==&#34;,&#xA;      &#34;X7DmUVoCri5i6vdYVBBgXg==&#34;,&#xA;      &#34;l6IrI73Pg+lrisEtcgX+0Q==&#34;,&#xA;      &#34;mllkaOQAaJYNZpdIF7Bkbw==&#34;,&#xA;      &#34;FQwXyPZ+oHyxQZ9RBQXbpw==&#34;,&#xA;      &#34;Cpn7PI6CgTg1FJ1Ijp4TIQ==&#34;,&#xA;      &#34;vMgggE6Cjv/N2Jk4Dk6FYw==&#34;,&#xA;      &#34;6rEIsdyQtCC456AuGwgsDQ==&#34;,&#xA;      &#34;+TrS27bZKgEeir9pISurnQ==&#34;,&#xA;      &#34;3UNcgW64Eji4iyY2ZDB1cg==&#34;,&#xA;      &#34;ctALzLE36TiW3KdxIlF4Mw==&#34;,&#xA;      &#34;8MfvwX+dRI6Qt2H+x71rZg==&#34;,&#xA;      &#34;d0nPfXoEZybRuV9TMDY3YQ==&#34;,&#xA;      &#34;xC8Y7thfNSAfn5daCQFvgQ==&#34;,&#xA;      &#34;X4Ym25zfqcH7/samBN+yPw==&#34;,&#xA;      &#34;zqGJegkbTlVqcHBa6HtRTQ==&#34;,&#xA;      &#34;/rrV/dLSeVDaHUnAvPeh7A==&#34;,&#xA;      &#34;6+rn6nrQrafYloJtAeJ2Bg==&#34;,&#xA;      &#34;smB1yCGhBb8gDhPAER7odg==&#34;,&#xA;      &#34;S0PFhlHzk3DOoPuq+7jmPA==&#34;,&#xA;      &#34;H1wshPoazj8pmzsnWAztZA==&#34;,&#xA;      &#34;Pza9Y2xtH9MChVMkZwgw2A==&#34;,&#xA;      &#34;vnI8VBZMnSK/Spr6qFIUOA==&#34;,&#xA;      &#34;kDNo+1U3zj32TNGC/5DIKw==&#34;&#xA;    ],&#xA;    &#34;Z+lO9FXEjKlmAeYPAHGorA==&#34;: [&#xA;      &#34;n30+9otRNHBUO3IOHvF3kA==&#34;&#xA;    ],&#xA;    &#34;cHAJILwEV0OAQcBBnKqncg==&#34;: [&#xA;      &#34;fSeU4QTAs+fY+ihLpgdM9A==&#34;,&#xA;      &#34;XW4X9/W6MfETfE/VICA4Jw==&#34;,&#xA;      &#34;n39YhRffL6tFFAy/S18A8Q==&#34;,&#xA;      &#34;R1x4adkbkgVhxc9hzgUZcA==&#34;&#xA;    ],&#xA;    &#34;cZtZpGQDMJ8/qYUdQbgb3Q==&#34;: [&#xA;      &#34;GKtRNrhu6jQDTa3SPO81Kg==&#34;,&#xA;      &#34;YfN4DMNLaz3lIsbsDdrsLA==&#34;,&#xA;      &#34;W9ATeYhnrC0UlelRIXFecQ==&#34;,&#xA;      &#34;UsEuyAuS2VCokppecP9FXw==&#34;,&#xA;      &#34;5d35KoGqN7hqoORJbRxrzg==&#34;,&#xA;      &#34;6ULb2hTeXRKRWDAjQMdnAQ==&#34;,&#xA;      &#34;mt2uKyaY1pD5PD0HEI8sFg==&#34;&#xA;    ],&#xA;    &#34;dBKXgz7fNBsMAqmGTkj8sQ==&#34;: [&#xA;      &#34;BBVHDYnqIwi0Vk9ZX1yGIw==&#34;&#xA;    ],&#xA;    &#34;dC9CoYt17eaqinGSVCfCxw==&#34;: [&#xA;      &#34;kGC5RaOJSDDnqCSoiLqrIA==&#34;&#xA;    ],&#xA;    &#34;e40n/77uWc/t2R+0m7WchA==&#34;: [&#xA;      &#34;W/xTZXt8arFxTmTRnfh2+g==&#34;,&#xA;      &#34;1I5Zdk3zr6CO9kf+WEea4Q==&#34;,&#xA;      &#34;76eg4nI+WwZq6jvunMGVEQ==&#34;,&#xA;      &#34;YwrNcgB1VRavvqQXhCICXg==&#34;,&#xA;      &#34;uJJdxHNbejxspD7yZE5qWA==&#34;,&#xA;      &#34;8hlo60BBnOd97TpyGOfaLA==&#34;,&#xA;      &#34;/M50+nAheHXCE2atpE2VJA==&#34;,&#xA;      &#34;qIUMlexpn07c5Ly85v5AjQ==&#34;,&#xA;      &#34;kGY3woMWc1W36Wi2YstJ0Q==&#34;&#xA;    ],&#xA;    &#34;e9e6iwwufr2qvMYpuZgq7Q==&#34;: [&#xA;      &#34;fSeU4QTAs+fY+ihLpgdM9A==&#34;,&#xA;      &#34;XW4X9/W6MfETfE/VICA4Jw==&#34;,&#xA;      &#34;n39YhRffL6tFFAy/S18A8Q==&#34;,&#xA;      &#34;R1x4adkbkgVhxc9hzgUZcA==&#34;&#xA;    ],&#xA;    &#34;ev4LjEwclLnf3ehIi3l8oA==&#34;: [&#xA;      &#34;HxI42iSjURjRki+uV6q/9w==&#34;,&#xA;      &#34;vH+nziLZjIpD4JaIkhx3FA==&#34;,&#xA;      &#34;bugTfOdgCaATW4vTnuXTSQ==&#34;&#xA;    ],&#xA;    &#34;ewbqmzgK8Rzf739yT7IKUQ==&#34;: [&#xA;      &#34;tbhLz74i3ShwS72WbIsoOA==&#34;&#xA;    ],&#xA;    &#34;fDuwmXmKOYEK5h1q2eODXQ==&#34;: [&#xA;      &#34;/rKG82d/RCig7yYmsr6Kpg==&#34;,&#xA;      &#34;bJGGlc8FG/c2T93ktUh6Ig==&#34;,&#xA;      &#34;75iSdAKFlPvTmCAp8d99YQ==&#34;,&#xA;      &#34;YdpqbsRbo4xx71CiWUF39Q==&#34;,&#xA;      &#34;8zIRit7VqNRaBPLxL/+VAg==&#34;&#xA;    ],&#xA;    &#34;fVq3Liql8bu1Y+KmIvpQoA==&#34;: [&#xA;      &#34;e57+W7idPeSI15OIacmH5Q==&#34;,&#xA;      &#34;q7c6mw4iAmau1l6sfNLk8w==&#34;,&#xA;      &#34;9GliauANgklOt4mKxwOygQ==&#34;,&#xA;      &#34;haC60dPgMQIFAnJX4zid+A==&#34;,&#xA;      &#34;Sygyk9+T2DbXETLWiB21dA==&#34;,&#xA;      &#34;352rQmt68kXSxd4G583XXA==&#34;&#xA;    ],&#xA;    &#34;fao+yXdp7lvp4+d732rCkw==&#34;: [&#xA;      &#34;5LplZpuSZzAiOH2fmk3HWg==&#34;&#xA;    ],&#xA;    &#34;gihIEYR/lLwr4ndjyvVROA==&#34;: [&#xA;      &#34;9B4gl+qnaOhRLjmkdKMYbw==&#34;,&#xA;      &#34;U8pdHlQlr/x1RsdiZ3YQOg==&#34;,&#xA;      &#34;eZAX5+dryNgqi55C7fN1LQ==&#34;,&#xA;      &#34;FFVNPAck6QPQFhxf4KhO3g==&#34;,&#xA;      &#34;zXyE3S2RgbWC3bSm5zxzpw==&#34;,&#xA;      &#34;rzmoKvIFGvuPP0SzaH7s9w==&#34;&#xA;    ],&#xA;    &#34;gjJq4XQiX28zDnKvnb0/jg==&#34;: [&#xA;      &#34;MdEybCUhVKCoyI/dXRvNlA==&#34;,&#xA;      &#34;e0/Fzu8wfMZp9zX32i9rMQ==&#34;,&#xA;      &#34;7CfySs4FmTkWgJPjEar4eg==&#34;&#xA;    ],&#xA;    &#34;hWZOSd0A+iLGAwoMoW6sgw==&#34;: [&#xA;      &#34;QskDoDnTSvrQeDXklM4YOw==&#34;,&#xA;      &#34;bZGx+ktPNqzyr9hXBoIOTA==&#34;,&#xA;      &#34;dZ7ryQ0b1w50+eNxXX/Jcg==&#34;,&#xA;      &#34;QZ+YDQI7XEpbDFIIv4hUIw==&#34;&#xA;    ],&#xA;    &#34;hktk4wXij5O6pY5X6Pdp/Q==&#34;: [&#xA;      &#34;fSeU4QTAs+fY+ihLpgdM9A==&#34;,&#xA;      &#34;XW4X9/W6MfETfE/VICA4Jw==&#34;,&#xA;      &#34;n39YhRffL6tFFAy/S18A8Q==&#34;,&#xA;      &#34;R1x4adkbkgVhxc9hzgUZcA==&#34;&#xA;    ],&#xA;    &#34;izKk4aK07ZN99JT+tBsSBg==&#34;: [&#xA;      &#34;ST+HmAso4vf4Hnu6TuBXXQ==&#34;,&#xA;      &#34;bXKnVRmmXzNE9gSoSjNlOQ==&#34;&#xA;    ],&#xA;    &#34;jDR7o2j2gfJePh/5YNDLjw==&#34;: [&#xA;      &#34;3FpQibjt3OzhrwoSJ9I0Mg==&#34;,&#xA;      &#34;DjqCxCryg8LYvAZ67mAiSQ==&#34;,&#xA;      &#34;nCQ2LebiZFodYZ8OrVfuXw==&#34;,&#xA;      &#34;QskDoDnTSvrQeDXklM4YOw==&#34;&#xA;    ],&#xA;    &#34;lNWcYbl6h71sUZV6B4E+bw==&#34;: [&#xA;      &#34;j7yoSCks+i8LevHtgFwCwQ==&#34;&#xA;    ],&#xA;    &#34;lV2MRz2nTh21rS47LJ6XIQ==&#34;: [&#xA;      &#34;gpPTgXxcA95Uk2vaf3/2dw==&#34;,&#xA;      &#34;jGwIyHTli8TFB8vvlYRLgQ==&#34;,&#xA;      &#34;o16kBwzDyL2DXuhbCPWX9Q==&#34;,&#xA;      &#34;9iADtyaox0PEZ/SbvPWJcw==&#34;,&#xA;      &#34;DtkRUkQTzcJrj8ZsC36kqQ==&#34;,&#xA;      &#34;zHSqcJBwH0Go6UqHQ1Fu/Q==&#34;,&#xA;      &#34;ScOp6HuJxBp54FxFpTVDnA==&#34;,&#xA;      &#34;TsVNXuAeF3PhiRZhIOjjtQ==&#34;&#xA;    ],&#xA;    &#34;mqINnrlOZQGPnpnT9GZG5w==&#34;: [&#xA;      &#34;S1vpC2/S8eBK717462wBrQ==&#34;,&#xA;      &#34;CKAla6xchD1gy0q9ML/2xg==&#34;,&#xA;      &#34;rWO0jZdArYZ9zSTLMe8r8w==&#34;,&#xA;      &#34;rVRinaBex/zPmHE0cI9QNQ==&#34;,&#xA;      &#34;qIj6aIlqGJtvbX658qTpDQ==&#34;,&#xA;      &#34;aN7J4vjcApPz2ZabMR0Irg==&#34;&#xA;    ],&#xA;    &#34;mx/6FfeunMu7M9pQ9cRKkQ==&#34;: [&#xA;      &#34;ZkozpC3UXStcW3ZbPMbsTA==&#34;,&#xA;      &#34;2wdtg9odVWp21dq/2MNviQ==&#34;,&#xA;      &#34;tuPGTYWKd0OWuEIwEsNtuA==&#34;,&#xA;      &#34;fzE91AQotuZJ8swhDTTd+g==&#34;,&#xA;      &#34;w8vuCHS+4au/MfXahCBARA==&#34;,&#xA;      &#34;+X2XfuAS28uyjxaPoK8Ysw==&#34;&#xA;    ],&#xA;    &#34;n9GoYS9J7jkIET4QDQWijA==&#34;: [&#xA;      &#34;xpncb/4iGS4E4GyJA4P7Vg==&#34;,&#xA;      &#34;041SU8x5Wrw6mRfaRurHIg==&#34;,&#xA;      &#34;3mZTUjJt0v6SBGf7lIXm2Q==&#34;,&#xA;      &#34;lPpQZfWnRR1kvdFRKr34Kg==&#34;,&#xA;      &#34;9K1bGbpJNlcAkIrOMal8Gw==&#34;,&#xA;      &#34;bS47R6kjzBYQaQepU2dXHw==&#34;,&#xA;      &#34;MZUC9kv5PI1Xlt1QOYz1SQ==&#34;,&#xA;      &#34;2Jpm8Zc5oiON+VhscwC/4w==&#34;,&#xA;      &#34;6+TrxTb+GrNbsX7xQgQW9Q==&#34;,&#xA;      &#34;bg8JYRcvY0wFh5b8Bl6Gmw==&#34;,&#xA;      &#34;dQM2EJNgLlaaPe53GlhnMg==&#34;,&#xA;      &#34;XKTHMaJwDxmLjk9FkUhg8Q==&#34;,&#xA;      &#34;3lmx9lr/AS2B0oQRtI5gOA==&#34;,&#xA;      &#34;269Lb6JhyjdTwif2gzpsMQ==&#34;,&#xA;      &#34;mESXtMr2XIcnFGpdxMD0iA==&#34;,&#xA;      &#34;DAEgBJ6jpEvrKn3TAPAfVQ==&#34;,&#xA;      &#34;orI4WDU+1BLBSEG99OS8MA==&#34;,&#xA;      &#34;Py++HyN8+aNZZa9dPe2rDQ==&#34;,&#xA;      &#34;bNVewgNMQNWC+EwlyIyTlA==&#34;,&#xA;      &#34;WhQSrxicq09HlEU8PxUQSQ==&#34;,&#xA;      &#34;dw03VWGdtImJ58988UyhtQ==&#34;,&#xA;      &#34;pgBZKIeBAAyMOCe6qVOUxg==&#34;,&#xA;      &#34;WhY0uvyUG/ImjnbaewZftw==&#34;,&#xA;      &#34;/h81Nr0GSz2fO9zGO8rpYw==&#34;,&#xA;      &#34;pzONVbRfZmj1lkGaWtUucQ==&#34;,&#xA;      &#34;KFwkHKkJGVyJAn2RsW13sw==&#34;,&#xA;      &#34;B5DU5CG3Y0pIFFmMM3RU1A==&#34;,&#xA;      &#34;gPjSjC7XxsCvs5w6EQPViQ==&#34;,&#xA;      &#34;po1D239o+AaKFXhspYJxNw==&#34;&#xA;    ],&#xA;    &#34;niOKQxfAYGHJ3oUq3VHjdA==&#34;: [&#xA;      &#34;0HbetX2gSM32682C6raRqA==&#34;,&#xA;      &#34;chGqAT1jYixNKwXlctnUeg==&#34;,&#xA;      &#34;R7olSy1x/HelcHgr9AjG7A==&#34;,&#xA;      &#34;ayJ94QRlWYBn8mXMxBDr+Q==&#34;,&#xA;      &#34;P0gqeMXeqGecgv5yzB/trQ==&#34;,&#xA;      &#34;ZA3vHdd4PXjvIsTBPl1mxg==&#34;,&#xA;      &#34;1r+syFhyATToDtkOkMLqDw==&#34;,&#xA;      &#34;4XO5TL/zvh/gBT0sz3RSYw==&#34;,&#xA;      &#34;i9sUrKKUObLH200e/JvjcA==&#34;,&#xA;      &#34;E69qsmSRl4PzNiueJkPUDw==&#34;,&#xA;      &#34;4FPYx+QEdkXz09AmCNB74A==&#34;,&#xA;      &#34;Qvw0/zOlMy3n6XUCrN6SmQ==&#34;,&#xA;      &#34;0u4nnKNMeZ58/8R+sWLPSQ==&#34;,&#xA;      &#34;CfMK+8nnfjDlpiJ86nDqnQ==&#34;,&#xA;      &#34;OB+gdUis8HhIN+YuJZ0d3w==&#34;,&#xA;      &#34;VpM36keMJ87mG4yZ97wQdw==&#34;,&#xA;      &#34;9v8e/1gKgcwShm3I7m4SiQ==&#34;,&#xA;      &#34;0nKksdratD87mbqRPBOINQ==&#34;,&#xA;      &#34;Pi9su0FguY3j1GBpXhwKIA==&#34;,&#xA;      &#34;fqP9GV2+ELPjUr/DY2avpQ==&#34;,&#xA;      &#34;d28O4EsS+H4v4JSsIykoOg==&#34;,&#xA;      &#34;j9OVo/jK62GKOQBSgKgJGw==&#34;,&#xA;      &#34;nxtlAyA33msfy3ysIKdYBg==&#34;,&#xA;      &#34;jAAGS0/fgd26tdTkBYM5+w==&#34;,&#xA;      &#34;FeNPPUXNvPHMFZ28E13Mog==&#34;,&#xA;      &#34;DwTrtZS+niTc7qfIVCIZAQ==&#34;,&#xA;      &#34;3zxG1J6bDKAhZ9wlUE9Y4g==&#34;,&#xA;      &#34;z6EnRvmkq3BmM0fg3cIFAQ==&#34;,&#xA;      &#34;BB1IXjQVr93It/qGF51Vqg==&#34;,&#xA;      &#34;wOf+QLuqfByteGwfULI8YA==&#34;,&#xA;      &#34;bk6ikdg+f6vAFzgypr0cOw==&#34;&#xA;    ],&#xA;    &#34;nzQEyt4JfkGeZIIHPiBhog==&#34;: [&#xA;      &#34;bOC69k4Gpn8Av1w/ra2Tdw==&#34;,&#xA;      &#34;e0/Fzu8wfMZp9zX32i9rMQ==&#34;,&#xA;      &#34;7CfySs4FmTkWgJPjEar4eg==&#34;&#xA;    ],&#xA;    &#34;q8h8ag3Ho33Zc/60lMOvVA==&#34;: [&#xA;      &#34;Z0bbSkX8e3OUKdJa86CbBw==&#34;,&#xA;      &#34;r3RLKNYtYvKarBqnnrlrew==&#34;,&#xA;      &#34;xQ6R88+x8IssPvOAavmZXw==&#34;&#xA;    ],&#xA;    &#34;qGKV3oqLguMWpyzvjv1+wg==&#34;: [&#xA;      &#34;tvq/gvjGf6pzxLuMOglBaw==&#34;,&#xA;      &#34;TrnW8DIZgc2e/W4a1+ccJw==&#34;,&#xA;      &#34;YodqYykSYwoW2Z78DZNfRA==&#34;&#xA;    ],&#xA;    &#34;qc0Yt1AzZC+CY6qdjO+fZA==&#34;: [&#xA;      &#34;Di0hwt0owko/VaT8i7ICOw==&#34;&#xA;    ],&#xA;    &#34;rY/kE/V4JnxYoqV+lmc9mg==&#34;: [&#xA;      &#34;X8OJykaOJlN5EhVA7Y11uQ==&#34;,&#xA;      &#34;DDxCHnX+kCqcRQj9b90/cg==&#34;,&#xA;      &#34;R5XnexvMFgBiw/v8sY0BOA==&#34;,&#xA;      &#34;iwe2PkNe91EUwDENn+pmew==&#34;&#xA;    ],&#xA;    &#34;s6wkZ09Eozv3vmfwsPHUvQ==&#34;: [&#xA;      &#34;AILk1bhdEUQriiNdRe9Buw==&#34;,&#xA;      &#34;yXjhPZPggtyVHOPFjmeHOg==&#34;,&#xA;      &#34;4ugLfuPhGpzb4ohYABxG+w==&#34;,&#xA;      &#34;QskDoDnTSvrQeDXklM4YOw==&#34;&#xA;    ],&#xA;    &#34;sJhS0sL3jXf+ZUi4oTiojw==&#34;: [&#xA;      &#34;vyw54XHJNXkWpKNGLbf2jQ==&#34;,&#xA;      &#34;V1rPWqhvOrQycOtSN8Ve9g==&#34;,&#xA;      &#34;hLbfRT5oTN6ilWiJVmH5Uw==&#34;,&#xA;      &#34;05N5Len6XyuiKITeFewI+A==&#34;,&#xA;      &#34;WbtmlW8SfW38NUPRnGwbsA==&#34;,&#xA;      &#34;wp75ZuWMdeSuJ4xUhgowQA==&#34;&#xA;    ],&#xA;    &#34;sREtPFILPccNXLGF49Cnmw==&#34;: [&#xA;      &#34;XKuZX/r+YD1eQ8+4f77NQQ==&#34;&#xA;    ],&#xA;    &#34;ssPaV1VLDu6d5ZJ6Rrmh3A==&#34;: [&#xA;      &#34;XwLJYEytIMCdc6/A4MTJHg==&#34;&#xA;    ],&#xA;    &#34;tGPn3pK3U8y547XMf1WmhQ==&#34;: [&#xA;      &#34;14Ky/IzCleKAYRnLtZIRFw==&#34;,&#xA;      &#34;6F1zSnZjp7g1twFO1AhdxA==&#34;,&#xA;      &#34;UUa5vuAfloHekZLBPCTvFQ==&#34;,&#xA;      &#34;+Ny4TpLzLiX1vAXKrYuRkg==&#34;,&#xA;      &#34;rSxPRb6y8rOV71QNzjYBEA==&#34;,&#xA;      &#34;J/9bEF16NjSRIAmmzZMBkQ==&#34;,&#xA;      &#34;pDJ3Xpebdx7KToS5V5VZDQ==&#34;,&#xA;      &#34;qIUMlexpn07c5Ly85v5AjQ==&#34;,&#xA;      &#34;kGY3woMWc1W36Wi2YstJ0Q==&#34;&#xA;    ],&#xA;    &#34;u3thu0wHuvY+STb8TrhkKQ==&#34;: [&#xA;      &#34;vkypiN/HZjIiT/S9k2qxvA==&#34;,&#xA;      &#34;tOOsPkEJCdO66XvUUd+xnQ==&#34;,&#xA;      &#34;j3PAipb/hCxnbdoUmJvkNQ==&#34;,&#xA;      &#34;oxSfxLnytv2y2gHjvplCuw==&#34;,&#xA;      &#34;0lUHXQNoRQLden1OTY/5/w==&#34;,&#xA;      &#34;D17rv5OxhiqZrK+otc1Xcg==&#34;,&#xA;      &#34;kuuz4akZvpNKTf2txpaWog==&#34;,&#xA;      &#34;PD08BQc1tUldC8QSScd1aA==&#34;,&#xA;      &#34;NrNei+pIM0R36v4Js8XxAg==&#34;,&#xA;      &#34;p8wzfQhvimCzJ24LCz0qSQ==&#34;,&#xA;      &#34;rjcajgsmKA8I5yMLMT8DHg==&#34;,&#xA;      &#34;YKgthSAonF3epY42eqsMRw==&#34;,&#xA;      &#34;O+92Gg/bs8C9EjretuiP8A==&#34;,&#xA;      &#34;zE3cPdw4Ma9jQQUVeE/hdg==&#34;,&#xA;      &#34;idDdN00zXJT8ntMCqQfdkA==&#34;,&#xA;      &#34;j8SFSR8BZ09zBKgRkzC7Jg==&#34;,&#xA;      &#34;FInGJTEa3gToUzpaoDNNQw==&#34;,&#xA;      &#34;rlHsuoluzmy30odv/xIILA==&#34;,&#xA;      &#34;UG+yX6nADJgJWegetH+HQg==&#34;,&#xA;      &#34;xRDJz3P8IApYf+UqTsFimg==&#34;,&#xA;      &#34;LUQxjpYcQwxSDC7CX78VUw==&#34;,&#xA;      &#34;bf41zTvm6HAv6xdiXpwGWQ==&#34;,&#xA;      &#34;EOFhzMVjLzNyQsRKP/y6ag==&#34;,&#xA;      &#34;SH2AP7i0ZzGmFbD1kuJsew==&#34;,&#xA;      &#34;G/nM9FqgWuICAFy4kMmJlA==&#34;,&#xA;      &#34;bpwdCug2xQZhmaazCqwIew==&#34;,&#xA;      &#34;j71n+HvL+1UIm3Tw+EUHpw==&#34;&#xA;    ],&#xA;    &#34;v3i4ez5juML2ZWwR+6dFFg==&#34;: [&#xA;      &#34;AUiFITCnRjRxctzqqbDeeA==&#34;,&#xA;      &#34;iF/o4aDbQf1DAw7R+LiVQw==&#34;,&#xA;      &#34;9iigvnuYDaC8UzcOIDLjIQ==&#34;,&#xA;      &#34;2F6XtsAYpNWm5w+Rwl/tuQ==&#34;,&#xA;      &#34;GAn7gWUe2pFr7PbwechqxA==&#34;,&#xA;      &#34;76z9Mpn8Jp7lhZSPsHTHug==&#34;&#xA;    ],&#xA;    &#34;vtNcuXyRth8r8K/W3sfqrQ==&#34;: [&#xA;      &#34;SJA+1v6mehbGh4JXJ2n5jA==&#34;,&#xA;      &#34;2No3jCnnmCwOEpCbk+TZGA==&#34;,&#xA;      &#34;BDC/Jijmwb4kfsAYqG7t2Q==&#34;,&#xA;      &#34;aKcPzJFDOswSNCIlBX5/jQ==&#34;,&#xA;      &#34;0n2Q+dTJnzCs850WQs7VXA==&#34;,&#xA;      &#34;MtOwgWyogkVoNGuQavHN8g==&#34;,&#xA;      &#34;Uwj2IeJYZ6kg0JLABYAJ/Q==&#34;,&#xA;      &#34;JPakAMrmBlullQ47gJ/fkw==&#34;,&#xA;      &#34;//8buewiV8gb20qv4g1cqQ==&#34;,&#xA;      &#34;gn3bQe/78AdzPhooNm1KQw==&#34;&#xA;    ],&#xA;    &#34;wYIIhtw19AhoRPO0XAvoxw==&#34;: [&#xA;      &#34;qSRGSB2uV6n5bH1pdu2LUQ==&#34;,&#xA;      &#34;nS3gw6C5KX889pH0DdnXbQ==&#34;,&#xA;      &#34;FzTxCzGYtLmJVoQ1syBiUQ==&#34;,&#xA;      &#34;f2M9JeIe3F0Fc9CFbQ6bTQ==&#34;&#xA;    ],&#xA;    &#34;wfJGCqOH8d+IYg/dAepx1A==&#34;: [&#xA;      &#34;lQBARBTddFvexevUD04GZA==&#34;,&#xA;      &#34;Kqq2xlybjD/tOLmQWu2xPw==&#34;,&#xA;      &#34;xxrOMZzPk7ETmnvrIjBo0A==&#34;,&#xA;      &#34;/GP9UYzgnUNp/vOMMDf7mw==&#34;,&#xA;      &#34;sykv+pGN4TXggZNIwL/H4g==&#34;,&#xA;      &#34;Ez8lHT2uV9Tf9vJC/T4WXg==&#34;,&#xA;      &#34;76mWuVYhbmIFsc4DNorK9A==&#34;,&#xA;      &#34;uaetuJImncB6wudykQLpEA==&#34;,&#xA;      &#34;o/v8DGswQXGkB45uD8rRUw==&#34;,&#xA;      &#34;mJw+LvAbCoVMIOZXCXNFpg==&#34;,&#xA;      &#34;VWEbeFnFOHy1IkG21b5a5g==&#34;,&#xA;      &#34;YX2rGofSXHBcNhTOGpNkAA==&#34;,&#xA;      &#34;LxYgcRll4fEnbCHHZWt4BA==&#34;,&#xA;      &#34;KMGV9rbVZ/vVUNSX6f+JqA==&#34;,&#xA;      &#34;O3XylFvGObsPmzTrCuhV8A==&#34;&#xA;    ],&#xA;    &#34;xMqWNWDJot/UVGgOoRsUVQ==&#34;: [&#xA;      &#34;9VSflkDgRQsGPkKM4aVDHw==&#34;,&#xA;      &#34;W3SNJz91vyAPBvH2kz/itQ==&#34;,&#xA;      &#34;FMWVyBjC/IhzfdU57RFV5A==&#34;,&#xA;      &#34;gt3d97KykHIhCqEzLKzqHQ==&#34;,&#xA;      &#34;c2gL4Z8Tbc2Ge5iwCDCV9Q==&#34;,&#xA;      &#34;iT0wLV5um6Novvux5XEDSA==&#34;&#xA;    ],&#xA;    &#34;xTea8RVD9wez5DTFDIkCYg==&#34;: [&#xA;      &#34;QNrS4atSfp1tFVuWE/Cnqg==&#34;,&#xA;      &#34;cebQbn0Dg58LegYW4JDjIA==&#34;,&#xA;      &#34;kXRjhXGDLvcaf9UDToCwQQ==&#34;&#xA;    ],&#xA;    &#34;xuRjbnwW5VkRHg0Huc5RCg==&#34;: [&#xA;      &#34;e0/Fzu8wfMZp9zX32i9rMQ==&#34;,&#xA;      &#34;7CfySs4FmTkWgJPjEar4eg==&#34;,&#xA;      &#34;+4boUUXSpak/++mwJDcv/A==&#34;&#xA;    ],&#xA;    &#34;znACbAN0JGBPtCXNh1d0Ng==&#34;: [&#xA;      &#34;+usEQpepP7UaLaTDZ7AUHQ==&#34;,&#xA;      &#34;dTHv7xNEey4Rvi0jaC90Ng==&#34;,&#xA;      &#34;pe4Shj+F17XwL0468/ASsg==&#34;,&#xA;      &#34;jZO++vSydJTiCIbVesbXEQ==&#34;,&#xA;      &#34;gSYlqWWhsq36L2EzWb/x+w==&#34;,&#xA;      &#34;Dl7D7r3bnERvJ1K3e9T3bQ==&#34;&#xA;    ]&#xA;  },&#xA;  &#34;enrichments&#34;: {&#xA;    &#34;message/vnd.clair.map.vulnerability; enricher=clair.cvss schema=https://csrc.nist.gov/schema/nvd/api/2.0/cve_api_json_2.0.schema&#34;: [&#xA;      {&#xA;        &#34;+81WHs4+NlxNNP8OWMLJ2g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;+CgZKiM2jpLyW2jlIXneLw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;+Kc8jbRzLLDVqPaeFngWtQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;+PjI2yN4wCMPyf1oygeT5Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 4.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;+TrS27bZKgEeir9pISurnQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;+X2XfuAS28uyjxaPoK8Ysw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.1,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;+hBhqk1qKnkU+nqn6a96qg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 4.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;+ihXD4KFgwxouHTRyQ5EbA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 3.7,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;+p1B+LZP5hvhPeU88puOfg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;+uMSPU5jbqI0+jsP/eX6PA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;+vYcckG24NBhOrHM/LGq8A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.0,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;/MgFHW097IAGIZkNc/Fltw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;/Q70+j219nLwNP4Phg4sag==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;/YcdipQjiqJUDpddwhDiIw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;/Zbh/oTVYOn4fLQqcvLFNw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;/h81Nr0GSz2fO9zGO8rpYw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;/rKG82d/RCig7yYmsr6Kpg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;00cDk2w3qfvdzMbO27c/+w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;08ogBuWXS+d72R0TAjgJaQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.2,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;0E1VjQWdmolR9lr9ElIZZQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;0HbetX2gSM32682C6raRqA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;0YVxD0vSH+0MhijemP/Jmg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;0bK7Vo3x9SXQYvDvMmgzXA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;0hc+Z9xWtVy4dEgLyf7GUQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;0nKksdratD87mbqRPBOINQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;0u4nnKNMeZ58/8R+sWLPSQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;0v5F4x1W0RxkklLvRs6NKQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;19Kvl4LS7MCiBo2cRD5fxQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;1WQ/LJu/kefEuHRv58l0Lw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;1WaijHYxan9df8+fB0SQJQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;1cSKTg9cjDeVqfRjC+3dyA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;1geoBO6lBMXVRM+dfApwgw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;1npmxgSnoYj2MyAhQMaE7g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;1r+syFhyATToDtkOkMLqDw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;2I/0B+uXhxpPJWXGwNGlLw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;2No3jCnnmCwOEpCbk+TZGA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;2RZ3u6UmceVG9iB/xb73SA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;2UHqEqfMIIn53NkDlDEppQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;2d2KejA0Nrz6tVNnB1dB5A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;2fFhV4f06vNDz4aMbkPOZA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;2luu38jiVQvy6qOXHFgpAg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;2sm08sXcjWtT2Gtu3CdSug==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;3285RkL43CGSYbmius5+sg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;352rQmt68kXSxd4G583XXA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;38nk80Avdc96iwBjm0zdqA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;3Lvdmj//2sze9S8I3n8yrw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;3WRC4Vl08/leTJ1MFHuCEg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;3xFSeDOxGkdisnqW9w6B+Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;49x+aBSIi92s9+9k0YBLsA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;4H2TsDPy1XcHidTqNqeZpg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 3.3,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;4Ir8FDWM4WPrO3dybbfnYQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;4LZWGm07jnOHHBGX2FzAwg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.9,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;4WgtH2AC4w3jDaPCHFqEaw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;4aJ6IaFsuGhRpz+mkfUGqQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;4ardx/cPJA31l/GjZ5ssvw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;4o31bbgKJ2cSqPGCPyFjLQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 6.9,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;4os+HU28VQ7buZvoEKQ/kg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 4.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;4w9ia49tOv0+yiq1lgkH0w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;4wegIDtvEZ75QrQWM65auQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;5D5WFK01Su4Lrj4hhwDYGQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 4.7,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;5JPRWlHhzvwdgcYt2OnpZg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.2,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;5Wx/BMcr6FkgwAbn3tdwLA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;5snUlx7ztOquC9N7WioMbg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;6LazNwUBgu5kQGKPCQnaOw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;6MW1lRUdNNc4s+6uD2JNvw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;6QirCtH9GCLBepYrxwQRIg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;6asSIEJz7ggo9QEXpbSOYg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 4.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;6dwQWrojfQ/1hgTT2PQckg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;6o8ui0RxMttDzkyqTDO5tg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;75iSdAKFlPvTmCAp8d99YQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;76mWuVYhbmIFsc4DNorK9A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.0,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;76z9Mpn8Jp7lhZSPsHTHug==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.0,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;7AoZZiCMmvqX9d9WD62FnQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;7CfySs4FmTkWgJPjEar4eg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;7sGexlbSpX41SOBbWHg8BQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;8563iLEht/ghMGItALTFUw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.6,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;8efBqSZ3OYqd+nT8a21FNA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;8kndQj/aRn+NNJdGVP9v4g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;8zIRit7VqNRaBPLxL/+VAg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;93O9BjbBwz1jYmTNCzgkUw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;9GliauANgklOt4mKxwOygQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;9iADtyaox0PEZ/SbvPWJcw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;9iigvnuYDaC8UzcOIDLjIQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;9k9GsZftBlKIenK0IOSwoQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;9v8e/1gKgcwShm3I7m4SiQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;A+Jv9uRM/keGEYgIGq4WhQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;A/L5cxR0pUN6sSD1UL7wlw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;A1ZQfTMMpQF7G100W1c/Rg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;A2s8gCjK3uaWI7+q7M5Aog==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;AIlN8RmMOvhBveVuVAyHQQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;AKiLQ/xfYs8rccBZaw62bQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ALEb7ClqbpU4flidf9/9Vg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;AUiFITCnRjRxctzqqbDeeA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 3.3,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Ah03jmj/7fQOqUbg05PtZg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;AwUdH/KSEhHnx1nx0tagUQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;AzESlP5N9z0ume0UnpGELg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 4.7,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;BS5Qx6nN3HmM64VVoKmayw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;BTToHfvg0weSXCH9D0acFA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;            &#34;baseScore&#34;: 4.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;BaEDBo8YJd5pwSQNkGzAFg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 6.9,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;BfDjqoaYrd0NKCGGxtokTg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 4.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Bh96oSV9q0619slTJCaM0Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;BrupyHHgUisGe91mdtTkog==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;BtU7U8JaAB8UA19RIrHuHQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Bu9dxnhmsLXDd3x0oRPHfA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;C5z0AxIvQN3JdMLvMYB+qg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;CKAla6xchD1gy0q9ML/2xg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;CO6FDlFyRSUjPhv7/gdAAA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;CQPV/OxtJ+DwYc6C4gniNQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;CfMK+8nnfjDlpiJ86nDqnQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;D17rv5OxhiqZrK+otc1Xcg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;DDxCHnX+kCqcRQj9b90/cg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;DNd0sdbW83acQbIl3FDaPw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;DVhbZtpHlSM2ukk3QurV1w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;DXoWfwXPN9ZCvCU/obObKQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.0,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Di0hwt0owko/VaT8i7ICOw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Dif/+rLLCWjJt5Bzau2zsA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 3.3,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Dl7D7r3bnERvJ1K3e9T3bQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Ds5dBDqvRggZONNskvuAwg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;CHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;DsZp+BRVz/OTV0jFXHylmA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;DtkRUkQTzcJrj8ZsC36kqQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;CHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;DwTrtZS+niTc7qfIVCIZAQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;E69qsmSRl4PzNiueJkPUDw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 9.1,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;EOFhzMVjLzNyQsRKP/y6ag==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ElE6r7xQZAfd5MScs95BXQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ExqOQ5ldBNUvCH4EdaOK5w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 2.5,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;FAhn0w8CyRA5pQLzx0KOLg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;FInGJTEa3gToUzpaoDNNQw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 2.5,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;FMWVyBjC/IhzfdU57RFV5A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;FW+E40XkknH5Jv24oip5Ow==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;FroZeKbNhNx69+bj8o0OqQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;G/nM9FqgWuICAFy4kMmJlA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;GAn7gWUe2pFr7PbwechqxA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 4.7,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;GXMpRf2go/wGEbwpp9BPPQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.6,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;GfPY5zBbHJQI4ZGaDcJj2A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;GnBCRP9H+R6do428z3nOkQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Go9bB5Mq4W4FHPvmZKBhCg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Gv9SmnUKqHUi+G3vQah9BA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 9.1,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;H1wshPoazj8pmzsnWAztZA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;HHBOKYlzeD2Busv7btyBAA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 4.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;HSaKorahiaNwGqqE2DJSaw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;HlOu0EmTxHkjzmJeJEuJmw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Hoba3nMTEuYEZMkGsuPdgg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.9,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;HxI42iSjURjRki+uV6q/9w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;I3+uP7bb+nPtzRYHH2UUgw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;I3vwwgMxzxWo15otCOgvAw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;IF/pusRwq2cM2AL083HZhw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;CHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;IGF/2G1+7Y+pT7nmmFHvPw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;IPiVFeI45MBrWEz4KZcdQQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;IeTK1HBLKpS1+gfVSPrpvg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;J/M93jueASHywmph2g+HMg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;J1e16b0P6Tp2x5sVgsqutQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;J9gq9t3ASg6Sp5n2QRemEA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;JAlZO0sgdy1FBW5F7Zj+Pg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 2.5,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;JD0llI0bGUOG/VBz+9LeVQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 4.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;JmKf//IQj2eMVJFTB1Feyw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 4.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;JpVSLeyNGU9aXWuvL1lvmw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;JtGggrfMckWn0xvfWBMJJQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;K3SBN066vVckR2wFFfybNw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;KB8w2g8b8sP5A8+iqhqw8A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;KHHIjt6Egtc7csaIbQ3mbw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;KWRSi8vxblrZIdlqIEG3zA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;KYv6PwzjV6/5I33cZ9LUmQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Kpg8AKRn9eUVlQlRye20Tg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Kqq2xlybjD/tOLmQWu2xPw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.6,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Kr2KcyJfYQ8J1RDorzTofQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;KsboTEAsiwsdLEKIDivkyA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;LUQxjpYcQwxSDC7CX78VUw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;LdeUngez6mnzZ7ugJzuAmQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;LkJjju2s50oKpBRyBT8s0A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;            &#34;baseScore&#34;: 4.2,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Ly8YGlWm8+S4CYtF8Y/Htw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;M293c+QguJ/aaYP3cMwfyQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;M29Ot9TqS/JJH7ICJCbCog==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;MEeKHFVdv0EwpaMPKCy3Sw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;MIaYLvbJRWXm7UR3+CJ1PA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;MLyBE3p9/9+LMOMl2JBi6w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;MMLwOzBcCET4jaa3dPuTwQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;MqEiWiJF+vNoM9tbeG6KSw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;MtOwgWyogkVoNGuQavHN8g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;N6nQdxnBzns6IrsJM+Xsuw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;NKSXZUie8BGH5nwjKc1B6A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;NXO5f9Vv38zu/sOzuqBB9Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;NeZAaBfGrzLvaMKrJL7WlA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;NfiEOtFyxMslIq3QwoTtjQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;NrNei+pIM0R36v4Js8XxAg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;NxJdA8sdmOpi2KE8EaPazA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;O+92Gg/bs8C9EjretuiP8A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;OXr+UvfSDAQbLGP4xOBSMw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Ob+LJ5zYHnbjt14Yf8W7UA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;OwBRDeukhCJw3hE9ZsCdCg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;PD08BQc1tUldC8QSScd1aA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 9.4,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;PInmzCd2elAZed8XII2H3A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Pml3cIw2PYIOjBurBs3LFQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;PvgbBaq86gnOp8hffKEHhQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Pza9Y2xtH9MChVMkZwgw2A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Q0D37bmhhLGtYILIAMgFXg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Q2616MMrHflQbREkbaxMFg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Q6H4f5u2pbj98wlSQQLoGg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;QG/MLFKQxQOk84kYcs5X4A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;QX9gQ7esz1e73iQHmwojXA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;QaKFgrY/cUPl6Ls/xAwlFQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;QbgvVzhz2dr5BDvAUM6wFQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Qe1reyLPtQVZ5wKqKa9jQA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.6,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;QgRg8usqYLpC2SzTmhUKsQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;QmXO38HGjUD9lc3XwducGg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;CHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Qvw0/zOlMy3n6XUCrN6SmQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;CHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;R5XnexvMFgBiw/v8sY0BOA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          },&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;R7olSy1x/HelcHgr9AjG7A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;RATpPhLUqjEbe+XxyYxOOw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;RHShqbO2hqcBNPYbKDg/3A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;RI2wKrfD1EyE3/UfHBEmcA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;CHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;RRtBD+EuTLmzasgAaBJyZw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Rd2hVVbUws+mcvoC7DaoiQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Rd6dUUcujScJTEeiIRkyqw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 3.3,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;RzrQmVvfhyaExSlpoLqDzg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 9.1,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;S5Dzz9cigoJDCj8s5UcT0g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;SGRK/IsCkjX097oRuDhiEQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 2.5,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;SIuaHC7QSLhT9Coo7Xm2hA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;SJA+1v6mehbGh4JXJ2n5jA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;SQcVquEPU3fE4fDQPb3bLQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 2.5,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ScOp6HuJxBp54FxFpTVDnA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;SvhQ7tNvl6ANrVnaJ4cBNw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Sygyk9+T2DbXETLWiB21dA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;T5Nghm4crNWWnUrYvZZItg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;T7eVCD5Gwe0DXPZP59mQUQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;TIcWaTRsDD52irGN4xUQyA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;TL19l7Dr/wLwmp6malQ4FQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;TSYnGqVe9WLIg9cR9McW7A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;TT6ujth4uzblGI4VcnKBOw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;TZnGp6lc5MuTXKrvF6Ln8Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;TsVNXuAeF3PhiRZhIOjjtQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;CHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;U6rJ6LmaVlYRjI8Lq/aM/A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;U8pdHlQlr/x1RsdiZ3YQOg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;UBzPfwycyyJOBETwdSTG/w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 4.7,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;UG+yX6nADJgJWegetH+HQg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Uk5o/hpaP3fKN3OvrwIC+w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.9,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Ur6VVwVyUIHSLLbySiZhfA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;V1rPWqhvOrQycOtSN8Ve9g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;VJENPcmZwV+YJWnk88f2ug==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;VWEbeFnFOHy1IkG21b5a5g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;VgtQ3XmdoIWt3qbuW7WZzQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 9.1,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Vm1exr1mz0tcpwIoZQ3ySQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;VuDrFzex6yJBFISXUtfUGQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 3.3,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;VvaHtDrsl/vKtefhsm7IUA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;VwRZMkFc1pqkTIff/cjZtQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;W0TAw6aTfwXOMlJwloDkZA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;W3SNJz91vyAPBvH2kz/itQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;WbtmlW8SfW38NUPRnGwbsA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;WjQCog+GPmCa3VQIGXKhRg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.2,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;X10PEbhI2yv6KYFUPacecg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;X4Ym25zfqcH7/samBN+yPw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;X8OJykaOJlN5EhVA7Y11uQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;XIh88yJoOK2Ff8cGZL7F+g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;XKTHMaJwDxmLjk9FkUhg8Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;XL1Nv8y45q8aiA92A99YyA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;XPUXyp+BOEJyEGOgXafi8Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;XQDeROSRzMSiFTbbLCST/A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;XW4X9/W6MfETfE/VICA4Jw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 4.7,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;XkiVaSOj/tcz5wNKnglN4w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.3,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;XuMP4XKeqFlYH9jgvFKXXw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Xvp9bEwIvwUrD61DySkWgA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Y/6FiFNJ+h2jXNTlPOzrnQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Y1YZsYV7ls1vsluhREpXlw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Y6TEBwH0+CoZ50j5sQV23w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.0,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;YKgthSAonF3epY42eqsMRw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;YQGeiQ1baJrwVuNrCjd79A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;YR9IlxlHBBSlj3ZLdc6/eQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;YSP3jWIJP4TspvpKDx/wvA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.1,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;YUwZZ9Cg1FloxBZV60vOCg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;YdpqbsRbo4xx71CiWUF39Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;YgehfkOilPM31dosmRXxDA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Ywdulqdw8k75jjL2qb8gPg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Z/nuiLo/kSAcxolOXcSWYw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;Z0bbSkX8e3OUKdJa86CbBw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 3.3,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ZCLP8N4soyt53A9I5VdxcA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 2.5,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ZNpRshLHRo06/00CGV605Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ZRSF+MayCxLJlIAPWIqUVA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ZuhhG1bpyIKZ8+BvJQvoUQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;a8Muru+syePTNtU2/rVrUg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;aJsQ4a3gp8/jsNBVC56QHw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;aK9Mq6KdK8L3Pl0r1rTwYA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;aN7J4vjcApPz2ZabMR0Irg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;aOUfuyvyyWEe7Z1IZT+fGw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;axpLUf/WfpliDV7UixDwiQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;b1aMkFsUYzQ15fp9A4JV2w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 9.1,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;b2xf65/2S45gOxG8Grxy0g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;bACUKZThWu3kcO82NfO4eg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;bHbadSMaYCdCzwHNWG3fzw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;bJGGlc8FG/c2T93ktUh6Ig==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;bbylqjYpcbE9/Bm4AdduVQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;bf41zTvm6HAv6xdiXpwGWQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 3.8,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;CHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;bh7RRRlNP555+LOFASdB0w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;bk6ikdg+f6vAFzgypr0cOw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;boWBDvSNZPI7kiGalqeu1g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;bpwdCug2xQZhmaazCqwIew==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.0,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;c2gL4Z8Tbc2Ge5iwCDCV9Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;c76DQiDMr2npmMChLqBaow==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;cMY+6QfPqyOZE380Mf5rIQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;cQ4uQyL9nbrYK9Ka1PjEaQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;cQHSxL+ZfKCYmJnTVIzcRw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;cXB5uJOI3UJ7dOyNiQwFDg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;cly/G/AvUZQM2J1YMymkpQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;cxMZ2TEnkk6RdtuU9fDThg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;czyzjx8xL/qpVEGcPiV7Og==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.8,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;CHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;d28O4EsS+H4v4JSsIykoOg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;d9oy2JiAKtie2N1lu2J6ew==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;dO/rj/SVo/ZlfJAB2ajOEQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;dOcg60kDi70nJl9Km2ugWQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 3.3,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;dTHv7xNEey4Rvi0jaC90Ng==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;dtQx2uUyC6Kj72i0o1bELQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;e+FXR06J5tPREKXnCKeZWg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;e/bnYsWq3UNe4TO8qzzb8A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;e7h3lwyDkLbzwbeza9/TWw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;eZAX5+dryNgqi55C7fN1LQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;edQImQW6OalMt0U0nrXR2Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;eekbTUpqIafepE8Hfmhn6g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;eiMh0pZiJlWSr3FHHfVKhg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;f6JDKuVN2cqa3h32gmRjXA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;fKu2JVqQCl/zwzvO3uUkJw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;fPh6cJ7fj6ecJeD/S/iyJg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;fSeU4QTAs+fY+ihLpgdM9A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;fqP9GV2+ELPjUr/DY2avpQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;fzE91AQotuZJ8swhDTTd+g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;g6spFzT6DoopzuQCE0pjRg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;gGrGej/Pj6/poAgebFb+dg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;gNGv6C2nj/tHk2ntVJUOWw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;gSYlqWWhsq36L2EzWb/x+w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;gpPTgXxcA95Uk2vaf3/2dw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 4.2,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;ADJACENT_NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;HIGH&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;guG+lyS5JQIDSZS6MEfIow==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;h+nOQU6khNxAH7kkGqVqkQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;hLNqQASPtA3T5zDQurOMBA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;hLbfRT5oTN6ilWiJVmH5Uw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;hMMTiPhU7F2ErldK8mMkDQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;hUC86VV8kD262xFcev0ZiA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;haEbUAG+u1TE1V7073rUjA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;hxluEp8Si16NQcfaJDWcLg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;hxsQAGbTfRAveju4VaX/RA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;i6aHe7Qjo768bvS9xSorFw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;i9sUrKKUObLH200e/JvjcA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;iCq8lbTZO3yBSlU4d4JPMQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;iF/o4aDbQf1DAw7R+LiVQw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 4.7,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;iFdXYPdbzmitrrthD7u8yA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;iT0wLV5um6Novvux5XEDSA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;iYahLjRBvYk4Zq4Nz9JtHg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;idDdN00zXJT8ntMCqQfdkA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;iwe2PkNe91EUwDENn+pmew==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          },&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.1,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ixD2h349uZz3eCy55KxIlw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ixc06f0H9vqMfsbwQSwwvA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;j71n+HvL+1UIm3Tw+EUHpw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;j7yoSCks+i8LevHtgFwCwQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;jVOV80BPiMF1EYk2uq9ohg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;jVeIQzIm92EdkbCIlGT1qA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;jiVVTQmOtKqVixv7agF/Hg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;jw+r2jbroWxBcAHcFZs/eg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;kR9Bs/gd2Qm09J0HnMmVzg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.6,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;kTyfGInwWoCVv7gGPYCF5g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;kaUbMItvWrS1leJMEsAk9A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;kuuz4akZvpNKTf2txpaWog==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;kxWAVe7EWU20jParQphcRA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;lCc1jyHfsFJK2HfULjN8pA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;lFQcTCheSGIjEbZVivulnA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;lFfYg6015iTLGI5pZVMU7w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.2,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;lHLNxD93t7uUJfmDhNwvCQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;lJ8RTw7m+AgAnWW6upSntA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;lNSOU9e0rQLWWUuG6KmS+w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 9.4,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;lWdVDKK0NI1ECjrQyrQZhA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;lz6O0nYiDpis8SScmTUuSg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;m9ROycwLgAur/M8HFSigEw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;mJw+LvAbCoVMIOZXCXNFpg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.6,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;mXoGTWRL/KLyEYWh5uyvXQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;mXtaaJBTQTZ/zl5a00GqaA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;mZC3gBcn6x1aC7q9hXUpKg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;mZCCwO//htsOIXazj/SeOw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;mllkaOQAaJYNZpdIF7Bkbw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;mmFI4mA7exd6BfbwTUwJfQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;mwfwMX3+sIJWibPk7jkY/Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;n39YhRffL6tFFAy/S18A8Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;nZ2DFaqiaft4/Dqj5SJp4Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;novhorrUhD5n0pl3qmImIw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;o16kBwzDyL2DXuhbCPWX9Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.7,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;o8O4Ttqnv0lQfm1yyfyVsw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;oGYbR6FNz1KIQ8VJiypCZg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;oGhsPyoyEtiEHT7/0qF+CQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;oIBUxFCAPk4vRXBwpcmtFw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;oVgcRSL89qnSRkMXpV8N8A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;oxSfxLnytv2y2gHjvplCuw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;oyvtOIVUDqm1ruQx8vhRhA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;p8wzfQhvimCzJ24LCz0qSQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;pOKoOa+tppgNwBAEgYrxlg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;pe4Shj+F17XwL0468/ASsg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;q59Dz6hmc7o1qITDwl3CCw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;q5joCCZ2cOTa0rXBUtiSpQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;q7c6mw4iAmau1l6sfNLk8w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;qEhRdzGH44SGjJIcqcIv/g==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;qIj6aIlqGJtvbX658qTpDQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;qN6ac9Xwm6AOaO1fAB7fOQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.1,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;qWK7H7gz7e8gS19GJSeIIg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;qYORp6v9x0Jy6S8OKerZvw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;qn72KaShSoWOaJmw6qKS3Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;qug1advw8m4TjVAUPEUPiA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;r3RLKNYtYvKarBqnnrlrew==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;r410Z5X0yojDsVg9YVcNqQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;rJljaCTiTdw1uI1lvfy+hw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.6,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;rO5a9fYyaqaIZ4bH0M8fdA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;rR226S9SV4WbmIVotM0CsQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;rWO0jZdArYZ9zSTLMe8r8w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;rjcajgsmKA8I5yMLMT8DHg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;rlHsuoluzmy30odv/xIILA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 2.5,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;rxGz0C3kTCQwThekjofucw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L&#34;,&#xA;            &#34;baseScore&#34;: 6.9,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;rzmoKvIFGvuPP0SzaH7s9w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;s2uSNGuV+OyVW2eHDGWWKw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 4.4,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;s6kt2DqKLHgzYSGciPtGtQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;sROfYAX8Ekl+9at4JgS5Lg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;tLSR0X6hQ7hvyPbBXZslBQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;tOOsPkEJCdO66XvUUd+xnQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;tUTc+tWHx1wVpIbeqTmR0w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;tbhLz74i3ShwS72WbIsoOA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;tbkEtEs3aa+p2/YQaD8BfQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 6.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;tuPGTYWKd0OWuEIwEsNtuA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 9.8,&#xA;            &#34;baseSeverity&#34;: &#34;CRITICAL&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;u1caIbS4Tk6y8c7sz8Hvhw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;uDfc8ZaPfrhTGcFwVaIvAA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 4.7,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;uEn9qA67O/SoYHOtH/EL2w==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 3.1,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;uLJc9xWoMs4KcjASTFLV/A==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;uO3OOEY6W3k9QH/tNVK0LQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 3.7,&#xA;            &#34;baseSeverity&#34;: &#34;LOW&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;uPUnbuUJlh23l0km8iQ2tA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;uaetuJImncB6wudykQLpEA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;vFpvBSl3ZcIap1nZTTjWsg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;vSLFgRYoehmDve19rxyjcw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;vTajNh0ysqaO8NuTMU//uw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;vkypiN/HZjIiT/S9k2qxvA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;w1094TrprBpG+5TZJus6FA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;w8af/LTYrBLWhYkZBSi2Lg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;wM3p6vKgVqUkJtSPSQjDlw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;wp75ZuWMdeSuJ4xUhgowQA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;xC8Y7thfNSAfn5daCQFvgQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;xQ6R88+x8IssPvOAavmZXw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;xh8zszQflFXgahc/vYUUWQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;xvCKE5h7HgdGkBMwA/kPeg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N&#34;,&#xA;            &#34;baseScore&#34;: 6.1,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;CHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;y6oEGtDp1H5C2csZKAF6bQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;yNrm+PctJj5AEVwT8bDpBg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ylg3k+AtgUcIl3hJiXNMlw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;ymZOc8rtV2bmln3PExOD3Q==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;yyVb0QTi/Vc4LSIxOEuhqA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N&#34;,&#xA;            &#34;baseScore&#34;: 7.4,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;NONE&#34;&#xA;          }&#xA;        ],&#xA;        &#34;zAQhwfD+1kpXY0CwZC6HxA==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H&#34;,&#xA;            &#34;baseScore&#34;: 5.5,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;LOW&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;LOW&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;zDmU3WG0c3AQYw7NFebUCQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.8,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;LOCAL&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;REQUIRED&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;zE3cPdw4Ma9jQQUVeE/hdg==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H&#34;,&#xA;            &#34;baseScore&#34;: 8.1,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;HIGH&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;HIGH&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;zXyE3S2RgbWC3bSm5zxzpw==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&#34;,&#xA;            &#34;baseScore&#34;: 5.3,&#xA;            &#34;baseSeverity&#34;: &#34;MEDIUM&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;LOW&#34;&#xA;          }&#xA;        ],&#xA;        &#34;zY7J45b8Kt4bFIMHib/PGQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ],&#xA;        &#34;zx97OaxgXH8j+mFWesQySQ==&#34;: [&#xA;          {&#xA;            &#34;version&#34;: &#34;3.1&#34;,&#xA;            &#34;vectorString&#34;: &#34;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&#34;,&#xA;            &#34;baseScore&#34;: 7.5,&#xA;            &#34;baseSeverity&#34;: &#34;HIGH&#34;,&#xA;            &#34;attackVector&#34;: &#34;NETWORK&#34;,&#xA;            &#34;attackComplexity&#34;: &#34;LOW&#34;,&#xA;            &#34;privilegesRequired&#34;: &#34;NONE&#34;,&#xA;            &#34;userInteraction&#34;: &#34;NONE&#34;,&#xA;            &#34;scope&#34;: &#34;UNCHANGED&#34;,&#xA;            &#34;confidentialityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;integrityImpact&#34;: &#34;NONE&#34;,&#xA;            &#34;availabilityImpact&#34;: &#34;HIGH&#34;&#xA;          }&#xA;        ]&#xA;      }&#xA;    ]&#xA;  },&#xA;  &#34;PackageNotVulnerable&#34;: {}&#xA;}&#xA;&#xA;pod: component-prefetch-bundler-on-pull-request-ncd7p-clair-scan-pod | container step-oci-attach-report: &#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;Attaching clair-report-amd64.json to quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler@sha256:1806486990f86738e26ea4751f25cd961b841d64af0fffe4c91affa4f2d116f9&#xA;[retry] executing: oras attach --no-tty --format go-template=\{\{.digest\}\} --registry-config /tmp/auth/config.json --artifact-type application/vnd.redhat.clair-report+json quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler@sha256:1806486990f86738e26ea4751f25cd961b841d64af0fffe4c91affa4f2d116f9 clair-report-amd64.json:application/vnd.redhat.clair-report+json&#xA;&#xA;pod: component-prefetch-bundler-on-pull-request-ncd7p-clair-scan-pod | container step-conftest-vulnerabilities: &#xA;[&#xA;&#x9;{&#xA;&#x9;&#x9;&#34;filename&#34;: &#34;/tekton/home/clair-result-amd64.json&#34;,&#xA;&#x9;&#x9;&#34;namespace&#34;: &#34;required_checks&#34;,&#xA;&#x9;&#x9;&#34;successes&#34;: 4,&#xA;&#x9;&#x9;&#34;warnings&#34;: [&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found packages with high vulnerabilities associated with RHSA fixes. Consider updating to a newer version of those packages, they may no longer be affected by the reported CVEs.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Vulnerabilities found: libpq-devel-13.20-1.el9_5 (CVE-2026-6477), nodejs-full-i18n-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2025-55130, CVE-2025-55131, CVE-2025-59465, CVE-2026-12151, CVE-2026-13149, CVE-2026-1526, CVE-2026-1528, CVE-2026-21710, CVE-2026-2229, CVE-2026-27135, CVE-2026-42338, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874), gnutls-3.8.3-9.el9 (CVE-2026-33845, CVE-2026-33846, CVE-2026-42009, CVE-2026-42010), npm-1:10.9.3-1.22.19.0.2.module+el9.6.0+23473+45664c2d (CVE-2025-55130, CVE-2025-55131, CVE-2025-59465, CVE-2026-12151, CVE-2026-13149, CVE-2026-1526, CVE-2026-1528, CVE-2026-21710, CVE-2026-2229, CVE-2026-27135, CVE-2026-42338, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874), ruby-libs-3.3.8-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), ruby-default-gems-3.3.8-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), nodejs-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2025-55130, CVE-2025-55131, CVE-2025-59465, CVE-2026-12151, CVE-2026-13149, CVE-2026-1526, CVE-2026-1528, CVE-2026-21710, CVE-2026-2229, CVE-2026-27135, CVE-2026-42338, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874), libbrotli-1.0.9-7.el9_5 (CVE-2025-6176), rubygem-irb-1.13.1-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), glib2-2.68.4-18.el9_7 (CVE-2026-58016), libnghttp2-1.43.0-6.el9 (CVE-2026-27135), glib2-devel-2.68.4-18.el9_7 (CVE-2026-58016), bsdtar-3.5.3-6.el9_6 (CVE-2026-4111, CVE-2026-4424), go-srpm-macros-3.6.0-12.el9_7 (CVE-2025-61726, CVE-2026-25679), vim-minimal-2:8.2.2637-23.el9_7 (CVE-2026-33412, CVE-2026-34982), ruby-3.3.8-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), libtiff-4.4.0-15.el9_7.2 (CVE-2026-12912, CVE-2026-4775), rubygem-io-console-0.7.1-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), nodejs-docs-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2025-55130, CVE-2025-55131, CVE-2025-59465, CVE-2026-12151, CVE-2026-13149, CVE-2026-1526, CVE-2026-1528, CVE-2026-21710, CVE-2026-2229, CVE-2026-27135, CVE-2026-42338, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874), openssh-clients-8.7p1-46.el9 (CVE-2026-3497, CVE-2026-35385, CVE-2026-60002), rubygem-bigdecimal-3.1.5-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), rubygem-rdoc-6.6.3.1-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), openssl-libs-1:3.5.1-4.el9_7 (CVE-2025-15467, CVE-2026-45447), nodejs-libs-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2025-55130, CVE-2025-55131, CVE-2025-59465, CVE-2026-12151, CVE-2026-13149, CVE-2026-1526, CVE-2026-1528, CVE-2026-21710, CVE-2026-2229, CVE-2026-27135, CVE-2026-42338, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874), expat-2.5.0-5.el9_7.1 (CVE-2026-45186), libpng-2:1.6.37-12.el9 (CVE-2025-64720, CVE-2025-65018, CVE-2025-66293, CVE-2026-25646), rubygem-json-2.7.2-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), libpq-13.20-1.el9_5 (CVE-2026-6477), libacl-2.3.1-4.el9 (CVE-2026-54369), rubygem-bundler-2.5.22-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), vim-filesystem-2:8.2.2637-23.el9_7 (CVE-2026-34982), rubygem-rake-13.1.0-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), libcap-2.48-10.el9 (CVE-2026-4878), libpng-devel-2:1.6.37-12.el9 (CVE-2025-64720, CVE-2025-65018, CVE-2025-66293, CVE-2026-25646), python3-libs-3.9.23-2.el9 (CVE-2026-11940, CVE-2026-15308, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100), brotli-devel-1.0.9-7.el9_5 (CVE-2025-6176), brotli-1.0.9-7.el9_5 (CVE-2025-6176), openssl-devel-1:3.5.1-4.el9_7 (CVE-2025-15467, CVE-2026-45447), rubygem-psych-5.1.2-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), python3-3.9.23-2.el9 (CVE-2026-11940, CVE-2026-15308, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100), python3-urllib3-1.26.5-6.el9 (CVE-2025-66418, CVE-2025-66471, CVE-2026-21441, CVE-2026-44432), libtiff-devel-4.4.0-15.el9_7.2 (CVE-2026-12912, CVE-2026-4775), ruby-bundled-gems-3.3.8-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), openssh-8.7p1-46.el9 (CVE-2026-3497, CVE-2026-35385, CVE-2026-60002), rsync-3.2.5-3.el9 (CVE-2026-29518, CVE-2026-41035, CVE-2026-43618), gnupg2-2.3.3-4.el9 (CVE-2025-68973), ruby-devel-3.3.8-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258), libarchive-3.5.3-6.el9_6 (CVE-2026-4111, CVE-2026-4424), openssl-1:3.5.1-4.el9_7 (CVE-2025-15467, CVE-2026-45447), rubygems-3.5.22-4.module+el9.7.0+23096+6a95897f (CVE-2026-41316, CVE-2026-42246, CVE-2026-42258)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;clair_high_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 183&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found packages with unpatched high vulnerabilities. These vulnerabilities don&#39;t have a known fix at this time.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Vulnerabilities found: curl-minimal-7.76.1-34.el9 (CVE-2026-8286, CVE-2026-8458, CVE-2026-8927, CVE-2026-9547), vim-minimal-2:8.2.2637-23.el9_7 (CVE-2026-73078), sqlite-libs-3.34.1-9.el9_7 (CVE-2026-51298), openssh-clients-8.7p1-46.el9 (CVE-2026-59999), vim-filesystem-2:8.2.2637-23.el9_7 (CVE-2026-73078), libcurl-minimal-7.76.1-34.el9 (CVE-2026-8286, CVE-2026-8458, CVE-2026-8927, CVE-2026-9547), openssh-8.7p1-46.el9 (CVE-2026-59999)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;clair_unpatched_high_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 13&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found packages with medium vulnerabilities associated with RHSA fixes. Consider updating to a newer version of those packages, they may no longer be affected by the reported CVEs.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Vulnerabilities found: libpq-devel-13.20-1.el9_5 (CVE-2025-12818), nodejs-full-i18n-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2025-55132, CVE-2025-59466, CVE-2026-1525, CVE-2026-21637, CVE-2026-25547, CVE-2026-26996, CVE-2026-27904, CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934, CVE-2026-9678), glibc-langpack-en-2.34-231.el9_7.2 (CVE-2026-4046, CVE-2026-4437, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), gnutls-3.8.3-9.el9 (CVE-2025-14831, CVE-2026-3833, CVE-2026-42011, CVE-2026-42012, CVE-2026-42013, CVE-2026-42014, CVE-2026-42015, CVE-2026-5260), libmount-devel-2.37.4-21.el9 (CVE-2025-14104), npm-1:10.9.3-1.22.19.0.2.module+el9.6.0+23473+45664c2d (CVE-2025-55132, CVE-2025-59466, CVE-2026-1525, CVE-2026-21637, CVE-2026-25547, CVE-2026-26996, CVE-2026-27904, CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934, CVE-2026-9678), ruby-libs-3.3.8-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), ruby-default-gems-3.3.8-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), libxslt-1.1.34-13.el9_6 (CVE-2023-40403, CVE-2025-10911), libxslt-devel-1.1.34-13.el9_6 (CVE-2023-40403, CVE-2025-10911), nodejs-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2025-55132, CVE-2025-59466, CVE-2026-1525, CVE-2026-21637, CVE-2026-25547, CVE-2026-26996, CVE-2026-27904, CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934, CVE-2026-9678), glibc-2.34-231.el9_7.2 (CVE-2026-0915, CVE-2026-4046, CVE-2026-4437, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), curl-minimal-7.76.1-34.el9 (CVE-2025-9086), glibc-headers-2.34-231.el9_7.2 (CVE-2026-4046, CVE-2026-4437, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), libblkid-2.37.4-21.el9 (CVE-2025-14104), glibc-locale-source-2.34-231.el9_7.2 (CVE-2026-4046, CVE-2026-4437, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), p11-kit-trust-0.25.3-3.el9_5 (CVE-2026-13757, CVE-2026-2100), rubygem-irb-1.13.1-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), glib2-2.68.4-18.el9_7 (CVE-2025-13601, CVE-2025-14087, CVE-2025-14512), libnghttp2-1.43.0-6.el9 (CVE-2026-58055), systemd-252-55.el9_7.2 (CVE-2025-4598, CVE-2026-29111), glib2-devel-2.68.4-18.el9_7 (CVE-2025-13601, CVE-2025-14087, CVE-2025-14512), bsdtar-3.5.3-6.el9_6 (CVE-2026-14164, CVE-2026-5121), libsolv-0.7.24-3.el9 (CVE-2026-48864), vim-minimal-2:8.2.2637-23.el9_7 (CVE-2026-25749, CVE-2026-28421, CVE-2026-41411), ruby-3.3.8-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), util-linux-2.37.4-21.el9 (CVE-2025-14104), krb5-libs-1.21.1-8.el9_6 (CVE-2026-40355, CVE-2026-40356), libfdisk-2.37.4-21.el9 (CVE-2025-14104), rubygem-io-console-0.7.1-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), nodejs-docs-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2025-55132, CVE-2025-59466, CVE-2026-1525, CVE-2026-21637, CVE-2026-25547, CVE-2026-26996, CVE-2026-27904, CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934, CVE-2026-9678), openssl-fips-provider-3.0.7-8.el9 (CVE-2026-31790), binutils-gold-2.35.2-67.el9 (CVE-2025-11083), binutils-2.35.2-67.el9 (CVE-2025-11083), libcurl-devel-7.76.1-34.el9 (CVE-2025-9086), openssh-clients-8.7p1-46.el9 (CVE-2025-61984, CVE-2025-61985, CVE-2026-35414, CVE-2026-55653, CVE-2026-55655, CVE-2026-59996), rubygem-bigdecimal-3.1.5-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), rubygem-rdoc-6.6.3.1-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), openssl-libs-1:3.5.1-4.el9_7 (CVE-2025-11187, CVE-2025-69419, CVE-2026-28390, CVE-2026-31790, CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-45445), libgcrypt-1.10.0-11.el9 (CVE-2026-41989), nodejs-libs-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2025-55132, CVE-2025-59466, CVE-2026-1525, CVE-2026-21637, CVE-2026-25547, CVE-2026-26996, CVE-2026-27904, CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934, CVE-2026-9678), libblkid-devel-2.37.4-21.el9 (CVE-2025-14104), systemd-rpm-macros-252-55.el9_7.2 (CVE-2025-4598, CVE-2026-29111), libsmartcols-2.37.4-21.el9 (CVE-2025-14104), libpng-2:1.6.37-12.el9 (CVE-2026-22695, CVE-2026-22801, CVE-2026-33416, CVE-2026-33636), rubygem-json-2.7.2-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), libpq-13.20-1.el9_5 (CVE-2025-12818), glibc-minimal-langpack-2.34-231.el9_7.2 (CVE-2026-4046, CVE-2026-4437, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), rubygem-bundler-2.5.22-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), libmount-2.37.4-21.el9 (CVE-2025-14104), rubygem-rake-13.1.0-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), libpng-devel-2:1.6.37-12.el9 (CVE-2026-22695, CVE-2026-22801, CVE-2026-33416, CVE-2026-33636), libcurl-minimal-7.76.1-34.el9 (CVE-2025-9086), python3-libs-3.9.23-2.el9 (CVE-2025-12084, CVE-2025-15366, CVE-2025-15367, CVE-2025-6069, CVE-2025-8291, CVE-2026-0865, CVE-2026-1299), acl-2.3.1-4.el9 (CVE-2026-54370), glibc-common-2.34-231.el9_7.2 (CVE-2026-4046, CVE-2026-4437, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), glibc-devel-2.34-231.el9_7.2 (CVE-2026-4046, CVE-2026-4437, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), util-linux-core-2.37.4-21.el9 (CVE-2025-14104), glibc-gconv-extra-2.34-231.el9_7.2 (CVE-2026-4046, CVE-2026-4437, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), openssl-devel-1:3.5.1-4.el9_7 (CVE-2025-11187, CVE-2025-69419, CVE-2026-28390, CVE-2026-31790, CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-45445), rubygem-psych-5.1.2-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), python3-3.9.23-2.el9 (CVE-2025-12084, CVE-2025-15366, CVE-2025-15367, CVE-2025-6069, CVE-2025-8291, CVE-2026-0865, CVE-2026-1299), python3-urllib3-1.26.5-6.el9 (CVE-2026-44431), ruby-bundled-gems-3.3.8-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), openssh-8.7p1-46.el9 (CVE-2025-61984, CVE-2025-61985, CVE-2026-35414, CVE-2026-55653, CVE-2026-55655, CVE-2026-59996), libuuid-2.37.4-21.el9 (CVE-2025-14104), python3-idna-2.10-7.el9_4.1 (CVE-2026-45409), rsync-3.2.5-3.el9 (CVE-2024-12086, CVE-2025-10158), systemd-libs-252-55.el9_7.2 (CVE-2025-4598, CVE-2026-29111), coreutils-single-8.32-39.el9 (CVE-2025-5278), tar-2:1.34-7.el9 (CVE-2025-45582), p11-kit-0.25.3-3.el9_5 (CVE-2026-13757, CVE-2026-2100), ruby-devel-3.3.8-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245), systemd-pam-252-55.el9_7.2 (CVE-2025-4598, CVE-2026-29111), libarchive-3.5.3-6.el9_6 (CVE-2026-14164, CVE-2026-5121), openssl-1:3.5.1-4.el9_7 (CVE-2025-11187, CVE-2025-69419, CVE-2026-28390, CVE-2026-31790, CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-45445), openssl-fips-provider-so-3.0.7-8.el9 (CVE-2026-31790), rubygems-3.5.22-4.module+el9.7.0+23096+6a95897f (CVE-2025-24294, CVE-2025-58767, CVE-2026-42245)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;clair_medium_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 281&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found packages with unpatched medium vulnerabilities. These vulnerabilities don&#39;t have a known fix at this time.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Vulnerabilities found: xz-libs-5.2.5-8.el9_0 (CVE-2026-34743), glibc-langpack-en-2.34-231.el9_7.2 (CVE-2026-6368, CVE-2026-6791), python3-pip-wheel-21.3.1-1.el9 (CVE-2023-45803, CVE-2025-50181, CVE-2025-50182, CVE-2026-13346, CVE-2026-25645, CVE-2026-32284, CVE-2026-45409), glibc-2.34-231.el9_7.2 (CVE-2026-6368, CVE-2026-6791), curl-minimal-7.76.1-34.el9 (CVE-2025-13034, CVE-2025-14017, CVE-2026-11856, CVE-2026-1965, CVE-2026-3783, CVE-2026-3784, CVE-2026-4873, CVE-2026-5545, CVE-2026-5773, CVE-2026-6253, CVE-2026-6429, CVE-2026-7168, CVE-2026-8924, CVE-2026-8932), libblkid-2.37.4-21.el9 (CVE-2026-13595, CVE-2026-27456), glib2-2.68.4-18.el9_7 (CVE-2026-1484, CVE-2026-1489, CVE-2026-15588, CVE-2026-16118, CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015), systemd-252-55.el9_7.2 (CVE-2026-4105), harfbuzz-2.7.4-10.el9 (CVE-2026-22693), gawk-5.1.0-6.el9 (CVE-2026-40467, CVE-2026-40468, CVE-2026-40553), libsolv-0.7.24-3.el9 (CVE-2026-9149, CVE-2026-9150), vim-minimal-2:8.2.2637-23.el9_7 (CVE-2025-29768, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420, CVE-2026-39881, CVE-2026-42307, CVE-2026-44656, CVE-2026-45130, CVE-2026-52859, CVE-2026-55892, CVE-2026-57451, CVE-2026-57452, CVE-2026-59857), util-linux-2.37.4-21.el9 (CVE-2026-13595, CVE-2026-27456), krb5-libs-1.21.1-8.el9_6 (CVE-2026-11850), libfdisk-2.37.4-21.el9 (CVE-2026-13595, CVE-2026-27456), openssl-fips-provider-3.0.7-8.el9 (CVE-2026-2673), binutils-gold-2.35.2-67.el9 (CVE-2021-20197, CVE-2021-45078, CVE-2025-11081, CVE-2025-11082, CVE-2025-5245, CVE-2025-7545, CVE-2026-15003, CVE-2026-19548, CVE-2026-6844, CVE-2026-6845), binutils-2.35.2-67.el9 (CVE-2021-20197, CVE-2021-45078, CVE-2025-11081, CVE-2025-11082, CVE-2025-5245, CVE-2025-7545, CVE-2026-15003, CVE-2026-19548, CVE-2026-6844, CVE-2026-6845), openssh-clients-8.7p1-46.el9 (CVE-2023-51767, CVE-2025-32728, CVE-2026-59995, CVE-2026-59997, CVE-2026-59998, CVE-2026-60000, CVE-2026-60001), openssl-libs-1:3.5.1-4.el9_7 (CVE-2026-2673), libxml2-2.9.13-14.el9_7 (CVE-2026-0990, CVE-2026-11979, CVE-2026-1757, CVE-2026-6653, CVE-2026-6732), gzip-1.12-1.el9 (CVE-2026-41991), expat-2.5.0-5.el9_7.1 (CVE-2026-32776, CVE-2026-32777, CVE-2026-32778, CVE-2026-50219, CVE-2026-56131, CVE-2026-56132, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407, CVE-2026-56412), bzip2-1.0.8-10.el9_5 (CVE-2026-42250), systemd-rpm-macros-252-55.el9_7.2 (CVE-2026-4105), libsmartcols-2.37.4-21.el9 (CVE-2026-13595, CVE-2026-27456), libpng-2:1.6.37-12.el9 (CVE-2025-28164, CVE-2025-64505, CVE-2025-64506, CVE-2026-34757), glibc-minimal-langpack-2.34-231.el9_7.2 (CVE-2026-6368, CVE-2026-6791), attr-2.5.1-3.el9 (CVE-2026-54371), libmount-2.37.4-21.el9 (CVE-2026-13595, CVE-2026-27456), vim-filesystem-2:8.2.2637-23.el9_7 (CVE-2025-29768, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420, CVE-2026-39881, CVE-2026-42307, CVE-2026-44656, CVE-2026-45130, CVE-2026-52859, CVE-2026-55892, CVE-2026-57451, CVE-2026-57452, CVE-2026-59857), sed-4.8-9.el9 (CVE-2026-5958), libcurl-minimal-7.76.1-34.el9 (CVE-2025-13034, CVE-2025-14017, CVE-2026-11856, CVE-2026-1965, CVE-2026-3783, CVE-2026-3784, CVE-2026-4873, CVE-2026-5545, CVE-2026-5773, CVE-2026-6253, CVE-2026-6429, CVE-2026-7168, CVE-2026-8924, CVE-2026-8932), python3-libs-3.9.23-2.el9 (CVE-2025-11468, CVE-2025-12781, CVE-2025-13837, CVE-2025-15282, CVE-2025-4516, CVE-2026-0672, CVE-2026-11972, CVE-2026-1502, CVE-2026-3276, CVE-2026-3644, CVE-2026-4224, CVE-2026-42308, CVE-2026-4360, CVE-2026-5713, CVE-2026-6019, CVE-2026-7210), xz-5.2.5-8.el9_0 (CVE-2026-34743), glibc-common-2.34-231.el9_7.2 (CVE-2026-6368, CVE-2026-6791), tpm2-tss-3.2.3-1.el9 (CVE-2024-29040), util-linux-core-2.37.4-21.el9 (CVE-2026-13595, CVE-2026-27456), glibc-gconv-extra-2.34-231.el9_7.2 (CVE-2026-6368, CVE-2026-6791), pam-1.5.1-26.el9_6 (CVE-2026-12610, CVE-2026-54411), python3-3.9.23-2.el9 (CVE-2025-11468, CVE-2025-12781, CVE-2025-13837, CVE-2025-15282, CVE-2025-4516, CVE-2026-0672, CVE-2026-11972, CVE-2026-1502, CVE-2026-3276, CVE-2026-3644, CVE-2026-4224, CVE-2026-42308, CVE-2026-4360, CVE-2026-5713, CVE-2026-6019, CVE-2026-7210), openssh-8.7p1-46.el9 (CVE-2023-51767, CVE-2025-32728, CVE-2026-59995, CVE-2026-59997, CVE-2026-59998, CVE-2026-60000, CVE-2026-60001), libuuid-2.37.4-21.el9 (CVE-2026-13595, CVE-2026-27456), bzip2-libs-1.0.8-10.el9_5 (CVE-2026-42250), freetype-2.10.4-10.el9_5 (CVE-2026-23865), rsync-3.2.5-3.el9 (CVE-2026-43617, CVE-2026-43619, CVE-2026-43620, CVE-2026-45232), gnupg2-2.3.3-4.el9 (CVE-2025-68972), systemd-libs-252-55.el9_7.2 (CVE-2026-4105), coreutils-single-8.32-39.el9 (CVE-2026-56391, CVE-2026-56392), tar-2:1.34-7.el9 (CVE-2025-64118, CVE-2026-18477, CVE-2026-18508, CVE-2026-33056, CVE-2026-53655, CVE-2026-5704, CVE-2026-59871, CVE-2026-59875), openldap-2.6.8-4.el9 (CVE-2026-22185), systemd-pam-252-55.el9_7.2 (CVE-2026-4105), dbus-broker-28-7.el9 (CVE-2026-16730), libarchive-3.5.3-6.el9_6 (CVE-2023-30571, CVE-2025-60753, CVE-2026-4426, CVE-2026-5745), openssl-1:3.5.1-4.el9_7 (CVE-2026-2673), openssl-fips-provider-so-3.0.7-8.el9 (CVE-2026-2673), libattr-2.5.1-3.el9 (CVE-2026-54371)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;clair_unpatched_medium_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 229&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found packages with low/negligible vulnerabilities associated with RHSA fixes. Consider updating to a newer version of those packages, they may no longer be affected by the reported CVEs.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Vulnerabilities found: nodejs-full-i18n-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2026-11525, CVE-2026-48935, CVE-2026-6733), glibc-langpack-en-2.34-231.el9_7.2 (CVE-2026-4438), gnutls-3.8.3-9.el9 (CVE-2025-9820, CVE-2026-3832, CVE-2026-5419), npm-1:10.9.3-1.22.19.0.2.module+el9.6.0+23473+45664c2d (CVE-2026-11525, CVE-2026-48935, CVE-2026-6733), nodejs-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2026-11525, CVE-2026-48935, CVE-2026-6733), glibc-2.34-231.el9_7.2 (CVE-2025-15281, CVE-2026-0861, CVE-2026-4438), glibc-headers-2.34-231.el9_7.2 (CVE-2026-4438), glibc-locale-source-2.34-231.el9_7.2 (CVE-2026-4438), nodejs-docs-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2026-11525, CVE-2026-48935, CVE-2026-6733), openssh-clients-8.7p1-46.el9 (CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-55654), openssl-libs-1:3.5.1-4.el9_7 (CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796, CVE-2026-34180, CVE-2026-34181, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-45446, CVE-2026-7383, CVE-2026-9076), nodejs-libs-1:22.19.0-2.module+el9.6.0+23473+45664c2d (CVE-2026-11525, CVE-2026-48935, CVE-2026-6733), libxml2-2.9.13-14.el9_7 (CVE-2024-34459, CVE-2025-6170), libxml2-devel-2.9.13-14.el9_7 (CVE-2024-34459, CVE-2025-6170), glibc-minimal-langpack-2.34-231.el9_7.2 (CVE-2026-4438), python3-libs-3.9.23-2.el9 (CVE-2024-5642, CVE-2025-6075), libtasn1-4.16.0-9.el9 (CVE-2025-13151), glibc-common-2.34-231.el9_7.2 (CVE-2026-4438), glibc-devel-2.34-231.el9_7.2 (CVE-2026-4438), glibc-gconv-extra-2.34-231.el9_7.2 (CVE-2026-4438), openssl-devel-1:3.5.1-4.el9_7 (CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796, CVE-2026-34180, CVE-2026-34181, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-45446, CVE-2026-7383, CVE-2026-9076), python3-3.9.23-2.el9 (CVE-2024-5642, CVE-2025-6075), openssh-8.7p1-46.el9 (CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-55654), openssl-1:3.5.1-4.el9_7 (CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796, CVE-2026-34180, CVE-2026-34181, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-45446, CVE-2026-7383, CVE-2026-9076)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;clair_low_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 102&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found packages with unpatched low/negligible vulnerabilities. These vulnerabilities don&#39;t have a known fix at this time.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Vulnerabilities found: ncurses-base-6.2-12.20210508.el9 (CVE-2023-50495), popt-1.18-8.el9 (CVE-2026-18739, CVE-2026-18839), python3-pip-wheel-21.3.1-1.el9 (CVE-2021-3572), curl-minimal-7.76.1-34.el9 (CVE-2024-11053, CVE-2024-7264, CVE-2024-9681, CVE-2025-14524, CVE-2025-15079, CVE-2025-15224, CVE-2026-6276), pkgconf-pkg-config-1.7.3-10.el9 (CVE-2023-24056), pkgconf-m4-1.7.3-10.el9 (CVE-2023-24056), elfutils-debuginfod-client-0.193-1.el9 (CVE-2024-25260, CVE-2025-1371, CVE-2025-1376, CVE-2025-1377), zlib-1.2.11-40.el9 (CVE-2026-27171), ncurses-6.2-12.20210508.el9 (CVE-2023-50495), glib2-2.68.4-18.el9_7 (CVE-2023-32636, CVE-2025-3360, CVE-2025-7039, CVE-2026-0988, CVE-2026-1485), gawk-5.1.0-6.el9 (CVE-2023-4156), vim-minimal-2:8.2.2637-23.el9_7 (CVE-2021-3927, CVE-2021-3928, CVE-2021-3968, CVE-2021-3973, CVE-2021-3974, CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4187, CVE-2022-0213, CVE-2022-0351, CVE-2022-1616, CVE-2022-1619, CVE-2022-1620, CVE-2022-1674, CVE-2022-1720, CVE-2022-1725, CVE-2022-2042, CVE-2022-2124, CVE-2022-2125, CVE-2022-2126, CVE-2022-2129, CVE-2022-2175, CVE-2022-2182, CVE-2022-2183, CVE-2022-2206, CVE-2022-2207, CVE-2022-2208, CVE-2022-2210, CVE-2022-2257, CVE-2022-2284, CVE-2022-2285, CVE-2022-2286, CVE-2022-2287, CVE-2022-2304, CVE-2022-2343, CVE-2022-2344, CVE-2022-2345, CVE-2022-2522, CVE-2022-2817, CVE-2022-2819, CVE-2022-2845, CVE-2022-2849, CVE-2022-2862, CVE-2022-2874, CVE-2022-2889, CVE-2022-2923, CVE-2022-2946, CVE-2022-2980, CVE-2022-2982, CVE-2022-3016, CVE-2022-3037, CVE-2022-3099, CVE-2022-3134, CVE-2022-3153, CVE-2022-3234, CVE-2022-3235, CVE-2022-3256, CVE-2022-3278, CVE-2022-3296, CVE-2022-3297, CVE-2022-3324, CVE-2022-3352, CVE-2022-3705, CVE-2022-4141, CVE-2022-4292, CVE-2022-4293, CVE-2023-0049, CVE-2023-0051, CVE-2023-0054, CVE-2023-0288, CVE-2023-0433, CVE-2023-0512, CVE-2023-1127, CVE-2023-1170, CVE-2023-1175, CVE-2023-1264, CVE-2023-2609, CVE-2023-2610, CVE-2023-46246, CVE-2023-4734, CVE-2023-4735, CVE-2023-4738, CVE-2023-4751, CVE-2023-4781, CVE-2023-48231, CVE-2023-48232, CVE-2023-48233, CVE-2023-48234, CVE-2023-48235, CVE-2023-48236, CVE-2023-48237, CVE-2023-48706, CVE-2023-5344, CVE-2023-5441, CVE-2023-5535, CVE-2024-22667, CVE-2024-41957, CVE-2024-41965, CVE-2024-43374, CVE-2024-43802, CVE-2024-45306, CVE-2024-47814, CVE-2025-1215, CVE-2025-22134, CVE-2025-24014, CVE-2025-26603, CVE-2026-26269, CVE-2026-28422), sqlite-libs-3.34.1-9.el9_7 (CVE-2024-0232, CVE-2025-70873), libgomp-11.5.0-11.el9 (CVE-2021-46195, CVE-2022-27943), pkgconf-1.7.3-10.el9 (CVE-2023-24056), libgcc-11.5.0-11.el9 (CVE-2021-46195, CVE-2022-27943), binutils-gold-2.35.2-67.el9 (CVE-2021-3826, CVE-2022-38533, CVE-2022-44840, CVE-2022-47007, CVE-2022-47008, CVE-2022-47010, CVE-2022-47011, CVE-2023-1972, CVE-2024-57360, CVE-2025-11412, CVE-2025-11413, CVE-2025-11414, CVE-2025-11494, CVE-2025-11495, CVE-2025-1150, CVE-2025-1151, CVE-2025-1152, CVE-2025-1153, CVE-2025-11839, CVE-2025-11840, CVE-2025-3198, CVE-2025-66861, CVE-2025-66862, CVE-2025-66863, CVE-2025-66864, CVE-2025-66865, CVE-2025-66866, CVE-2025-69644, CVE-2025-69645, CVE-2025-69646, CVE-2025-69647, CVE-2025-69648, CVE-2025-69649, CVE-2025-69650, CVE-2025-69651, CVE-2025-69652), binutils-2.35.2-67.el9 (CVE-2021-3826, CVE-2022-38533, CVE-2022-44840, CVE-2022-47007, CVE-2022-47008, CVE-2022-47010, CVE-2022-47011, CVE-2023-1972, CVE-2024-57360, CVE-2025-11412, CVE-2025-11413, CVE-2025-11414, CVE-2025-11494, CVE-2025-11495, CVE-2025-1150, CVE-2025-1151, CVE-2025-1152, CVE-2025-1153, CVE-2025-11839, CVE-2025-11840, CVE-2025-3198, CVE-2025-66861, CVE-2025-66862, CVE-2025-66863, CVE-2025-66864, CVE-2025-66865, CVE-2025-66866, CVE-2025-69644, CVE-2025-69645, CVE-2025-69646, CVE-2025-69647, CVE-2025-69648, CVE-2025-69649, CVE-2025-69650, CVE-2025-69651, CVE-2025-69652), openssh-clients-8.7p1-46.el9 (CVE-2026-73281), openssl-libs-1:3.5.1-4.el9_7 (CVE-2024-13176, CVE-2024-41996, CVE-2025-9232, CVE-2026-28388, CVE-2026-28389, CVE-2026-31789), libgcrypt-1.10.0-11.el9 (CVE-2026-41990), pcre2-syntax-10.40-6.el9 (CVE-2022-41409), libxml2-2.9.13-14.el9_7 (CVE-2023-45322, CVE-2025-27113, CVE-2026-0989, CVE-2026-0992), expat-2.5.0-5.el9_7.1 (CVE-2025-66382, CVE-2026-24515, CVE-2026-41080), elfutils-libs-0.193-1.el9 (CVE-2024-25260, CVE-2025-1371, CVE-2025-1376, CVE-2025-1377), pcre2-10.40-6.el9 (CVE-2022-41409), elfutils-libelf-0.193-1.el9 (CVE-2024-25260, CVE-2025-1371, CVE-2025-1376, CVE-2025-1377), ncurses-libs-6.2-12.20210508.el9 (CVE-2023-50495), vim-filesystem-2:8.2.2637-23.el9_7 (CVE-2021-3927, CVE-2021-3928, CVE-2021-3968, CVE-2021-3973, CVE-2021-3974, CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4187, CVE-2022-0213, CVE-2022-0351, CVE-2022-1616, CVE-2022-1619, CVE-2022-1620, CVE-2022-1674, CVE-2022-1720, CVE-2022-1725, CVE-2022-2042, CVE-2022-2124, CVE-2022-2125, CVE-2022-2126, CVE-2022-2129, CVE-2022-2175, CVE-2022-2182, CVE-2022-2183, CVE-2022-2206, CVE-2022-2207, CVE-2022-2208, CVE-2022-2210, CVE-2022-2257, CVE-2022-2284, CVE-2022-2285, CVE-2022-2286, CVE-2022-2287, CVE-2022-2304, CVE-2022-2343, CVE-2022-2344, CVE-2022-2345, CVE-2022-2522, CVE-2022-2817, CVE-2022-2819, CVE-2022-2845, CVE-2022-2849, CVE-2022-2862, CVE-2022-2874, CVE-2022-2889, CVE-2022-2923, CVE-2022-2946, CVE-2022-2980, CVE-2022-2982, CVE-2022-3016, CVE-2022-3037, CVE-2022-3099, CVE-2022-3134, CVE-2022-3153, CVE-2022-3234, CVE-2022-3235, CVE-2022-3256, CVE-2022-3278, CVE-2022-3296, CVE-2022-3297, CVE-2022-3324, CVE-2022-3352, CVE-2022-3705, CVE-2022-4141, CVE-2022-4292, CVE-2022-4293, CVE-2023-0049, CVE-2023-0051, CVE-2023-0054, CVE-2023-0288, CVE-2023-0433, CVE-2023-0512, CVE-2023-1127, CVE-2023-1170, CVE-2023-1175, CVE-2023-1264, CVE-2023-2609, CVE-2023-2610, CVE-2023-46246, CVE-2023-4734, CVE-2023-4735, CVE-2023-4738, CVE-2023-4751, CVE-2023-4781, CVE-2023-48231, CVE-2023-48232, CVE-2023-48233, CVE-2023-48234, CVE-2023-48235, CVE-2023-48236, CVE-2023-48237, CVE-2023-48706, CVE-2023-5344, CVE-2023-5441, CVE-2023-5535, CVE-2024-22667, CVE-2024-41957, CVE-2024-41965, CVE-2024-43374, CVE-2024-43802, CVE-2024-45306, CVE-2024-47814, CVE-2025-1215, CVE-2025-22134, CVE-2025-24014, CVE-2025-26603, CVE-2026-26269, CVE-2026-28422), libcurl-minimal-7.76.1-34.el9 (CVE-2024-11053, CVE-2024-7264, CVE-2024-9681, CVE-2025-14524, CVE-2025-15079, CVE-2025-15224, CVE-2026-6276), python3-libs-3.9.23-2.el9 (CVE-2025-13462, CVE-2025-1795, CVE-2026-2297, CVE-2026-3479), unzip-6.0-59.el9 (CVE-2021-4217, CVE-2022-0529, CVE-2022-0530), elfutils-default-yama-scope-0.193-1.el9 (CVE-2024-25260, CVE-2025-1371, CVE-2025-1376, CVE-2025-1377), python3-3.9.23-2.el9 (CVE-2025-13462, CVE-2025-1795, CVE-2026-2297, CVE-2026-3479), libpkgconf-1.7.3-10.el9 (CVE-2023-24056), openssh-8.7p1-46.el9 (CVE-2026-73281), libstdc++-11.5.0-11.el9 (CVE-2021-46195, CVE-2022-27943), rsync-3.2.5-3.el9 (CVE-2026-27171), gnupg2-2.3.3-4.el9 (CVE-2022-3219, CVE-2025-30258, CVE-2026-24883, CVE-2026-57062), tar-2:1.34-7.el9 (CVE-2023-39804), libarchive-3.5.3-6.el9_6 (CVE-2025-1632, CVE-2025-5915, CVE-2025-5916, CVE-2025-5917, CVE-2025-5918, CVE-2026-15028, CVE-2026-16517), openssl-1:3.5.1-4.el9_7 (CVE-2024-13176, CVE-2024-41996, CVE-2025-9232, CVE-2026-28388, CVE-2026-28389, CVE-2026-31789)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;clair_unpatched_low_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 393&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;]&#xA;&#x9;}&#xA;]&#xA;{&#34;vulnerabilities&#34;:{&#34;critical&#34;:0,&#34;high&#34;:183,&#34;medium&#34;:281,&#34;low&#34;:102,&#34;unknown&#34;:0},&#34;unpatched_vulnerabilities&#34;:{&#34;critical&#34;:0,&#34;high&#34;:13,&#34;medium&#34;:229,&#34;low&#34;:393,&#34;unknown&#34;:0}}&#xA;{&#34;image&#34;: {&#34;pullspec&#34;: &#34;quay.io/redhat-appstudio-qe/build-e2e-prefetch-bundler/component-prefetch-bundler:on-pr-cd88ba9cbcd358acc1785329ed6ce0c60587e84c&#34;, &#34;digests&#34;: [&#34;sha256:1806486990f86738e26ea4751f25cd961b841d64af0fffe4c91affa4f2d116f9&#34;]}}&#xA;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-08-14T13:22:15+00:00&#34;,&#34;note&#34;:&#34;Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#xA;&#xA; pod: component-prefetch-bundler-on-pull-request-ncd7p-init-pod | init container: prepare&#xA;2026/08/14 13:13:01 Entrypoint initialization&#xA;&#xA;pod: component-prefetch-bundler-on-pull-request-ncd7p-init-pod | container step-init: &#xA;time=&#34;2026-08-14T13:13:20Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-08-14T13:13:20Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-08-14T13:13:20Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-08-14T13:13:20Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-08-14T13:13:20Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-08-14T13:13:20Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-08-14T13:13:20Z&#34; level=info msg=&#34;Cache proxy is disabled via param&#34;&#xA;time=&#34;2026-08-14T13:13:20Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-08-14T13:13:20Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;New PipelineRun component-prefetch-bundler-on-pull-request-94mj6 found after retrigger for component build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 found for Component build-e2e-prefetch-bundler/component-prefetch-bundler&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: ResolvingTaskRef&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Running&#xA;PipelineRun component-prefetch-bundler-on-pull-request-94mj6 reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:27:37.951 (14m36.084s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-bundler&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.192939513">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:27:37.987&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:27:39.179 (1.193s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-bundler&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.405994248">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:27:39.18&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:27:39.586 (406ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-bundler&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.00032956">
              <skipped message="skipped - floating tag validation is not needed for: prefetch-bundler"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:27:39.587&#xA;[SKIPPED] floating tag validation is not needed for: prefetch-bundler&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:27:39.587&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:27:39.587 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-bundler&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.306702228">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:27:39.588&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:27:39.894 (307ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-bundler&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.322066727">
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:27:39.895&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:27:40.217 (322ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-bundler&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="1.054681296">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:27:40.217&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:27:40.218&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:27:40.218 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;prefetch-bundler&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:27:40.218&#xA;&lt; Exit [AfterAll] scenario &#34;prefetch-bundler&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:27:41.272 (1.054s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-npm&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="33.254687933">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;prefetch-npm&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:27:41.273&#xA;Image repository for component component-prefetch-npm in namespace build-e2e-prefetch-npm do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: prefetch-npm&#xA;RUNNING SCENARIO: prefetch-npm&#xA;&lt; Exit [BeforeAll] scenario &#34;prefetch-npm&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:27:54.333 (13.06s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:27:54.333&#xA;PipelineRun has not been created yet for the component build-e2e-prefetch-npm/component-prefetch-npm&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:28:14.527 (20.195s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-npm&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="300.193612642">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:28:14.528&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm found for Component build-e2e-prefetch-npm/component-prefetch-npm&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Running&#xA;PipelineRun component-prefetch-npm-on-pull-request-k6fkm reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:33:14.722 (5m0.193s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-npm&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.313412253">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:33:14.722&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:33:16.036 (1.313s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-npm&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.606338887">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:33:16.036&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:33:16.643 (606ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-npm&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.00035714">
              <skipped message="skipped - floating tag validation is not needed for: prefetch-npm"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:33:16.643&#xA;[SKIPPED] floating tag validation is not needed for: prefetch-npm&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:33:16.644&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:33:16.644 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-npm&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.300462079">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:33:16.644&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:33:16.944 (300ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-npm&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.295937937">
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:33:16.945&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:33:17.241 (296ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-npm&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="1.3881813250000001">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:33:17.242&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:33:17.242&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:33:17.242 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;prefetch-npm&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:33:17.242&#xA;&lt; Exit [AfterAll] scenario &#34;prefetch-npm&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:33:18.63 (1.388s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-classic&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="33.324662691">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;prefetch-yarn-classic&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:33:18.631&#xA;Image repository for component component-prefetch-yarn-classic in namespace build-e2e-prefetch-yarn-classic do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: prefetch-yarn-classic&#xA;RUNNING SCENARIO: prefetch-yarn-classic&#xA;&lt; Exit [BeforeAll] scenario &#34;prefetch-yarn-classic&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:33:31.761 (13.13s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:33:31.761&#xA;PipelineRun has not been created yet for the component build-e2e-prefetch-yarn-classic/component-prefetch-yarn-classic&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:33:51.955 (20.194s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-classic&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="480.211819359">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:33:51.956&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm found for Component build-e2e-prefetch-yarn-classic/component-prefetch-yarn-classic&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Running&#xA;PipelineRun component-prefetch-yarn-classic-on-pull-request-cd4tm reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:41:52.168 (8m0.212s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-classic&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="1.121308244">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:41:52.168&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:41:53.29 (1.121s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-classic&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.579535618">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:41:53.29&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:41:53.87 (579ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-classic&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000371801">
              <skipped message="skipped - floating tag validation is not needed for: prefetch-yarn-classic"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:41:53.87&#xA;[SKIPPED] floating tag validation is not needed for: prefetch-yarn-classic&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:41:53.871&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:41:53.871 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-classic&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.346606758">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:41:53.871&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:41:54.218 (346ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-classic&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.310809703">
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:41:54.218&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:41:54.529 (311ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;prefetch-yarn-classic&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="1.427130772">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:41:54.53&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:41:54.53&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:41:54.53 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;prefetch-yarn-classic&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:41:54.53&#xA;&lt; Exit [AfterAll] scenario &#34;prefetch-yarn-classic&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:41:55.957 (1.427s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build&#34; triggers a PipelineRun [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="33.197027476">
              <system-err>&gt; Enter [BeforeAll] scenario &#34;sample-python-basic-oci-docker-build&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:41:55.958&#xA;Image repository for component component-sample-python-basic-oci-docker-build in namespace build-e2e-sample-python-basic-oci-docker-build do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;    } []}.&#xA;Created component for scenario: sample-python-basic-oci-docker-build&#xA;RUNNING SCENARIO: sample-python-basic-oci-docker-build&#xA;&lt; Exit [BeforeAll] scenario &#34;sample-python-basic-oci-docker-build&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:38 @ 08/14/26 13:42:08.938 (12.98s)&#xA;&gt; Enter [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:42:08.939&#xA;PipelineRun has not been created yet for the component build-e2e-sample-python-basic-oci-docker-build/component-sample-python-basic-oci-docker-build&#xA;&lt; Exit [It] triggers a PipelineRun - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:89 @ 08/14/26 13:42:29.155 (20.216s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build&#34; the PipelineRun should eventually finish [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="200.215083239">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:42:29.156&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l found for Component build-e2e-sample-python-basic-oci-docker-build/component-sample-python-basic-oci-docker-build&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Running&#xA;PipelineRun component-sample-python-basic-oci-docker-build-on-pull-reqclb9l reason: Completed&#xA;&lt; Exit [It] the PipelineRun should eventually finish - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:103 @ 08/14/26 13:45:49.371 (3m20.215s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build&#34; should push Dockerfile to registry [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="4.752503681">
              <system-err>&gt; Enter [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:45:49.371&#xA;&lt; Exit [It] should push Dockerfile to registry - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:123 @ 08/14/26 13:45:54.124 (4.752s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build&#34; should validate tekton taskrun test results [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.689240905">
              <system-err>&gt; Enter [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:45:54.125&#xA;&lt; Exit [It] should validate tekton taskrun test results - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:130 @ 08/14/26 13:45:54.814 (689ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build&#34; floating tags are created successfully [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.00034006">
              <skipped message="skipped - floating tag validation is not needed for: sample-python-basic-oci-docker-build"></skipped>
              <system-err>&gt; Enter [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:45:54.815&#xA;[SKIPPED] floating tag validation is not needed for: sample-python-basic-oci-docker-build&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:139 @ 08/14/26 13:45:54.815&#xA;&lt; Exit [It] floating tags are created successfully - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:137 @ 08/14/26 13:45:54.815 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build&#34; image manifest mediaType is correct [build-pipeline-e2e]" classname="Build Pipeline E2E" status="passed" time="0.291839066">
              <system-err>&gt; Enter [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:45:54.815&#xA;&lt; Exit [It] image manifest mediaType is correct - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:153 @ 08/14/26 13:45:55.107 (292ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build&#34; should have Hermeto content in the SBOM in case the build was hermetic [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="0.000372131">
              <skipped message="skipped - Hermetic build is not enabled, skipping the test"></skipped>
              <system-err>&gt; Enter [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:45:55.108&#xA;[SKIPPED] Hermetic build is not enabled, skipping the test&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:182 @ 08/14/26 13:45:55.108&#xA;&lt; Exit [It] should have Hermeto content in the SBOM in case the build was hermetic - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:180 @ 08/14/26 13:45:55.108 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [build-service-suite Build pipeline E2E test] Build pipeline scenario &#34;sample-python-basic-oci-docker-build&#34; check for source images if enabled in pipeline [build-pipeline-e2e]" classname="Build Pipeline E2E" status="skipped" time="2.108777737">
              <skipped message="skipped - Skipping source image check since it is not enabled in the pipeline"></skipped>
              <system-err>&gt; Enter [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:45:55.109&#xA;Source build is enabled: false&#xA;[SKIPPED] Skipping source image check since it is not enabled in the pipeline&#xA;In [It] at: /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:223 @ 08/14/26 13:45:55.109&#xA;&lt; Exit [It] check for source images if enabled in pipeline - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:214 @ 08/14/26 13:45:55.109 (0s)&#xA;&gt; Enter [AfterAll] scenario &#34;sample-python-basic-oci-docker-build&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:45:55.109&#xA;&lt; Exit [AfterAll] scenario &#34;sample-python-basic-oci-docker-build&#34; - /workspace/source/e2e-tests/tests/build/build_pipeline_tests.go:55 @ 08/14/26 13:45:57.217 (2.108s)&#xA;</system-err>
          </testcase>
      </testsuite>
  </testsuites>