Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-yarn-modern/component-prefetch-yarn-modern Running clair-action on amd64 image manifest... 2026/08/15 03:08:10 INFO matchers created matcher.python=https://pkg.go.dev/github.com/quay/claircore/python matcher.aws-matcher=https://pkg.go.dev/github.com/quay/claircore/aws matcher.gobin=https://pkg.go.dev/github.com/quay/claircore/gobin matcher.oracle=https://pkg.go.dev/github.com/quay/claircore/oracle matcher.ruby-gem=https://pkg.go.dev/github.com/quay/claircore/ruby matcher.rhel=https://pkg.go.dev/github.com/quay/claircore/rhel matcher.debian-matcher=https://pkg.go.dev/github.com/quay/claircore/debian matcher.rhel-container-matcher=https://pkg.go.dev/github.com/quay/claircore/rhel/rhcc matcher.suse=https://pkg.go.dev/github.com/quay/claircore/suse matcher.ubuntu-matcher=https://pkg.go.dev/github.com/quay/claircore/ubuntu matcher.alpine-matcher=https://pkg.go.dev/github.com/quay/claircore/alpine matcher.java-maven=https://pkg.go.dev/github.com/quay/claircore/java matcher.photon=https://pkg.go.dev/github.com/quay/claircore/photon 2026/08/15 03:08:10 INFO vex factory configured base_url=https://security.access.redhat.com/data/csaf/v2/vex/ compressed_file_timeout=2m0s 2026/08/15 03:08:10 INFO libvuln initialized 2026/08/15 03:08:10 INFO registered configured scanners 2026/08/15 03:08:10 INFO constructing 2026/08/15 03:08:10 INFO index request start 2026/08/15 03:08:10 INFO starting scan 2026/08/15 03:08:10 INFO manifest to be scanned 2026/08/15 03:08:10 INFO layers fetch start 2026/08/15 03:08:13 INFO layers fetch success 2026/08/15 03:08:13 INFO layers fetch done 2026/08/15 03:08:13 INFO layers scan start 2026/08/15 03:08:13 WARN rpm source packages always record 0 epoch; this may cause incorrect matching see-also="https://github.com/rpm-software-management/rpm/issues/2796 https://github.com/rpm-software-management/rpm/discussions/3703 https://github.com/rpm-software-management/rpm/pull/3755" 2026/08/15 03:08:14 INFO layers scan done 2026/08/15 03:08:14 INFO starting index manifest 2026/08/15 03:08:14 INFO finishing scan 2026/08/15 03:08:14 INFO manifest successfully scanned 2026/08/15 03:08:14 INFO index request done { "manifest_hash": "sha256:69e6deea2432dc0bcd70c907d74cb9273a8edb537f81fc9af0df4e6286aa42a9", "packages": { "+A7/nzEXX3Q/xJZ50VMnlQ==": { "id": "+A7/nzEXX3Q/xJZ50VMnlQ==", "name": "libidn2", "version": "2.3.0-7.el9", "kind": "binary", "source": { "id": "", "name": "libidn2", "version": "2.3.0-7.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "+X1MdmtPTbyDb/wq7joJhA==": { "id": "+X1MdmtPTbyDb/wq7joJhA==", "name": "libtool-ltdl", "version": "2.4.6-46.el9", "kind": "binary", "source": { "id": "", "name": "libtool", "version": "2.4.6-46.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "+lY+UUpyo/55vgqUUOuejg==": { "id": "+lY+UUpyo/55vgqUUOuejg==", "name": "nodejs-full-i18n", "version": "1:22.22.2-1.module+el9.7.0+24157+8ddb2461", "kind": "binary", "source": { "id": "", "name": "nodejs", "version": "22.22.2-1.module+el9.7.0+24157+8ddb2461", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "module": "nodejs:22", "arch": "x86_64", "cpe": "", "detector": null }, "/3dC79z2JmZ/i03s/r5MGQ==": { "id": "/3dC79z2JmZ/i03s/r5MGQ==", "name": "Konflux yarn builder", "version": "1786763159", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "rhctag:1786763159.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "/Jp1+jxuGVB8kf+IVvkLrQ==": { "id": "/Jp1+jxuGVB8kf+IVvkLrQ==", "name": "tar", "version": "2:1.34-11.el9", "kind": "binary", "source": { "id": "", "name": "tar", "version": "1.34-11.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "/L1kFEoHZTukrNTCQLypFQ==": { "id": "/L1kFEoHZTukrNTCQLypFQ==", "name": "xz-libs", "version": "5.2.5-8.el9_0", "kind": "binary", "source": { "id": "", "name": "xz", "version": "5.2.5-8.el9_0", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "/O7rOBo1qRMFm3q3Kf3mEw==": { "id": "/O7rOBo1qRMFm3q3Kf3mEw==", "name": "libselinux", "version": "3.6-3.el9", "kind": "binary", "source": { "id": "", "name": "libselinux", "version": "3.6-3.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "/T3unXthUSp/zJaVYpuQfQ==": { "id": "/T3unXthUSp/zJaVYpuQfQ==", "name": "curl-minimal", "version": "7.76.1-40.el9", "kind": "binary", "source": { "id": "", "name": "curl", "version": "7.76.1-40.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "/THiuz93dsCZJETS3A4Xtw==": { "id": "/THiuz93dsCZJETS3A4Xtw==", "name": "libcom_err", "version": "1.46.5-8.el9", "kind": "binary", "source": { "id": "", "name": "e2fsprogs", "version": "1.46.5-8.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "/TtZcCefM8OHHof3XKTmHw==": { "id": "/TtZcCefM8OHHof3XKTmHw==", "name": "redhat-release", "version": "9.8-1.0.el9", "kind": "binary", "source": { "id": "", "name": "redhat-release", "version": "9.8-1.0.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "2Q5QnVvn83+RyQcaQ745Gw==": { "id": "2Q5QnVvn83+RyQcaQ745Gw==", "name": "ubi9/nodejs-22-minimal", "version": "1779828950", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779828950.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "2daNj17YVWGx0KV9TCa6Ag==": { "id": "2daNj17YVWGx0KV9TCa6Ag==", "name": "p11-kit", "version": "0.26.2-1.el9", "kind": "binary", "source": { "id": "", "name": "p11-kit", "version": "0.26.2-1.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "2gCbp4kt+cF44NF/LqukDg==": { "id": "2gCbp4kt+cF44NF/LqukDg==", "name": "pcre2-syntax", "version": "10.40-6.el9", "kind": "binary", "source": { "id": "", "name": "pcre2", "version": "10.40-6.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "2s+WoHFOH6YMNQHNWXDuRg==": { "id": "2s+WoHFOH6YMNQHNWXDuRg==", "name": "dnf-data", "version": "4.14.0-34.el9_8", "kind": "binary", "source": { "id": "", "name": "dnf", "version": "4.14.0-34.el9_8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "40CUjHKsWI2oXBGOxO5+Kg==": { "id": "40CUjHKsWI2oXBGOxO5+Kg==", "name": "glibc-common", "version": "2.34-270.el9_8", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.34-270.el9_8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "4iqV8aUHNk1o4YJaOnnBOg==": { "id": "4iqV8aUHNk1o4YJaOnnBOg==", "name": "libmount", "version": "2.37.4-25.el9", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.37.4-25.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "5JAFUJWmy04+T6x2oJw2jg==": { "id": "5JAFUJWmy04+T6x2oJw2jg==", "name": "libxml2", "version": "2.9.13-14.el9_7", "kind": "binary", "source": { "id": "", "name": "libxml2", "version": "2.9.13-14.el9_7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "5T6eFHgFgSAq68A4uhcd5Q==": { "id": "5T6eFHgFgSAq68A4uhcd5Q==", "name": "Konflux yarn builder", "version": "1779860795", "kind": "ancestry", "source": { "id": "Vtcppx964Xo7bbcHDlWWag==", "name": "Konflux yarn builder", "version": "1779860795", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779860795.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779860795.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "6sUhut8O1JC80Cua0ljqAw==": { "id": "6sUhut8O1JC80Cua0ljqAw==", "name": "libcap", "version": "2.48-10.el9_8.1", "kind": "binary", "source": { "id": "", "name": "libcap", "version": "2.48-10.el9_8.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "73dAQtEmA5DMG7vTc637ig==": { "id": "73dAQtEmA5DMG7vTc637ig==", "name": "tzdata", "version": "2026b-1.el9", "kind": "binary", "source": { "id": "", "name": "tzdata", "version": "2026b-1.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "7cpIREEQnkaI7dbmWgmrvg==": { "id": "7cpIREEQnkaI7dbmWgmrvg==", "name": "gdbm-libs", "version": "1:1.23-1.el9", "kind": "binary", "source": { "id": "", "name": "gdbm", "version": "1.23-1.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "7mDaaxs3ev+uNEDYC97U3Q==": { "id": "7mDaaxs3ev+uNEDYC97U3Q==", "name": "zlib", "version": "1.2.11-40.el9", "kind": "binary", "source": { "id": "", "name": "zlib", "version": "1.2.11-40.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "7vssDPaHKfFKMLimKBo7Gw==": { "id": "7vssDPaHKfFKMLimKBo7Gw==", "name": "libpeas", "version": "1.30.0-4.el9", "kind": "binary", "source": { "id": "", "name": "libpeas", "version": "1.30.0-4.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "87EcTL94JiygUQLwYuL2AQ==": { "id": "87EcTL94JiygUQLwYuL2AQ==", "name": "libbrotli", "version": "1.0.9-9.el9_7", "kind": "binary", "source": { "id": "", "name": "brotli", "version": "1.0.9-9.el9_7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "933bwLexZewNfaJWrKZAJw==": { "id": "933bwLexZewNfaJWrKZAJw==", "name": "coreutils-single", "version": "8.32-40.el9", "kind": "binary", "source": { "id": "", "name": "coreutils", "version": "8.32-40.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "9olIUlLHZMdoUMju+8diyQ==": { "id": "9olIUlLHZMdoUMju+8diyQ==", "name": "filesystem", "version": "3.16-5.el9", "kind": "binary", "source": { "id": "", "name": "filesystem", "version": "3.16-5.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "9wWP1WdTrVCykiUHcmStWw==": { "id": "9wWP1WdTrVCykiUHcmStWw==", "name": "libsolv", "version": "0.7.24-4.el9", "kind": "binary", "source": { "id": "", "name": "libsolv", "version": "0.7.24-4.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "AYWPcXxdUay0d/qxFjyxxA==": { "id": "AYWPcXxdUay0d/qxFjyxxA==", "name": "libarchive", "version": "3.5.3-9.el9_7", "kind": "binary", "source": { "id": "", "name": "libarchive", "version": "3.5.3-9.el9_7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "BQhiFmX4hLYteW4oRCLTSA==": { "id": "BQhiFmX4hLYteW4oRCLTSA==", "name": "libassuan", "version": "2.5.5-3.el9", "kind": "binary", "source": { "id": "", "name": "libassuan", "version": "2.5.5-3.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "BRLVvSCW1qZQlEQR2x48fQ==": { "id": "BRLVvSCW1qZQlEQR2x48fQ==", "name": "gobject-introspection", "version": "1.68.0-11.el9", "kind": "binary", "source": { "id": "", "name": "gobject-introspection", "version": "1.68.0-11.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "CQ7LW8sdHcbka0B3IpMM1Q==": { "id": "CQ7LW8sdHcbka0B3IpMM1Q==", "name": "which", "version": "2.21-30.el9_6", "kind": "binary", "source": { "id": "", "name": "which", "version": "2.21-30.el9_6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "CS6z0/SKwjMOr6VBFQ1+lw==": { "id": "CS6z0/SKwjMOr6VBFQ1+lw==", "name": "findutils", "version": "1:4.8.0-7.el9", "kind": "binary", "source": { "id": "", "name": "findutils", "version": "4.8.0-7.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "DU6/TA2uNulT+q7hBfw/2w==": { "id": "DU6/TA2uNulT+q7hBfw/2w==", "name": "glibc", "version": "2.34-270.el9_8", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.34-270.el9_8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "DVT5EsNYhhc4TADNn+PvwA==": { "id": "DVT5EsNYhhc4TADNn+PvwA==", "name": "rootfiles", "version": "8.1-35.el9", "kind": "binary", "source": { "id": "", "name": "rootfiles", "version": "8.1-35.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "DrLq8qfU1bfE8o8AfdvkrQ==": { "id": "DrLq8qfU1bfE8o8AfdvkrQ==", "name": "libverto", "version": "0.3.2-3.el9", "kind": "binary", "source": { "id": "", "name": "libverto", "version": "0.3.2-3.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "E+86APTf07XmsaHw75dOYQ==": { "id": "E+86APTf07XmsaHw75dOYQ==", "name": "sed", "version": "4.8-10.el9", "kind": "binary", "source": { "id": "", "name": "sed", "version": "4.8-10.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "EsA7Dv6B+IUQ6wmp9oBkLA==": { "id": "EsA7Dv6B+IUQ6wmp9oBkLA==", "name": "libuuid", "version": "2.37.4-25.el9", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.37.4-25.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "G+944+S8mxpoNj+2qy2tQA==": { "id": "G+944+S8mxpoNj+2qy2tQA==", "name": "ubi9/ubi-minimal", "version": "1779809522", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779809522.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "G61ZL2SOHR2qgvQfi118gw==": { "id": "G61ZL2SOHR2qgvQfi118gw==", "name": "dejavu-sans-fonts", "version": "2.37-18.el9", "kind": "binary", "source": { "id": "", "name": "dejavu-fonts", "version": "2.37-18.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "HKlRsQZtXaa3HoNDv500tg==": { "id": "HKlRsQZtXaa3HoNDv500tg==", "name": "openssl-fips-provider-so", "version": "3.0.7-8.el9", "kind": "binary", "source": { "id": "", "name": "openssl-fips-provider", "version": "3.0.7-8.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "HQdWvmyUSqtI3UTY0T4JiQ==": { "id": "HQdWvmyUSqtI3UTY0T4JiQ==", "name": "pcre", "version": "8.44-4.el9", "kind": "binary", "source": { "id": "", "name": "pcre", "version": "8.44-4.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "HyBX75cInDsq7NDTuOp31w==": { "id": "HyBX75cInDsq7NDTuOp31w==", "name": "ca-certificates", "version": "2025.2.80_v9.0.305-91.el9", "kind": "binary", "source": { "id": "", "name": "ca-certificates", "version": "2025.2.80_v9.0.305-91.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "I16VSEydeiRYB1TSf5694A==": { "id": "I16VSEydeiRYB1TSf5694A==", "name": "libreport-filesystem", "version": "2.15.2-6.el9", "kind": "binary", "source": { "id": "", "name": "libreport", "version": "2.15.2-6.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "I37d1PMRX1UakcBjVAt7xw==": { "id": "I37d1PMRX1UakcBjVAt7xw==", "name": "file-libs", "version": "5.39-17.el9", "kind": "binary", "source": { "id": "", "name": "file", "version": "5.39-17.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "I5cVace6fizyXVtumzW7pg==": { "id": "I5cVace6fizyXVtumzW7pg==", "name": "libnghttp2", "version": "1.43.0-6.el9_8.1", "kind": "binary", "source": { "id": "", "name": "nghttp2", "version": "1.43.0-6.el9_8.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "IwPtZhSvUd42Go1Kioy9+Q==": { "id": "IwPtZhSvUd42Go1Kioy9+Q==", "name": "rpm", "version": "4.16.1.3-40.el9", "kind": "binary", "source": { "id": "", "name": "rpm", "version": "4.16.1.3-40.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "JKP7JzVg7UGaAz4VrH03lQ==": { "id": "JKP7JzVg7UGaAz4VrH03lQ==", "name": "langpacks-core-font-en", "version": "3.0-16.el9", "kind": "binary", "source": { "id": "", "name": "langpacks", "version": "3.0-16.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "KF5C+zKu/uFB7knCqOvDAQ==": { "id": "KF5C+zKu/uFB7knCqOvDAQ==", "name": "json-glib", "version": "1.6.6-1.el9", "kind": "binary", "source": { "id": "", "name": "json-glib", "version": "1.6.6-1.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "KxFesLSRtesBY4rvnejKaQ==": { "id": "KxFesLSRtesBY4rvnejKaQ==", "name": "crypto-policies", "version": "20260224-1.gitea0f072.el9_8", "kind": "binary", "source": { "id": "", "name": "crypto-policies", "version": "20260224-1.gitea0f072.el9_8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "L8X3lmrBrNsXuTdVU8i99A==": { "id": "L8X3lmrBrNsXuTdVU8i99A==", "name": "ubi9/ubi-minimal", "version": "1779809522", "kind": "binary", "source": { "id": "G+944+S8mxpoNj+2qy2tQA==", "name": "ubi9/ubi-minimal", "version": "1779809522", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779809522.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779809522.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "Lwqn0aweLQLZmo12VvYcog==": { "id": "Lwqn0aweLQLZmo12VvYcog==", "name": "popt", "version": "1.18-8.el9", "kind": "binary", "source": { "id": "", "name": "popt", "version": "1.18-8.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "MA8EMjMpjkzMuD4Zo1clCg==": { "id": "MA8EMjMpjkzMuD4Zo1clCg==", "name": "krb5-libs", "version": "1.21.1-10.el9_8", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.21.1-10.el9_8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "MDH8Zt4oQWDiYk9qFV5Lbg==": { "id": "MDH8Zt4oQWDiYk9qFV5Lbg==", "name": "libxcrypt", "version": "4.4.18-3.el9", "kind": "binary", "source": { "id": "", "name": "libxcrypt", "version": "4.4.18-3.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "NSiprMdkK5/5pxuNNJOh2A==": { "id": "NSiprMdkK5/5pxuNNJOh2A==", "name": "openssl-fips-provider", "version": "3.0.7-8.el9", "kind": "binary", "source": { "id": "", "name": "openssl-fips-provider", "version": "3.0.7-8.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "NdCY2/S+syamLH224R4hug==": { "id": "NdCY2/S+syamLH224R4hug==", "name": "langpacks-en", "version": "3.0-16.el9", "kind": "binary", "source": { "id": "", "name": "langpacks", "version": "3.0-16.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "OCIjbR16ktOEiFK36r0WNw==": { "id": "OCIjbR16ktOEiFK36r0WNw==", "name": "libtasn1", "version": "4.16.0-9.el9", "kind": "binary", "source": { "id": "", "name": "libtasn1", "version": "4.16.0-9.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "OgwdUybWl/HQYbnPTE4Psw==": { "id": "OgwdUybWl/HQYbnPTE4Psw==", "name": "npth", "version": "1.6-8.el9", "kind": "binary", "source": { "id": "", "name": "npth", "version": "1.6-8.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Ohssf0Jzlafd9vtrrUKCXg==": { "id": "Ohssf0Jzlafd9vtrrUKCXg==", "name": "bash", "version": "5.1.8-9.el9", "kind": "binary", "source": { "id": "", "name": "bash", "version": "5.1.8-9.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "P5Om9zCJ/QZ+hnrEvj6fGw==": { "id": "P5Om9zCJ/QZ+hnrEvj6fGw==", "name": "libgcrypt", "version": "1.10.0-11.el9", "kind": "binary", "source": { "id": "", "name": "libgcrypt", "version": "1.10.0-11.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "PIk2BBAWexCFofMi5q03RA==": { "id": "PIk2BBAWexCFofMi5q03RA==", "name": "pcre2", "version": "10.40-6.el9", "kind": "binary", "source": { "id": "", "name": "pcre2", "version": "10.40-6.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "PZXvGa4khHd2n6o73hJ/Pg==": { "id": "PZXvGa4khHd2n6o73hJ/Pg==", "name": "microdnf", "version": "3.9.1-3.el9", "kind": "binary", "source": { "id": "", "name": "microdnf", "version": "3.9.1-3.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "PvRYqRcexo7w5I906InQwA==": { "id": "PvRYqRcexo7w5I906InQwA==", "name": "libstdc++", "version": "11.5.0-14.el9", "kind": "binary", "source": { "id": "", "name": "gcc", "version": "11.5.0-14.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "QBTcpn4pqa+eJ8D8UVEiVg==": { "id": "QBTcpn4pqa+eJ8D8UVEiVg==", "name": "libcurl-minimal", "version": "7.76.1-40.el9", "kind": "binary", "source": { "id": "", "name": "curl", "version": "7.76.1-40.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "RXh3fimX8fGZeCt4chJEiA==": { "id": "RXh3fimX8fGZeCt4chJEiA==", "name": "librhsm", "version": "0.0.3-9.el9", "kind": "binary", "source": { "id": "", "name": "librhsm", "version": "0.0.3-9.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "RcZCiT+ycHJQmpV3/FuYsw==": { "id": "RcZCiT+ycHJQmpV3/FuYsw==", "name": "npm", "version": "1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461", "kind": "binary", "source": { "id": "", "name": "nodejs", "version": "22.22.2-1.module+el9.7.0+24157+8ddb2461", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "module": "nodejs:22", "arch": "x86_64", "cpe": "", "detector": null }, "S8p9UGak1oycptcpYp/1eg==": { "id": "S8p9UGak1oycptcpYp/1eg==", "name": "openldap", "version": "2.6.8-4.el9", "kind": "binary", "source": { "id": "", "name": "openldap", "version": "2.6.8-4.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "SUb+Lyjw6FDmZnaJmfkg2w==": { "id": "SUb+Lyjw6FDmZnaJmfkg2w==", "name": "bzip2-libs", "version": "1.0.8-11.el9", "kind": "binary", "source": { "id": "", "name": "bzip2", "version": "1.0.8-11.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "T1283MiUUtcDMYRJTXeZzA==": { "id": "T1283MiUUtcDMYRJTXeZzA==", "name": "openssl-libs", "version": "1:3.5.5-2.el9_8", "kind": "binary", "source": { "id": "", "name": "openssl", "version": "3.5.5-2.el9_8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "TPIRq84Pr3a6ywzPeCr3Pw==": { "id": "TPIRq84Pr3a6ywzPeCr3Pw==", "name": "libcap-ng", "version": "0.8.2-7.el9", "kind": "binary", "source": { "id": "", "name": "libcap-ng", "version": "0.8.2-7.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "To0NR+oyXDu1CYJfmVGurQ==": { "id": "To0NR+oyXDu1CYJfmVGurQ==", "name": "gpgme", "version": "1.15.1-6.el9", "kind": "binary", "source": { "id": "", "name": "gpgme", "version": "1.15.1-6.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "U+4qCFcZOyPHsmmdD44CrQ==": { "id": "U+4qCFcZOyPHsmmdD44CrQ==", "name": "glibc-minimal-langpack", "version": "2.34-270.el9_8", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.34-270.el9_8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "VS7DY+9FnbHX9Fem83CwXQ==": { "id": "VS7DY+9FnbHX9Fem83CwXQ==", "name": "nodejs-nodemon", "version": "3.0.1-1.module+el9.7.0+24157+8ddb2461", "kind": "binary", "source": { "id": "", "name": "nodejs-nodemon", "version": "3.0.1-1.module+el9.7.0+24157+8ddb2461", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "module": "nodejs:22", "arch": "noarch", "cpe": "", "detector": null }, "VV2Z1ngTs6sGvt5SrayPCg==": { "id": "VV2Z1ngTs6sGvt5SrayPCg==", "name": "libgpg-error", "version": "1.42-5.el9", "kind": "binary", "source": { "id": "", "name": "libgpg-error", "version": "1.42-5.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "VX9V+Y680L2xf2tBREdpCw==": { "id": "VX9V+Y680L2xf2tBREdpCw==", "name": "gmp", "version": "1:6.2.0-13.el9", "kind": "binary", "source": { "id": "", "name": "gmp", "version": "6.2.0-13.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Vtcppx964Xo7bbcHDlWWag==": { "id": "Vtcppx964Xo7bbcHDlWWag==", "name": "Konflux yarn builder", "version": "1779860795", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779860795.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "W7uBqJb8l9AhSXjNg1JZQg==": { "id": "W7uBqJb8l9AhSXjNg1JZQg==", "name": "ncurses-libs", "version": "6.2-12.20210508.el9", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.2-12.20210508.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "WVajSGKLGm8z6I23XYAhLQ==": { "id": "WVajSGKLGm8z6I23XYAhLQ==", "name": "cyrus-sasl-lib", "version": "2.1.27-22.el9", "kind": "binary", "source": { "id": "", "name": "cyrus-sasl", "version": "2.1.27-22.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "WwxYi5XJkmSTp/yi0EXIcQ==": { "id": "WwxYi5XJkmSTp/yi0EXIcQ==", "name": "audit-libs", "version": "3.1.5-8.el9", "kind": "binary", "source": { "id": "", "name": "audit", "version": "3.1.5-8.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "XG5+bW8np2NedSy/od6z8Q==": { "id": "XG5+bW8np2NedSy/od6z8Q==", "name": "libacl", "version": "2.3.1-4.el9", "kind": "binary", "source": { "id": "", "name": "acl", "version": "2.3.1-4.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Xa5h200SIiVSiheE2PRVIg==": { "id": "Xa5h200SIiVSiheE2PRVIg==", "name": "nodejs-libs", "version": "1:22.22.2-1.module+el9.7.0+24157+8ddb2461", "kind": "binary", "source": { "id": "", "name": "nodejs", "version": "22.22.2-1.module+el9.7.0+24157+8ddb2461", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "module": "nodejs:22", "arch": "x86_64", "cpe": "", "detector": null }, "XaWKjZmgTSvC2q3B/R5UNg==": { "id": "XaWKjZmgTSvC2q3B/R5UNg==", "name": "sqlite-libs", "version": "3.34.1-10.el9_8", "kind": "binary", "source": { "id": "", "name": "sqlite", "version": "3.34.1-10.el9_8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "XwbkaIGCYyq6BjBMVZ1wzw==": { "id": "XwbkaIGCYyq6BjBMVZ1wzw==", "name": "readline", "version": "8.1-4.el9", "kind": "binary", "source": { "id": "", "name": "readline", "version": "8.1-4.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "a7G//+ROQ5yESl9cZ0bfcg==": { "id": "a7G//+ROQ5yESl9cZ0bfcg==", "name": "ubi9/nodejs-22-minimal", "version": "1779828950", "kind": "binary", "source": { "id": "2Q5QnVvn83+RyQcaQ745Gw==", "name": "ubi9/nodejs-22-minimal", "version": "1779828950", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779828950.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779828950.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "aOUBKwKo1Yas7KseQYf5lQ==": { "id": "aOUBKwKo1Yas7KseQYf5lQ==", "name": "ubi9/ubi-minimal", "version": "1779809522", "kind": "ancestry", "source": { "id": "G+944+S8mxpoNj+2qy2tQA==", "name": "ubi9/ubi-minimal", "version": "1779809522", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779809522.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779809522.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "arLt5War9yeQ8auYn/Idmw==": { "id": "arLt5War9yeQ8auYn/Idmw==", "name": "nettle", "version": "3.10.1-1.el9", "kind": "binary", "source": { "id": "", "name": "nettle", "version": "3.10.1-1.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "bFvWffGqJWr7FWnI7K9NVw==": { "id": "bFvWffGqJWr7FWnI7K9NVw==", "name": "grep", "version": "3.6-5.el9", "kind": "binary", "source": { "id": "", "name": "grep", "version": "3.6-5.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "bemGVBhbDe9iV1Kjvd9hAA==": { "id": "bemGVBhbDe9iV1Kjvd9hAA==", "name": "libffi", "version": "3.4.2-8.el9", "kind": "binary", "source": { "id": "", "name": "libffi", "version": "3.4.2-8.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "bvKQIfHp90JS+LiY5WtU+w==": { "id": "bvKQIfHp90JS+LiY5WtU+w==", "name": "glib2", "version": "2.68.4-19.el9_8.1", "kind": "binary", "source": { "id": "", "name": "glib2", "version": "2.68.4-19.el9_8.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "dC9CoYt17eaqinGSVCfCxw==": { "id": "dC9CoYt17eaqinGSVCfCxw==", "name": "libattr", "version": "2.5.1-3.el9", "kind": "binary", "source": { "id": "", "name": "attr", "version": "2.5.1-3.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "de44cUqF23LvU0fOSvNRjA==": { "id": "de44cUqF23LvU0fOSvNRjA==", "name": "libevent", "version": "2.1.12-8.el9_4", "kind": "binary", "source": { "id": "", "name": "libevent", "version": "2.1.12-8.el9_4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "dpQG/pUwAqVv1OdQqnvylQ==": { "id": "dpQG/pUwAqVv1OdQqnvylQ==", "name": "libsigsegv", "version": "2.13-4.el9", "kind": "binary", "source": { "id": "", "name": "libsigsegv", "version": "2.13-4.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "e46hrGjNqSWudHlP8kB5TQ==": { "id": "e46hrGjNqSWudHlP8kB5TQ==", "name": "Konflux yarn builder", "version": "1779860795", "kind": "binary", "source": { "id": "Vtcppx964Xo7bbcHDlWWag==", "name": "Konflux yarn builder", "version": "1779860795", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779860795.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779860795.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "eF21TL12/odJlvaq9Hsuzg==": { "id": "eF21TL12/odJlvaq9Hsuzg==", "name": "p11-kit-trust", "version": "0.26.2-1.el9", "kind": "binary", "source": { "id": "", "name": "p11-kit", "version": "0.26.2-1.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "eRa7MZyiHBvsv7GPhkGKdg==": { "id": "eRa7MZyiHBvsv7GPhkGKdg==", "name": "lua-libs", "version": "5.4.4-4.el9", "kind": "binary", "source": { "id": "", "name": "lua", "version": "5.4.4-4.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "enagVWadN12gI5iPYugyvg==": { "id": "enagVWadN12gI5iPYugyvg==", "name": "gnupg2", "version": "2.3.3-5.el9_7", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.3.3-5.el9_7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "ewbqmzgK8Rzf739yT7IKUQ==": { "id": "ewbqmzgK8Rzf739yT7IKUQ==", "name": "ncurses-base", "version": "6.2-12.20210508.el9", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.2-12.20210508.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "f8lJd/yoDqE6O0RUQGqkpQ==": { "id": "f8lJd/yoDqE6O0RUQGqkpQ==", "name": "libusbx", "version": "1.0.26-1.el9", "kind": "binary", "source": { "id": "", "name": "libusbx", "version": "1.0.26-1.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "gsKPriszRNKAqMnHK+dXgw==": { "id": "gsKPriszRNKAqMnHK+dXgw==", "name": "libksba", "version": "1.5.1-7.el9", "kind": "binary", "source": { "id": "", "name": "libksba", "version": "1.5.1-7.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "hHreueaJ96AOxmI0383TIQ==": { "id": "hHreueaJ96AOxmI0383TIQ==", "name": "libdnf", "version": "0.69.0-18.el9", "kind": "binary", "source": { "id": "", "name": "libdnf", "version": "0.69.0-18.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "hYEisV19Dxn4PvCvxJFm5A==": { "id": "hYEisV19Dxn4PvCvxJFm5A==", "name": "lz4-libs", "version": "1.9.3-5.el9", "kind": "binary", "source": { "id": "", "name": "lz4", "version": "1.9.3-5.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "icCOAW3YxkHDgnEa2cteSA==": { "id": "icCOAW3YxkHDgnEa2cteSA==", "name": "nodejs", "version": "1:22.22.2-1.module+el9.7.0+24157+8ddb2461", "kind": "binary", "source": { "id": "", "name": "nodejs", "version": "22.22.2-1.module+el9.7.0+24157+8ddb2461", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "module": "nodejs:22", "arch": "x86_64", "cpe": "", "detector": null }, "ivNIwkLdGvkb89zNJZKIjQ==": { "id": "ivNIwkLdGvkb89zNJZKIjQ==", "name": "Konflux yarn builder", "version": "1786763159", "kind": "binary", "source": { "id": "/3dC79z2JmZ/i03s/r5MGQ==", "name": "Konflux yarn builder", "version": "1786763159", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "rhctag:1786763159.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "rhctag:1786763159.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "jAjaNW7NMGiv7HfByDu4RQ==": { "id": "jAjaNW7NMGiv7HfByDu4RQ==", "name": "alternatives", "version": "1.24-2.el9", "kind": "binary", "source": { "id": "", "name": "chkconfig", "version": "1.24-2.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "jEnEXZsP79wPnGLwBratuQ==": { "id": "jEnEXZsP79wPnGLwBratuQ==", "name": "openssl", "version": "1:3.5.5-2.el9_8", "kind": "binary", "source": { "id": "", "name": "openssl", "version": "3.5.5-2.el9_8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "jSB7glN8EEQ8tISPITn5pQ==": { "id": "jSB7glN8EEQ8tISPITn5pQ==", "name": "shadow-utils", "version": "2:4.9-16.el9", "kind": "binary", "source": { "id": "", "name": "shadow-utils", "version": "4.9-16.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "kFxhSjWy84mTZBM4XiZaeQ==": { "id": "kFxhSjWy84mTZBM4XiZaeQ==", "name": "setup", "version": "2.13.7-10.el9", "kind": "binary", "source": { "id": "", "name": "setup", "version": "2.13.7-10.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "kigiD4fuysu8/DeCr+ONKQ==": { "id": "kigiD4fuysu8/DeCr+ONKQ==", "name": "basesystem", "version": "11-13.el9", "kind": "binary", "source": { "id": "", "name": "basesystem", "version": "11-13.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "kp6BaioAZ30jbVeZkkzokA==": { "id": "kp6BaioAZ30jbVeZkkzokA==", "name": "libzstd", "version": "1.5.5-1.el9", "kind": "binary", "source": { "id": "", "name": "zstd", "version": "1.5.5-1.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "mK/FUfODp3MR7WS2xegPsw==": { "id": "mK/FUfODp3MR7WS2xegPsw==", "name": "langpacks-core-en", "version": "3.0-16.el9", "kind": "binary", "source": { "id": "", "name": "langpacks", "version": "3.0-16.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "mPqGnMbiXN6jP61aGbHvOA==": { "id": "mPqGnMbiXN6jP61aGbHvOA==", "name": "libyaml", "version": "0.2.5-7.el9", "kind": "binary", "source": { "id": "", "name": "libyaml", "version": "0.2.5-7.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "pKI3vM//04KzuTrMEsqZxQ==": { "id": "pKI3vM//04KzuTrMEsqZxQ==", "name": "Konflux yarn builder", "version": "1786763159", "kind": "ancestry", "source": { "id": "/3dC79z2JmZ/i03s/r5MGQ==", "name": "Konflux yarn builder", "version": "1786763159", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "rhctag:1786763159.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "rhctag:1786763159.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "qGoQ1lVBHBflNRoeTDzpoA==": { "id": "qGoQ1lVBHBflNRoeTDzpoA==", "name": "rpm-libs", "version": "4.16.1.3-40.el9", "kind": "binary", "source": { "id": "", "name": "rpm", "version": "4.16.1.3-40.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "qYSZ6aKFWol313IOGRXaug==": { "id": "qYSZ6aKFWol313IOGRXaug==", "name": "json-c", "version": "0.14-11.el9", "kind": "binary", "source": { "id": "", "name": "json-c", "version": "0.14-11.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "r13jqXkPJ02PeUmrpJHnSA==": { "id": "r13jqXkPJ02PeUmrpJHnSA==", "name": "libgcc", "version": "11.5.0-14.el9", "kind": "binary", "source": { "id": "", "name": "gcc", "version": "11.5.0-14.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "rC+O1MrO3khuR+Gi1/tvqA==": { "id": "rC+O1MrO3khuR+Gi1/tvqA==", "name": "mpfr", "version": "4.1.0-10.el9", "kind": "binary", "source": { "id": "", "name": "mpfr", "version": "4.1.0-10.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "rCLp3m64Catai9VuHvh3Lw==": { "id": "rCLp3m64Catai9VuHvh3Lw==", "name": "keyutils-libs", "version": "1.6.3-1.el9", "kind": "binary", "source": { "id": "", "name": "keyutils", "version": "1.6.3-1.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "rY/kE/V4JnxYoqV+lmc9mg==": { "id": "rY/kE/V4JnxYoqV+lmc9mg==", "name": "gawk", "version": "5.1.0-6.el9", "kind": "binary", "source": { "id": "", "name": "gawk", "version": "5.1.0-6.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "rd4/gPEUtK2p++ni1m1dDg==": { "id": "rd4/gPEUtK2p++ni1m1dDg==", "name": "libsepol", "version": "3.6-3.el9", "kind": "binary", "source": { "id": "", "name": "libsepol", "version": "3.6-3.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "s4D0cbFr4JfjY5l1vCuuXQ==": { "id": "s4D0cbFr4JfjY5l1vCuuXQ==", "name": "libsmartcols", "version": "2.37.4-25.el9", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.37.4-25.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "sx0C6L5COHIkv6yQQyPlbw==": { "id": "sx0C6L5COHIkv6yQQyPlbw==", "name": "libunistring", "version": "0.9.10-15.el9", "kind": "binary", "source": { "id": "", "name": "libunistring", "version": "0.9.10-15.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "u5TyEoU5GA6Z2czzwhMLiA==": { "id": "u5TyEoU5GA6Z2czzwhMLiA==", "name": "fonts-filesystem", "version": "1:2.0.5-7.el9.1", "kind": "binary", "source": { "id": "", "name": "fonts-rpm-macros", "version": "2.0.5-7.el9.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "uz56qUqp9s8PjH/5C8XCYA==": { "id": "uz56qUqp9s8PjH/5C8XCYA==", "name": "ubi9/nodejs-22-minimal", "version": "1779828950", "kind": "ancestry", "source": { "id": "2Q5QnVvn83+RyQcaQ745Gw==", "name": "ubi9/nodejs-22-minimal", "version": "1779828950", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779828950.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1779828950.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "w6X1O/naj1sTZnRBWDi6pw==": { "id": "w6X1O/naj1sTZnRBWDi6pw==", "name": "librepo", "version": "1.19.0-1.el9", "kind": "binary", "source": { "id": "", "name": "librepo", "version": "1.19.0-1.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "wJ6UaBi74Z5N+nH3gNGPKQ==": { "id": "wJ6UaBi74Z5N+nH3gNGPKQ==", "name": "systemd-libs", "version": "252-67.el9_8.2", "kind": "binary", "source": { "id": "", "name": "systemd", "version": "252-67.el9_8.2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "wsUUWQ2dQtO49MXEIan+Iw==": { "id": "wsUUWQ2dQtO49MXEIan+Iw==", "name": "gnutls", "version": "3.8.10-4.el9_8", "kind": "binary", "source": { "id": "", "name": "gnutls", "version": "3.8.10-4.el9_8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "wtWstARWoVJ6Jhp1LsdM3w==": { "id": "wtWstARWoVJ6Jhp1LsdM3w==", "name": "libblkid", "version": "2.37.4-25.el9", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.37.4-25.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "x4oijVhQU8BUwJwoFvk4QA==": { "id": "x4oijVhQU8BUwJwoFvk4QA==", "name": "libmodulemd", "version": "2.13.0-2.el9", "kind": "binary", "source": { "id": "", "name": "libmodulemd", "version": "2.13.0-2.el9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "yEp9fQVFIQAEDPCwC3GLmA==": { "id": "yEp9fQVFIQAEDPCwC3GLmA==", "name": "libsemanage", "version": "3.6-5.el9_6", "kind": "binary", "source": { "id": "", "name": "libsemanage", "version": "3.6-5.el9_6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null } }, "distributions": { "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7": { "id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "did": "rhel", "name": "Red Hat Enterprise Linux Server", "version": "9", "version_code_name": "", "version_id": "9", "arch": "", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "pretty_name": "Red Hat Enterprise Linux Server 9" } }, "repository": { "1b521834-1f1d-469b-b0cb-8a8457470bdf": { "id": "1b521834-1f1d-469b-b0cb-8a8457470bdf", "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhcc-container-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "3ecb146e-d75c-4ec5-a1af-5548662157b5": { "id": "3ecb146e-d75c-4ec5-a1af-5548662157b5", "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-9-for-x86_64-baseos-rpms", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "475c6940-2a8a-4763-88fa-5b6a93e49aa2": { "id": "475c6940-2a8a-4763-88fa-5b6a93e49aa2", "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-9-for-x86_64-appstream-rpms", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "55447650-b247-4012-965b-688c77cfb7e8": { "id": "55447650-b247-4012-965b-688c77cfb7e8", "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhcc-container-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "5e4ffe66-8da3-401a-96aa-810b11febccd": { "id": "5e4ffe66-8da3-401a-96aa-810b11febccd", "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhcc-container-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "792f7b02-064f-45ef-87a1-1cc23582d39d": { "id": "792f7b02-064f-45ef-87a1-1cc23582d39d", "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-9-for-x86_64-baseos-rpms", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "9cea1954-76f3-4e71-b37c-3e083c7efb2b": { "id": "9cea1954-76f3-4e71-b37c-3e083c7efb2b", "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-9-for-x86_64-appstream-rpms", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "9e71b28d-24aa-4458-857e-420738dc80c5": { "id": "9e71b28d-24aa-4458-857e-420738dc80c5", "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-9-for-x86_64-baseos-rpms", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "cad3277f-d1e3-4b52-af0f-0fdfe31de385": { "id": "cad3277f-d1e3-4b52-af0f-0fdfe31de385", "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-9-for-x86_64-baseos-rpms", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "e0dd0459-f057-4f49-96bd-3e17c78bdb08": { "id": "e0dd0459-f057-4f49-96bd-3e17c78bdb08", "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhcc-container-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" } }, "environments": { "+A7/nzEXX3Q/xJZ50VMnlQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "+X1MdmtPTbyDb/wq7joJhA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "+lY+UUpyo/55vgqUUOuejg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "475c6940-2a8a-4763-88fa-5b6a93e49aa2" ] } ], "/3dC79z2JmZ/i03s/r5MGQ==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:227924901b6441a2d1ad25248a64ff130c81f46b23438568603f9a6ddabcce15", "distribution_id": "", "repository_ids": [ "55447650-b247-4012-965b-688c77cfb7e8" ] } ], "/Jp1+jxuGVB8kf+IVvkLrQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "9e71b28d-24aa-4458-857e-420738dc80c5", "cad3277f-d1e3-4b52-af0f-0fdfe31de385" ] } ], "/L1kFEoHZTukrNTCQLypFQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "/O7rOBo1qRMFm3q3Kf3mEw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "/T3unXthUSp/zJaVYpuQfQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "/THiuz93dsCZJETS3A4Xtw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "/TtZcCefM8OHHof3XKTmHw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "2Q5QnVvn83+RyQcaQ745Gw==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": [ "e0dd0459-f057-4f49-96bd-3e17c78bdb08" ] } ], "2daNj17YVWGx0KV9TCa6Ag==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "2gCbp4kt+cF44NF/LqukDg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "2s+WoHFOH6YMNQHNWXDuRg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "40CUjHKsWI2oXBGOxO5+Kg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "4iqV8aUHNk1o4YJaOnnBOg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "5JAFUJWmy04+T6x2oJw2jg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "5T6eFHgFgSAq68A4uhcd5Q==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:69e552447849ab5a47bc7d42b210b9b06638bf6bbecaf4aa12b0161d1c3ee4e2", "distribution_id": "", "repository_ids": [ "5e4ffe66-8da3-401a-96aa-810b11febccd" ] } ], "6sUhut8O1JC80Cua0ljqAw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "73dAQtEmA5DMG7vTc637ig==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "7cpIREEQnkaI7dbmWgmrvg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "7mDaaxs3ev+uNEDYC97U3Q==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "7vssDPaHKfFKMLimKBo7Gw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "87EcTL94JiygUQLwYuL2AQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "9e71b28d-24aa-4458-857e-420738dc80c5", "cad3277f-d1e3-4b52-af0f-0fdfe31de385" ] } ], "933bwLexZewNfaJWrKZAJw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "9olIUlLHZMdoUMju+8diyQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "9wWP1WdTrVCykiUHcmStWw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "AYWPcXxdUay0d/qxFjyxxA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "BQhiFmX4hLYteW4oRCLTSA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "BRLVvSCW1qZQlEQR2x48fQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "CQ7LW8sdHcbka0B3IpMM1Q==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "9e71b28d-24aa-4458-857e-420738dc80c5", "cad3277f-d1e3-4b52-af0f-0fdfe31de385" ] } ], "CS6z0/SKwjMOr6VBFQ1+lw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "DU6/TA2uNulT+q7hBfw/2w==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "DVT5EsNYhhc4TADNn+PvwA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "DrLq8qfU1bfE8o8AfdvkrQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "E+86APTf07XmsaHw75dOYQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "EsA7Dv6B+IUQ6wmp9oBkLA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "G+944+S8mxpoNj+2qy2tQA==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": [ "1b521834-1f1d-469b-b0cb-8a8457470bdf" ] } ], "G61ZL2SOHR2qgvQfi118gw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "HKlRsQZtXaa3HoNDv500tg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "HQdWvmyUSqtI3UTY0T4JiQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "HyBX75cInDsq7NDTuOp31w==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "I16VSEydeiRYB1TSf5694A==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "I37d1PMRX1UakcBjVAt7xw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "I5cVace6fizyXVtumzW7pg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "IwPtZhSvUd42Go1Kioy9+Q==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "JKP7JzVg7UGaAz4VrH03lQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "9cea1954-76f3-4e71-b37c-3e083c7efb2b" ] } ], "KF5C+zKu/uFB7knCqOvDAQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "KxFesLSRtesBY4rvnejKaQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "L8X3lmrBrNsXuTdVU8i99A==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": [ "1b521834-1f1d-469b-b0cb-8a8457470bdf" ] } ], "Lwqn0aweLQLZmo12VvYcog==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "MA8EMjMpjkzMuD4Zo1clCg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "MDH8Zt4oQWDiYk9qFV5Lbg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "NSiprMdkK5/5pxuNNJOh2A==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "NdCY2/S+syamLH224R4hug==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "9cea1954-76f3-4e71-b37c-3e083c7efb2b" ] } ], "OCIjbR16ktOEiFK36r0WNw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "OgwdUybWl/HQYbnPTE4Psw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "Ohssf0Jzlafd9vtrrUKCXg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "P5Om9zCJ/QZ+hnrEvj6fGw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "PIk2BBAWexCFofMi5q03RA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "PZXvGa4khHd2n6o73hJ/Pg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "PvRYqRcexo7w5I906InQwA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "QBTcpn4pqa+eJ8D8UVEiVg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "RXh3fimX8fGZeCt4chJEiA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "RcZCiT+ycHJQmpV3/FuYsw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "475c6940-2a8a-4763-88fa-5b6a93e49aa2" ] } ], "S8p9UGak1oycptcpYp/1eg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "SUb+Lyjw6FDmZnaJmfkg2w==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "T1283MiUUtcDMYRJTXeZzA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "TPIRq84Pr3a6ywzPeCr3Pw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "To0NR+oyXDu1CYJfmVGurQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "U+4qCFcZOyPHsmmdD44CrQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "VS7DY+9FnbHX9Fem83CwXQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "475c6940-2a8a-4763-88fa-5b6a93e49aa2" ] } ], "VV2Z1ngTs6sGvt5SrayPCg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "VX9V+Y680L2xf2tBREdpCw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "Vtcppx964Xo7bbcHDlWWag==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:69e552447849ab5a47bc7d42b210b9b06638bf6bbecaf4aa12b0161d1c3ee4e2", "distribution_id": "", "repository_ids": [ "5e4ffe66-8da3-401a-96aa-810b11febccd" ] } ], "W7uBqJb8l9AhSXjNg1JZQg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "WVajSGKLGm8z6I23XYAhLQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "WwxYi5XJkmSTp/yi0EXIcQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "XG5+bW8np2NedSy/od6z8Q==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "Xa5h200SIiVSiheE2PRVIg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "475c6940-2a8a-4763-88fa-5b6a93e49aa2" ] } ], "XaWKjZmgTSvC2q3B/R5UNg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "XwbkaIGCYyq6BjBMVZ1wzw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "a7G//+ROQ5yESl9cZ0bfcg==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": [ "e0dd0459-f057-4f49-96bd-3e17c78bdb08" ] } ], "aOUBKwKo1Yas7KseQYf5lQ==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": [ "1b521834-1f1d-469b-b0cb-8a8457470bdf" ] } ], "arLt5War9yeQ8auYn/Idmw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "bFvWffGqJWr7FWnI7K9NVw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "bemGVBhbDe9iV1Kjvd9hAA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "bvKQIfHp90JS+LiY5WtU+w==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "dC9CoYt17eaqinGSVCfCxw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "de44cUqF23LvU0fOSvNRjA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "dpQG/pUwAqVv1OdQqnvylQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "e46hrGjNqSWudHlP8kB5TQ==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:69e552447849ab5a47bc7d42b210b9b06638bf6bbecaf4aa12b0161d1c3ee4e2", "distribution_id": "", "repository_ids": [ "5e4ffe66-8da3-401a-96aa-810b11febccd" ] } ], "eF21TL12/odJlvaq9Hsuzg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "eRa7MZyiHBvsv7GPhkGKdg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "enagVWadN12gI5iPYugyvg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "ewbqmzgK8Rzf739yT7IKUQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "f8lJd/yoDqE6O0RUQGqkpQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "gsKPriszRNKAqMnHK+dXgw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "hHreueaJ96AOxmI0383TIQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "hYEisV19Dxn4PvCvxJFm5A==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "icCOAW3YxkHDgnEa2cteSA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "475c6940-2a8a-4763-88fa-5b6a93e49aa2" ] } ], "ivNIwkLdGvkb89zNJZKIjQ==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:227924901b6441a2d1ad25248a64ff130c81f46b23438568603f9a6ddabcce15", "distribution_id": "", "repository_ids": [ "55447650-b247-4012-965b-688c77cfb7e8" ] } ], "jAjaNW7NMGiv7HfByDu4RQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "jEnEXZsP79wPnGLwBratuQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "9e71b28d-24aa-4458-857e-420738dc80c5", "cad3277f-d1e3-4b52-af0f-0fdfe31de385" ] } ], "jSB7glN8EEQ8tISPITn5pQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "kFxhSjWy84mTZBM4XiZaeQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "kigiD4fuysu8/DeCr+ONKQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "kp6BaioAZ30jbVeZkkzokA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "mK/FUfODp3MR7WS2xegPsw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "9cea1954-76f3-4e71-b37c-3e083c7efb2b" ] } ], "mPqGnMbiXN6jP61aGbHvOA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "pKI3vM//04KzuTrMEsqZxQ==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:227924901b6441a2d1ad25248a64ff130c81f46b23438568603f9a6ddabcce15", "distribution_id": "", "repository_ids": [ "55447650-b247-4012-965b-688c77cfb7e8" ] } ], "qGoQ1lVBHBflNRoeTDzpoA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "qYSZ6aKFWol313IOGRXaug==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "r13jqXkPJ02PeUmrpJHnSA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "rC+O1MrO3khuR+Gi1/tvqA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "rCLp3m64Catai9VuHvh3Lw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "rY/kE/V4JnxYoqV+lmc9mg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "rd4/gPEUtK2p++ni1m1dDg==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "s4D0cbFr4JfjY5l1vCuuXQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "sx0C6L5COHIkv6yQQyPlbw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "u5TyEoU5GA6Z2czzwhMLiA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "uz56qUqp9s8PjH/5C8XCYA==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:17f2ca0f01124ceb55c616ed0325fdf9fcb92afa198acc4d1d1f5410ca7e9e09", "distribution_id": "", "repository_ids": [ "e0dd0459-f057-4f49-96bd-3e17c78bdb08" ] } ], "w6X1O/naj1sTZnRBWDi6pw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "wJ6UaBi74Z5N+nH3gNGPKQ==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "wsUUWQ2dQtO49MXEIan+Iw==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "wtWstARWoVJ6Jhp1LsdM3w==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "x4oijVhQU8BUwJwoFvk4QA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ], "yEp9fQVFIQAEDPCwC3GLmA==": [ { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "", "repository_ids": null }, { "package_db": "sqlite:var/lib/rpm", "introduced_in": "sha256:1a36cba5a1d845cee5e57e6f2dc9f828b4cc53403e207333e2220cd426126f13", "distribution_id": "fd8aa1a9-c000-43f5-be13-5f2c1ba98ff7", "repository_ids": [ "3ecb146e-d75c-4ec5-a1af-5548662157b5", "792f7b02-064f-45ef-87a1-1cc23582d39d" ] } ] }, "vulnerabilities": { "+20onLS/dWLg9saGZqMvvA==": { "id": "+20onLS/dWLg9saGZqMvvA==", "updater": "rhel-vex", "name": "CVE-2026-42766", "description": "A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42766 https://bugzilla.redhat.com/show_bug.cgi?id=2481890 https://www.cve.org/CVERecord?id=CVE-2026-42766 https://nvd.nist.gov/vuln/detail/CVE-2026-42766 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42766.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+81WHs4+NlxNNP8OWMLJ2g==": { "id": "+81WHs4+NlxNNP8OWMLJ2g==", "updater": "rhel-vex", "name": "CVE-2026-33056", "description": "A flaw was found in tar-rs, a Rust library for reading and writing tar archives. When unpacking a crafted tar archive, an attacker can exploit a symbolic link vulnerability. By including a symlink followed by a directory with the same name, the library incorrectly applies file permissions to the symlink's target. This allows an attacker to modify the permissions of arbitrary directories outside the intended extraction location.", "issued": "2026-03-20T07:11:10Z", "links": "https://access.redhat.com/security/cve/CVE-2026-33056 https://bugzilla.redhat.com/show_bug.cgi?id=2449490 https://www.cve.org/CVERecord?id=CVE-2026-33056 https://nvd.nist.gov/vuln/detail/CVE-2026-33056 https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446 https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33056.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+8vzuOrwVwjhz/n9cpNEEQ==": { "id": "+8vzuOrwVwjhz/n9cpNEEQ==", "updater": "rhel-vex", "name": "CVE-2026-6733", "description": "A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici's HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.", "issued": "2026-06-17T17:14:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6733 https://bugzilla.redhat.com/show_bug.cgi?id=2490006 https://www.cve.org/CVERecord?id=CVE-2026-6733 https://nvd.nist.gov/vuln/detail/CVE-2026-6733 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 https://hackerone.com/reports/3582376 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6733.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+DR5Qfe30tw0byM4w3zykQ==": { "id": "+DR5Qfe30tw0byM4w3zykQ==", "updater": "rhel-vex", "name": "CVE-2026-16118", "description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.", "issued": "2026-07-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-16118 https://bugzilla.redhat.com/show_bug.cgi?id=2501732 https://www.cve.org/CVERecord?id=CVE-2026-16118 https://nvd.nist.gov/vuln/detail/CVE-2026-16118 https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16118.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+Kc8jbRzLLDVqPaeFngWtQ==": { "id": "+Kc8jbRzLLDVqPaeFngWtQ==", "updater": "rhel-vex", "name": "CVE-2026-48618", "description": "A flaw was found in Node.js. This flaw involves a mismatch in how Node.js handles TLS (Transport Layer Security) hostnames and unicode dot separators during authentication. This mismatch can lead to a wildcard-depth authentication bypass. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access and confidentiality impact.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48618 https://bugzilla.redhat.com/show_bug.cgi?id=2493337 https://www.cve.org/CVERecord?id=CVE-2026-48618 https://nvd.nist.gov/vuln/detail/CVE-2026-48618 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+R/6bpHEFR4SpBeguCorTQ==": { "id": "+R/6bpHEFR4SpBeguCorTQ==", "updater": "rhel-vex", "name": "CVE-2026-2673", "description": "A key group selection preference flaw has been discovered in OpenSSL. An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the \"DEFAULT\" keyword. A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.", "issued": "2026-03-13T13:23:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-2673 https://bugzilla.redhat.com/show_bug.cgi?id=2447327 https://www.cve.org/CVERecord?id=CVE-2026-2673 https://nvd.nist.gov/vuln/detail/CVE-2026-2673 https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34 https://openssl-library.org/news/secadv/20260313.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2673.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-fips-provider", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+TrS27bZKgEeir9pISurnQ==": { "id": "+TrS27bZKgEeir9pISurnQ==", "updater": "rhel-vex", "name": "CVE-2026-5773", "description": "A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5773 https://bugzilla.redhat.com/show_bug.cgi?id=2461201 https://www.cve.org/CVERecord?id=CVE-2026-5773 https://nvd.nist.gov/vuln/detail/CVE-2026-5773 https://curl.se/docs/CVE-2026-5773.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5773.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+p1B+LZP5hvhPeU88puOfg==": { "id": "+p1B+LZP5hvhPeU88puOfg==", "updater": "rhel-vex", "name": "CVE-2026-48930", "description": "A flaw was found in Node.js. This vulnerability in the TLS (Transport Layer Security) hostname handling allows embedded null characters in hostnames. This can lead to silent authority rebinding, potentially enabling an attacker to redirect network traffic to an unintended server and disclose sensitive information.", "issued": "2026-06-26T01:14:37Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48930 https://bugzilla.redhat.com/show_bug.cgi?id=2493326 https://www.cve.org/CVERecord?id=CVE-2026-48930 https://nvd.nist.gov/vuln/detail/CVE-2026-48930 https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e https://hackerone.com/reports/3656716 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48930.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/7Wi/I65INeazWgOf1LTAg==": { "id": "/7Wi/I65INeazWgOf1LTAg==", "updater": "rhel-vex", "name": "CVE-2026-48935", "description": "A flaw was found in Node.js. The Permission API allows a local user to modify file metadata on paths that have been explicitly set as read-only. This can lead to unauthorized changes in file properties, impacting the integrity of the file system.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48935 https://bugzilla.redhat.com/show_bug.cgi?id=2493329 https://www.cve.org/CVERecord?id=CVE-2026-48935 https://nvd.nist.gov/vuln/detail/CVE-2026-48935 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48935.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/9MMSCBwxCiKjJobh+tDpw==": { "id": "/9MMSCBwxCiKjJobh+tDpw==", "updater": "rhel-vex", "name": "CVE-2026-42766", "description": "A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42766 https://bugzilla.redhat.com/show_bug.cgi?id=2481890 https://www.cve.org/CVERecord?id=CVE-2026-42766 https://nvd.nist.gov/vuln/detail/CVE-2026-42766 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42766.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/DjJHQ4LUqD/kDDEZQnGMQ==": { "id": "/DjJHQ4LUqD/kDDEZQnGMQ==", "updater": "rhel-vex", "name": "CVE-2026-18477", "description": "A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.", "issued": "2026-07-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-18477 https://bugzilla.redhat.com/show_bug.cgi?id=2509735 https://www.cve.org/CVERecord?id=CVE-2026-18477 https://nvd.nist.gov/vuln/detail/CVE-2026-18477 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18477.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/GP9UYzgnUNp/vOMMDf7mw==": { "id": "/GP9UYzgnUNp/vOMMDf7mw==", "updater": "rhel-vex", "name": "CVE-2026-16517", "description": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.", "issued": "2026-07-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-16517 https://bugzilla.redhat.com/show_bug.cgi?id=2505492 https://www.cve.org/CVERecord?id=CVE-2026-16517 https://nvd.nist.gov/vuln/detail/CVE-2026-16517 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16517.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/Q70+j219nLwNP4Phg4sag==": { "id": "/Q70+j219nLwNP4Phg4sag==", "updater": "rhel-vex", "name": "CVE-2026-6653", "description": "A flaw was found in libxml2. A remote attacker can exploit a use-after-free vulnerability in the `xmlParseInternalSubset` function by providing maliciously crafted XML input. This improper handling of entity resolution can lead to a denial-of-service (DoS), making the affected system or application unavailable.", "issued": "2026-06-22T12:40:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6653 https://bugzilla.redhat.com/show_bug.cgi?id=2491354 https://www.cve.org/CVERecord?id=CVE-2026-6653 https://nvd.nist.gov/vuln/detail/CVE-2026-6653 https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260 https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6653.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/pEYCNwBz8VXiXwXl+mS3w==": { "id": "/pEYCNwBz8VXiXwXl+mS3w==", "updater": "rhel-vex", "name": "CVE-2026-6238", "description": "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.", "issued": "2026-04-28T16:43:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-274.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/rrV/dLSeVDaHUnAvPeh7A==": { "id": "/rrV/dLSeVDaHUnAvPeh7A==", "updater": "rhel-vex", "name": "CVE-2026-8927", "description": "A flaw was found in libcurl. When reusing a libcurl handle for sequential transfers with environment-variable proxy configuration, the library does not properly clear the proxy authentication state. This oversight can lead to the unintended disclosure of `Proxy-Authorization` headers to an incorrect proxy, potentially exposing sensitive authentication information to an unauthorized entity. This is an information disclosure vulnerability.", "issued": "2026-07-03T06:16:06Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8927 https://bugzilla.redhat.com/show_bug.cgi?id=2496769 https://www.cve.org/CVERecord?id=CVE-2026-8927 https://nvd.nist.gov/vuln/detail/CVE-2026-8927 https://curl.se/docs/CVE-2026-8927.html https://curl.se/docs/CVE-2026-8927.json https://hackerone.com/reports/3744543 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8927.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "High", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/s8Q0HsneAZhk9Mgclm/OA==": { "id": "/s8Q0HsneAZhk9Mgclm/OA==", "updater": "rhel-vex", "name": "CVE-2026-45445", "description": "A flaw was found in OpenSSL. Applications that use the AES-OCB encryption method with a specific one-shot interface (EVP_Cipher()) will have their provided Initialization Vector (IV) silently discarded. This leads to the same internal cryptographic value being used repeatedly, which compromises the confidentiality of encrypted data. Additionally, this issue allows for the universal forgery of authentication tags, undermining the integrity of communications.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-45445 https://bugzilla.redhat.com/show_bug.cgi?id=2481896 https://www.cve.org/CVERecord?id=CVE-2026-45445 https://nvd.nist.gov/vuln/detail/CVE-2026-45445 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45445.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "07xwapz2PAAGV6vMF10zQw==": { "id": "07xwapz2PAAGV6vMF10zQw==", "updater": "rhel-vex", "name": "CVE-2026-5928", "description": "A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.", "issued": "2026-04-20T20:37:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-274.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0E1VjQWdmolR9lr9ElIZZQ==": { "id": "0E1VjQWdmolR9lr9ElIZZQ==", "updater": "rhel-vex", "name": "CVE-2026-28389", "description": "A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-28389 https://bugzilla.redhat.com/show_bug.cgi?id=2451096 https://www.cve.org/CVERecord?id=CVE-2026-28389 https://nvd.nist.gov/vuln/detail/CVE-2026-28389 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28389.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0hc+Z9xWtVy4dEgLyf7GUQ==": { "id": "0hc+Z9xWtVy4dEgLyf7GUQ==", "updater": "rhel-vex", "name": "CVE-2026-59873", "description": "A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.", "issued": "2026-07-08T15:22:40Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59873 https://bugzilla.redhat.com/show_bug.cgi?id=2498120 https://www.cve.org/CVERecord?id=CVE-2026-59873 https://nvd.nist.gov/vuln/detail/CVE-2026-59873 https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3 https://github.com/isaacs/node-tar/releases/tag/v7.5.19 https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59873.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0q4mJ3RDNOZ/qRqKXOz7Tg==": { "id": "0q4mJ3RDNOZ/qRqKXOz7Tg==", "updater": "rhel-vex", "name": "CVE-2026-48864", "description": "A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.", "issued": "2026-05-26T16:07:55Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48864 https://bugzilla.redhat.com/show_bug.cgi?id=2460425 https://www.cve.org/CVERecord?id=CVE-2026-48864 https://nvd.nist.gov/vuln/detail/CVE-2026-48864 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48864.json https://access.redhat.com/errata/RHSA-2026:39315", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libsolv", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.7.24-6.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0u4nnKNMeZ58/8R+sWLPSQ==": { "id": "0u4nnKNMeZ58/8R+sWLPSQ==", "updater": "rhel-vex", "name": "CVE-2026-48928", "description": "A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48928 https://bugzilla.redhat.com/show_bug.cgi?id=2493333 https://www.cve.org/CVERecord?id=CVE-2026-48928 https://nvd.nist.gov/vuln/detail/CVE-2026-48928 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48928.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1I5Zdk3zr6CO9kf+WEea4Q==": { "id": "1I5Zdk3zr6CO9kf+WEea4Q==", "updater": "rhel-vex", "name": "CVE-2026-5450", "description": "A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.", "issued": "2026-04-20T20:55:41Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-272.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1npmxgSnoYj2MyAhQMaE7g==": { "id": "1npmxgSnoYj2MyAhQMaE7g==", "updater": "rhel-vex", "name": "CVE-2026-27171", "description": "A flaw was found in zlib. An attacker providing specially crafted input to the `crc32_combine64` or `crc32_combine_gen64` functions could trigger an infinite loop within the `x2nmodp` function. This leads to excessive CPU consumption, which can result in a Denial of Service (DoS) for the affected system.", "issued": "2026-02-18T02:36:19Z", "links": "https://access.redhat.com/security/cve/CVE-2026-27171 https://bugzilla.redhat.com/show_bug.cgi?id=2440530 https://www.cve.org/CVERecord?id=CVE-2026-27171 https://nvd.nist.gov/vuln/detail/CVE-2026-27171 https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/ https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf https://github.com/madler/zlib/issues/904 https://github.com/madler/zlib/releases/tag/v1.3.2 https://ostif.org/zlib-audit-complete/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27171.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "zlib", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1r+syFhyATToDtkOkMLqDw==": { "id": "1r+syFhyATToDtkOkMLqDw==", "updater": "rhel-vex", "name": "CVE-2026-48930", "description": "A flaw was found in Node.js. This vulnerability in the TLS (Transport Layer Security) hostname handling allows embedded null characters in hostnames. This can lead to silent authority rebinding, potentially enabling an attacker to redirect network traffic to an unintended server and disclose sensitive information.", "issued": "2026-06-26T01:14:37Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48930 https://bugzilla.redhat.com/show_bug.cgi?id=2493326 https://www.cve.org/CVERecord?id=CVE-2026-48930 https://nvd.nist.gov/vuln/detail/CVE-2026-48930 https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e https://hackerone.com/reports/3656716 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48930.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2Apbu80O6R41VOd2ICqODw==": { "id": "2Apbu80O6R41VOd2ICqODw==", "updater": "rhel-vex", "name": "CVE-2026-9076", "description": "A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9076 https://bugzilla.redhat.com/show_bug.cgi?id=2481880 https://www.cve.org/CVERecord?id=CVE-2026-9076 https://nvd.nist.gov/vuln/detail/CVE-2026-9076 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9076.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2F6XtsAYpNWm5w+Rwl/tuQ==": { "id": "2F6XtsAYpNWm5w+Rwl/tuQ==", "updater": "rhel-vex", "name": "CVE-2026-57062", "description": "A flaw in GnuPG's gpgsm component improperly handles the Cryptographic Message Syntax (CMS) format for AES-GCM. By accepting an authentication tag length of 4 bytes instead of the required 12 bytes, this vulnerability allows for a low-impact data integrity issue where the cryptographic validity of messages could be compromised.", "issued": "2026-06-23T17:26:25Z", "links": "https://access.redhat.com/security/cve/CVE-2026-57062 https://bugzilla.redhat.com/show_bug.cgi?id=2491859 https://www.cve.org/CVERecord?id=CVE-2026-57062 https://nvd.nist.gov/vuln/detail/CVE-2026-57062 https://blog.calif.io/p/how-to-format-a-ciphertext https://www.gnupg.org/download/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57062.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2TDjlt2gAEWsLyBBPigFYw==": { "id": "2TDjlt2gAEWsLyBBPigFYw==", "updater": "rhel-vex", "name": "CVE-2024-13176", "description": "A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected.", "issued": "2025-01-20T13:29:57Z", "links": "https://access.redhat.com/security/cve/CVE-2024-13176 https://bugzilla.redhat.com/show_bug.cgi?id=2338999 https://www.cve.org/CVERecord?id=CVE-2024-13176 https://nvd.nist.gov/vuln/detail/CVE-2024-13176 https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-13176.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2eh/JThmMghcGbhP7jHOJw==": { "id": "2eh/JThmMghcGbhP7jHOJw==", "updater": "rhel-vex", "name": "CVE-2026-31790", "description": "A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-31790 https://bugzilla.redhat.com/show_bug.cgi?id=2451094 https://www.cve.org/CVERecord?id=CVE-2026-31790 https://nvd.nist.gov/vuln/detail/CVE-2026-31790 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31790.json https://access.redhat.com/errata/RHSA-2026:27744", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-fips-provider", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.0.7-11.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2fFhV4f06vNDz4aMbkPOZA==": { "id": "2fFhV4f06vNDz4aMbkPOZA==", "updater": "rhel-vex", "name": "CVE-2026-28390", "description": "A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS).", "issued": "2026-04-07T22:00:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-28390 https://bugzilla.redhat.com/show_bug.cgi?id=2456314 https://www.cve.org/CVERecord?id=CVE-2026-28390 https://nvd.nist.gov/vuln/detail/CVE-2026-28390 https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6 https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4 https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788 https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28390.json https://access.redhat.com/errata/RHSA-2026:22312", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-3.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2w9brA/+oZ5OEdpav+Dkzw==": { "id": "2w9brA/+oZ5OEdpav+Dkzw==", "updater": "rhel-vex", "name": "CVE-2026-31790", "description": "A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-31790 https://bugzilla.redhat.com/show_bug.cgi?id=2451094 https://www.cve.org/CVERecord?id=CVE-2026-31790 https://nvd.nist.gov/vuln/detail/CVE-2026-31790 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31790.json https://access.redhat.com/errata/RHSA-2026:27744", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-fips-provider-so", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.0.7-11.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3UNcgW64Eji4iyY2ZDB1cg==": { "id": "3UNcgW64Eji4iyY2ZDB1cg==", "updater": "rhel-vex", "name": "CVE-2026-3783", "description": "A flaw was found in curl. When an OAuth2 bearer token is used for an HTTP(S) transfer that redirects to a second URL, curl could unintentionally leak the token. This occurs if the second hostname has entries in the `.netrc` file, allowing the bearer token intended for the first host to be sent to the redirected host. This information disclosure could allow an attacker to gain unauthorized access.", "issued": "2026-03-11T10:09:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3783 https://bugzilla.redhat.com/show_bug.cgi?id=2446450 https://www.cve.org/CVERecord?id=CVE-2026-3783 https://nvd.nist.gov/vuln/detail/CVE-2026-3783 http://www.openwall.com/lists/oss-security/2026/03/11/2 https://curl.se/docs/CVE-2026-3783.html https://curl.se/docs/CVE-2026-3783.json https://hackerone.com/reports/3583983 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3783.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3xFSeDOxGkdisnqW9w6B+Q==": { "id": "3xFSeDOxGkdisnqW9w6B+Q==", "updater": "rhel-vex", "name": "CVE-2026-53655", "description": "A flaw was found in node-tar. This vulnerability arises because node-tar incorrectly applies PAX extended header size records to subsequent intermediary metadata headers, leading to a desynchronization of the tar stream cursor compared to other standard tar implementations. A remote attacker could exploit this by crafting a malicious archive, causing different interpretations of archive contents between node-tar and other tools. This could allow an attacker to hide malicious files or sensitive information from security scanners that rely on different tar parsing libraries, potentially leading to information disclosure or bypassing security controls.", "issued": "2026-06-22T14:55:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-53655 https://bugzilla.redhat.com/show_bug.cgi?id=2491423 https://www.cve.org/CVERecord?id=CVE-2026-53655 https://nvd.nist.gov/vuln/detail/CVE-2026-53655 https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53655.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3zxG1J6bDKAhZ9wlUE9Y4g==": { "id": "3zxG1J6bDKAhZ9wlUE9Y4g==", "updater": "rhel-vex", "name": "CVE-2026-48935", "description": "A flaw was found in Node.js. The Permission API allows a local user to modify file metadata on paths that have been explicitly set as read-only. This can lead to unauthorized changes in file properties, impacting the integrity of the file system.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48935 https://bugzilla.redhat.com/show_bug.cgi?id=2493329 https://www.cve.org/CVERecord?id=CVE-2026-48935 https://nvd.nist.gov/vuln/detail/CVE-2026-48935 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48935.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "40wPd5q9E1sRluf3JeA8hw==": { "id": "40wPd5q9E1sRluf3JeA8hw==", "updater": "rhel-vex", "name": "CVE-2026-42764", "description": "A flaw was found in the OpenSSL QUIC (Quick UDP Internet Connections) server. A remote attacker could send a specially crafted QUIC initial packet with an invalid token. If the server's address validation is explicitly disabled, this could lead to a NULL pointer dereference, causing the server process to terminate abnormally and resulting in a Denial of Service (DoS).", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42764 https://bugzilla.redhat.com/show_bug.cgi?id=2481887 https://www.cve.org/CVERecord?id=CVE-2026-42764 https://nvd.nist.gov/vuln/detail/CVE-2026-42764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42764.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "41OUTxSbBLQGne4TzJuTQg==": { "id": "41OUTxSbBLQGne4TzJuTQg==", "updater": "rhel-vex", "name": "CVE-2026-2673", "description": "A key group selection preference flaw has been discovered in OpenSSL. An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the \"DEFAULT\" keyword. A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.", "issued": "2026-03-13T13:23:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-2673 https://bugzilla.redhat.com/show_bug.cgi?id=2447327 https://www.cve.org/CVERecord?id=CVE-2026-2673 https://nvd.nist.gov/vuln/detail/CVE-2026-2673 https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34 https://openssl-library.org/news/secadv/20260313.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2673.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "45NlEwqpAAjjjCgRktdWjA==": { "id": "45NlEwqpAAjjjCgRktdWjA==", "updater": "rhel-vex", "name": "CVE-2026-48930", "description": "A flaw was found in Node.js. This vulnerability in the TLS (Transport Layer Security) hostname handling allows embedded null characters in hostnames. This can lead to silent authority rebinding, potentially enabling an attacker to redirect network traffic to an unintended server and disclose sensitive information.", "issued": "2026-06-26T01:14:37Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48930 https://bugzilla.redhat.com/show_bug.cgi?id=2493326 https://www.cve.org/CVERecord?id=CVE-2026-48930 https://nvd.nist.gov/vuln/detail/CVE-2026-48930 https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e https://hackerone.com/reports/3656716 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48930.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4XO5TL/zvh/gBT0sz3RSYw==": { "id": "4XO5TL/zvh/gBT0sz3RSYw==", "updater": "rhel-vex", "name": "CVE-2026-13149", "description": "A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.", "issued": "2026-06-30T08:30:34Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13149 https://bugzilla.redhat.com/show_bug.cgi?id=2494813 https://www.cve.org/CVERecord?id=CVE-2026-13149 https://nvd.nist.gov/vuln/detail/CVE-2026-13149 https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754 https://www.npmjs.com/package/brace-expansion https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4aJ6IaFsuGhRpz+mkfUGqQ==": { "id": "4aJ6IaFsuGhRpz+mkfUGqQ==", "updater": "rhel-vex", "name": "CVE-2026-48615", "description": "A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48615 https://bugzilla.redhat.com/show_bug.cgi?id=2493335 https://www.cve.org/CVERecord?id=CVE-2026-48615 https://nvd.nist.gov/vuln/detail/CVE-2026-48615 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48615.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4kuxrTpUDtZ3uFOEEztq9g==": { "id": "4kuxrTpUDtZ3uFOEEztq9g==", "updater": "rhel-vex", "name": "CVE-2026-48933", "description": "A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48933 https://bugzilla.redhat.com/show_bug.cgi?id=2493331 https://www.cve.org/CVERecord?id=CVE-2026-48933 https://nvd.nist.gov/vuln/detail/CVE-2026-48933 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5BksN0izCeDRrtFMsNCyvg==": { "id": "5BksN0izCeDRrtFMsNCyvg==", "updater": "rhel-vex", "name": "CVE-2025-9232", "description": "A flaw was found in the OpenSSL HTTP client API no_proxy handling. This vulnerability allows an application level denial of service (application crash) via an attacker-controlled IPv6 URL when the no_proxy environment variable is set.", "issued": "2025-09-30T23:59:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-9232 https://bugzilla.redhat.com/show_bug.cgi?id=2396056 https://www.cve.org/CVERecord?id=CVE-2025-9232 https://nvd.nist.gov/vuln/detail/CVE-2025-9232 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9232.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5JPRWlHhzvwdgcYt2OnpZg==": { "id": "5JPRWlHhzvwdgcYt2OnpZg==", "updater": "rhel-vex", "name": "CVE-2026-58013", "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.", "issued": "2026-04-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58013 https://bugzilla.redhat.com/show_bug.cgi?id=2492248 https://www.cve.org/CVERecord?id=CVE-2026-58013 https://nvd.nist.gov/vuln/detail/CVE-2026-58013 https://gitlab.gnome.org/GNOME/glib/-/issues/3925 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58013.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5VGw1oph7DgrzGqxDXSJIA==": { "id": "5VGw1oph7DgrzGqxDXSJIA==", "updater": "rhel-vex", "name": "CVE-2026-42250", "description": "A flaw was found in bzip2. The bzip2recover utility contains an off-by-one error that allows a local attacker to cause an out-of-bounds write to a global buffer by processing a specially crafted file. This memory corruption can lead to a crash, resulting in a Denial of Service (DoS).", "issued": "2026-05-28T13:15:19Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42250 https://bugzilla.redhat.com/show_bug.cgi?id=2482704 https://www.cve.org/CVERecord?id=CVE-2026-42250 https://nvd.nist.gov/vuln/detail/CVE-2026-42250 https://cert.pl/en/posts/2026/05/CVE-2026-42250/ https://sourceware.org/bzip2/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42250.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "bzip2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5mdxwKcXZHEqEguvWMJQ3w==": { "id": "5mdxwKcXZHEqEguvWMJQ3w==", "updater": "rhel-vex", "name": "CVE-2026-34183", "description": "A flaw was found in OpenSSL's QUIC PATH_CHALLENGE handler. A remote attacker can exploit this vulnerability by flooding a QUIC client or server with specially crafted PATH_CHALLENGE frames. This leads to unbounded memory allocation within the local QUIC stack, as the system continuously allocates PATH_RESPONSE frames without them being acknowledged. The primary consequence is a Denial of Service (DoS), causing the affected application to terminate abnormally due to memory exhaustion.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34183 https://bugzilla.redhat.com/show_bug.cgi?id=2481885 https://www.cve.org/CVERecord?id=CVE-2026-34183 https://nvd.nist.gov/vuln/detail/CVE-2026-34183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34183.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6+rn6nrQrafYloJtAeJ2Bg==": { "id": "6+rn6nrQrafYloJtAeJ2Bg==", "updater": "rhel-vex", "name": "CVE-2024-11053", "description": "A flaw was found in curl. A logic error when processing credentials from the .netrc file while performing redirects allows the transfer of credentials from the original host to the followed-to host under certain circumstances, leaking the credentials to the followed-to host.", "issued": "2024-12-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-11053 https://bugzilla.redhat.com/show_bug.cgi?id=2331191 https://www.cve.org/CVERecord?id=CVE-2024-11053 https://nvd.nist.gov/vuln/detail/CVE-2024-11053 https://curl.se/docs/CVE-2024-11053.html https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-11053.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6hAQW3vY9ZA/8datv1rY4g==": { "id": "6hAQW3vY9ZA/8datv1rY4g==", "updater": "rhel-vex", "name": "CVE-2024-41996", "description": "A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations.", "issued": "2024-08-26T06:15:04Z", "links": "https://access.redhat.com/security/cve/CVE-2024-41996 https://bugzilla.redhat.com/show_bug.cgi?id=2307826 https://www.cve.org/CVERecord?id=CVE-2024-41996 https://nvd.nist.gov/vuln/detail/CVE-2024-41996 https://dheatattack.gitlab.io/details/ https://dheatattack.gitlab.io/faq/ https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1 https://github.com/openssl/openssl/issues/17374 https://openssl-library.org/post/2022-10-21-tls-groups-configuration/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-41996.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6rEIsdyQtCC456AuGwgsDQ==": { "id": "6rEIsdyQtCC456AuGwgsDQ==", "updater": "rhel-vex", "name": "CVE-2025-15079", "description": "A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15079 https://bugzilla.redhat.com/show_bug.cgi?id=2426409 https://www.cve.org/CVERecord?id=CVE-2025-15079 https://nvd.nist.gov/vuln/detail/CVE-2025-15079 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15079.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "71C1Nt6KoL1+Dpr0rTxWwA==": { "id": "71C1Nt6KoL1+Dpr0rTxWwA==", "updater": "rhel-vex", "name": "CVE-2026-12151", "description": "A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.", "issued": "2026-06-17T16:05:38Z", "links": "https://access.redhat.com/security/cve/CVE-2026-12151 https://bugzilla.redhat.com/show_bug.cgi?id=2489980 https://www.cve.org/CVERecord?id=CVE-2026-12151 https://nvd.nist.gov/vuln/detail/CVE-2026-12151 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "76eg4nI+WwZq6jvunMGVEQ==": { "id": "76eg4nI+WwZq6jvunMGVEQ==", "updater": "rhel-vex", "name": "CVE-2026-6238", "description": "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.", "issued": "2026-04-28T16:43:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-274.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "76mWuVYhbmIFsc4DNorK9A==": { "id": "76mWuVYhbmIFsc4DNorK9A==", "updater": "rhel-vex", "name": "CVE-2025-5917", "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5917 https://bugzilla.redhat.com/show_bug.cgi?id=2370874 https://www.cve.org/CVERecord?id=CVE-2025-5917 https://nvd.nist.gov/vuln/detail/CVE-2025-5917 https://github.com/libarchive/libarchive/pull/2588 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5917.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7CfySs4FmTkWgJPjEar4eg==": { "id": "7CfySs4FmTkWgJPjEar4eg==", "updater": "rhel-vex", "name": "CVE-2026-13595", "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.", "issued": "2026-05-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13595 https://bugzilla.redhat.com/show_bug.cgi?id=2494101 https://www.cve.org/CVERecord?id=CVE-2026-13595 https://nvd.nist.gov/vuln/detail/CVE-2026-13595 https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13595.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7KIsr/dNSaeE3wdgBYfrgQ==": { "id": "7KIsr/dNSaeE3wdgBYfrgQ==", "updater": "rhel-vex", "name": "CVE-2026-56392", "description": "A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a heap-based buffer overflow, occurs due to an integer overflow when `unexpand` processes unusually large tab stop values provided by a local attacker. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries. Successful exploitation can cause the `unexpand` utility to crash, potentially resulting in a denial of service or enabling further memory manipulation.", "issued": "2026-07-24T07:44:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56392 https://bugzilla.redhat.com/show_bug.cgi?id=2506694 https://www.cve.org/CVERecord?id=CVE-2026-56392 https://nvd.nist.gov/vuln/detail/CVE-2026-56392 https://cert.pl/en/posts/2026/07/CVE-2026-56391 https://git.savannah.gnu.org/cgit/coreutils.git/ https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56392.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8MfvwX+dRI6Qt2H+x71rZg==": { "id": "8MfvwX+dRI6Qt2H+x71rZg==", "updater": "rhel-vex", "name": "CVE-2025-15224", "description": "A flaw was found in libcurl. When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15224 https://bugzilla.redhat.com/show_bug.cgi?id=2426410 https://www.cve.org/CVERecord?id=CVE-2025-15224 https://nvd.nist.gov/vuln/detail/CVE-2025-15224 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15224.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8ZCpE1M7eqNdy615aO2gLQ==": { "id": "8ZCpE1M7eqNdy615aO2gLQ==", "updater": "rhel-vex", "name": "CVE-2026-0992", "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated \u003cnextCatalog\u003e elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0992 https://bugzilla.redhat.com/show_bug.cgi?id=2429975 https://www.cve.org/CVERecord?id=CVE-2026-0992 https://nvd.nist.gov/vuln/detail/CVE-2026-0992 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0992.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8gSzZr+GPWdWrD28SEc1Pg==": { "id": "8gSzZr+GPWdWrD28SEc1Pg==", "updater": "rhel-vex", "name": "CVE-2026-5450", "description": "A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.", "issued": "2026-04-20T20:55:41Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-272.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8hlo60BBnOd97TpyGOfaLA==": { "id": "8hlo60BBnOd97TpyGOfaLA==", "updater": "rhel-vex", "name": "CVE-2026-5928", "description": "A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.", "issued": "2026-04-20T20:37:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-274.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8kndQj/aRn+NNJdGVP9v4g==": { "id": "8kndQj/aRn+NNJdGVP9v4g==", "updater": "rhel-vex", "name": "CVE-2023-45322", "description": "A flaw was found in libxml2. In an out-of-memory condition or when limiting the memory allocation, processing a XML document using the HTML parser may result in a use-after-free vulnerability.", "issued": "2023-08-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-45322 https://bugzilla.redhat.com/show_bug.cgi?id=2242945 https://www.cve.org/CVERecord?id=CVE-2023-45322 https://nvd.nist.gov/vuln/detail/CVE-2023-45322 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-45322.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "922No9XwoInf4IDk2/SEuA==": { "id": "922No9XwoInf4IDk2/SEuA==", "updater": "rhel-vex", "name": "CVE-2026-9150", "description": "A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.", "issued": "2026-05-20T22:59:46Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9150 https://bugzilla.redhat.com/show_bug.cgi?id=2460379 https://www.cve.org/CVERecord?id=CVE-2026-9150 https://nvd.nist.gov/vuln/detail/CVE-2026-9150 https://github.com/openSUSE/libsolv/pull/616 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9150.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libsolv", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9DXLRStQLAgyQnNJqYTJEA==": { "id": "9DXLRStQLAgyQnNJqYTJEA==", "updater": "rhel-vex", "name": "CVE-2026-6733", "description": "A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici's HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.", "issued": "2026-06-17T17:14:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6733 https://bugzilla.redhat.com/show_bug.cgi?id=2490006 https://www.cve.org/CVERecord?id=CVE-2026-6733 https://nvd.nist.gov/vuln/detail/CVE-2026-6733 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 https://hackerone.com/reports/3582376 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6733.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9iigvnuYDaC8UzcOIDLjIQ==": { "id": "9iigvnuYDaC8UzcOIDLjIQ==", "updater": "rhel-vex", "name": "CVE-2026-24883", "description": "A flaw was found in GnuPG. A remote attacker could provide a specially crafted long signature packet that, when processed, causes the application to crash. This vulnerability leads to a denial of service (DoS), making the GnuPG application unavailable to legitimate users.", "issued": "2026-01-27T18:43:18Z", "links": "https://access.redhat.com/security/cve/CVE-2026-24883 https://bugzilla.redhat.com/show_bug.cgi?id=2433463 https://www.cve.org/CVERecord?id=CVE-2026-24883 https://nvd.nist.gov/vuln/detail/CVE-2026-24883 https://dev.gnupg.org/T8049 https://www.openwall.com/lists/oss-security/2026/01/27/8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24883.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9v8e/1gKgcwShm3I7m4SiQ==": { "id": "9v8e/1gKgcwShm3I7m4SiQ==", "updater": "rhel-vex", "name": "CVE-2026-59874", "description": "A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.", "issued": "2026-07-08T15:23:47Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59874 https://bugzilla.redhat.com/show_bug.cgi?id=2498116 https://www.cve.org/CVERecord?id=CVE-2026-59874 https://nvd.nist.gov/vuln/detail/CVE-2026-59874 https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59874.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AGwkok3hPLMsQFqdif59+w==": { "id": "AGwkok3hPLMsQFqdif59+w==", "updater": "rhel-vex", "name": "CVE-2026-7383", "description": "A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-7383 https://bugzilla.redhat.com/show_bug.cgi?id=2481879 https://www.cve.org/CVERecord?id=CVE-2026-7383 https://nvd.nist.gov/vuln/detail/CVE-2026-7383 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7383.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AUiFITCnRjRxctzqqbDeeA==": { "id": "AUiFITCnRjRxctzqqbDeeA==", "updater": "rhel-vex", "name": "CVE-2022-3219", "description": "A vulnerability was found in GnuPG. GnuPG can spin on a relatively small input by crafting a public key with thousands of signatures attached and compressed down to a few kilobytes. This issue can potentially cause a denial of service.", "issued": "2022-09-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-3219 https://bugzilla.redhat.com/show_bug.cgi?id=2127010 https://www.cve.org/CVERecord?id=CVE-2022-3219 https://nvd.nist.gov/vuln/detail/CVE-2022-3219 https://dev.gnupg.org/D556 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3219.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AzUHhCngmr5YuLLD/fQQEA==": { "id": "AzUHhCngmr5YuLLD/fQQEA==", "updater": "rhel-vex", "name": "CVE-2025-13151", "description": "A flaw was found in libtasn1. A remote attacker could exploit a stack-based buffer overflow vulnerability in the `asn1_expend_octet_string` function. This occurs due to a failure in validating the size of input data. Successful exploitation can lead to a Denial of Service (DoS) condition, making the affected system or application unavailable.", "issued": "2026-01-07T21:14:05Z", "links": "https://access.redhat.com/security/cve/CVE-2025-13151 https://bugzilla.redhat.com/show_bug.cgi?id=2427698 https://www.cve.org/CVERecord?id=CVE-2025-13151 https://nvd.nist.gov/vuln/detail/CVE-2025-13151 https://gitlab.com/gnutls/libtasn1 https://gitlab.com/gnutls/libtasn1/-/merge_requests/121 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13151.json https://access.redhat.com/errata/RHSA-2026:28253", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libtasn1", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:4.16.0-10.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BXYBFOm74zXwzmdOdyNhzA==": { "id": "BXYBFOm74zXwzmdOdyNhzA==", "updater": "rhel-vex", "name": "CVE-2026-7383", "description": "A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-7383 https://bugzilla.redhat.com/show_bug.cgi?id=2481879 https://www.cve.org/CVERecord?id=CVE-2026-7383 https://nvd.nist.gov/vuln/detail/CVE-2026-7383 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7383.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Bl8VfXimE6raefu05cOS8w==": { "id": "Bl8VfXimE6raefu05cOS8w==", "updater": "rhel-vex", "name": "CVE-2026-48933", "description": "A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48933 https://bugzilla.redhat.com/show_bug.cgi?id=2493331 https://www.cve.org/CVERecord?id=CVE-2026-48933 https://nvd.nist.gov/vuln/detail/CVE-2026-48933 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BrupyHHgUisGe91mdtTkog==": { "id": "BrupyHHgUisGe91mdtTkog==", "updater": "rhel-vex", "name": "CVE-2026-59871", "description": "A flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path processing. An attacker could exploit this to cause the application using node-tar to crash, resulting in a denial of service.", "issued": "2026-07-08T15:25:09Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59871 https://bugzilla.redhat.com/show_bug.cgi?id=2498126 https://www.cve.org/CVERecord?id=CVE-2026-59871 https://nvd.nist.gov/vuln/detail/CVE-2026-59871 https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59871.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "C2yGNOteTOSf1Z3ep0DvHQ==": { "id": "C2yGNOteTOSf1Z3ep0DvHQ==", "updater": "rhel-vex", "name": "CVE-2026-11525", "description": "A flaw was found in undici. When undici processes Set-Cookie headers, it incorrectly interprets the SameSite attribute, accepting partial matches instead of exact ones. This allows a malicious server to downgrade a cookie's SameSite policy to a less secure setting, potentially leading to unintended information disclosure or a weakening of security protections for the user.", "issued": "2026-06-17T17:31:03Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11525 https://bugzilla.redhat.com/show_bug.cgi?id=2490008 https://www.cve.org/CVERecord?id=CVE-2026-11525 https://nvd.nist.gov/vuln/detail/CVE-2026-11525 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11525.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CfMK+8nnfjDlpiJ86nDqnQ==": { "id": "CfMK+8nnfjDlpiJ86nDqnQ==", "updater": "rhel-vex", "name": "CVE-2026-48619", "description": "A flaw was found in Node.js. A malicious server can exploit the HTTP/2 client by sending an unlimited number of ORIGIN frames. This can lead to an Out of Memory error on the client, resulting in a denial of service.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48619 https://bugzilla.redhat.com/show_bug.cgi?id=2493325 https://www.cve.org/CVERecord?id=CVE-2026-48619 https://nvd.nist.gov/vuln/detail/CVE-2026-48619 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48619.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ChVC4WOnGJkEsPC5QHmS4Q==": { "id": "ChVC4WOnGJkEsPC5QHmS4Q==", "updater": "rhel-vex", "name": "CVE-2026-13757", "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.", "issued": "2026-06-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13757 https://bugzilla.redhat.com/show_bug.cgi?id=2494556 https://www.cve.org/CVERecord?id=CVE-2026-13757 https://nvd.nist.gov/vuln/detail/CVE-2026-13757 https://github.com/advisories/GHSA-p2wm-69qx-x25w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13757.json https://access.redhat.com/errata/RHSA-2026:49667", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "p11-kit", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.26.4-1.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Cpn7PI6CgTg1FJ1Ijp4TIQ==": { "id": "Cpn7PI6CgTg1FJ1Ijp4TIQ==", "updater": "rhel-vex", "name": "CVE-2026-8458", "description": "A flaw was found in libcurl. A logical error in the connection pooling mechanism may cause libcurl to reuse an authenticated connection for an unintended service. This could allow an application to wrongfully reuse an existing connection to the same server that was authenticated for a different service, potentially leading to unauthorized access or information disclosure.", "issued": "2026-07-03T06:14:42Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8458 https://bugzilla.redhat.com/show_bug.cgi?id=2496764 https://www.cve.org/CVERecord?id=CVE-2026-8458 https://nvd.nist.gov/vuln/detail/CVE-2026-8458 https://curl.se/docs/CVE-2026-8458.html https://curl.se/docs/CVE-2026-8458.json https://hackerone.com/reports/3721183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8458.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D4G1BWjcvupPxJokCdnHGA==": { "id": "D4G1BWjcvupPxJokCdnHGA==", "updater": "rhel-vex", "name": "CVE-2026-9076", "description": "A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9076 https://bugzilla.redhat.com/show_bug.cgi?id=2481880 https://www.cve.org/CVERecord?id=CVE-2026-9076 https://nvd.nist.gov/vuln/detail/CVE-2026-9076 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9076.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DDxCHnX+kCqcRQj9b90/cg==": { "id": "DDxCHnX+kCqcRQj9b90/cg==", "updater": "rhel-vex", "name": "CVE-2023-4156", "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.", "issued": "2023-06-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4156 https://bugzilla.redhat.com/show_bug.cgi?id=2215930 https://www.cve.org/CVERecord?id=CVE-2023-4156 https://nvd.nist.gov/vuln/detail/CVE-2023-4156 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4156.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DTApvRZh1HJD5XbbpU3ahw==": { "id": "DTApvRZh1HJD5XbbpU3ahw==", "updater": "rhel-vex", "name": "CVE-2026-1757", "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.", "issued": "2026-02-02T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1757 https://bugzilla.redhat.com/show_bug.cgi?id=2435940 https://www.cve.org/CVERecord?id=CVE-2026-1757 https://nvd.nist.gov/vuln/detail/CVE-2026-1757 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1757.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DW2DUdu8ljrldYoM7Mprtg==": { "id": "DW2DUdu8ljrldYoM7Mprtg==", "updater": "rhel-vex", "name": "CVE-2026-42769", "description": "A flaw was found in the Certificate Management Protocol (CMP) implementation within OpenSSL. An attacker with existing Registration Authority (RA) level credentials could exploit an error in the certificate verification process during a Root Certificate Authority (CA) key update. This vulnerability allows the attacker to replace the root CA certificate for CMP clients with a fraudulent one. The primary consequence is an escalation of privileges, enabling the attacker to gain control equivalent to the root CA.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42769 https://bugzilla.redhat.com/show_bug.cgi?id=2481893 https://www.cve.org/CVERecord?id=CVE-2026-42769 https://nvd.nist.gov/vuln/detail/CVE-2026-42769 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42769.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DsZp+BRVz/OTV0jFXHylmA==": { "id": "DsZp+BRVz/OTV0jFXHylmA==", "updater": "rhel-vex", "name": "CVE-2026-28390", "description": "A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS).", "issued": "2026-04-07T22:00:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-28390 https://bugzilla.redhat.com/show_bug.cgi?id=2456314 https://www.cve.org/CVERecord?id=CVE-2026-28390 https://nvd.nist.gov/vuln/detail/CVE-2026-28390 https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6 https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4 https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788 https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28390.json https://access.redhat.com/errata/RHSA-2026:22312", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-3.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "E9ztZ/MyJW/b90Qruzzb/A==": { "id": "E9ztZ/MyJW/b90Qruzzb/A==", "updater": "rhel-vex", "name": "CVE-2026-59875", "description": "A flaw was found in node-tar, a library for manipulating tar archives in Node.js. A remote attacker could craft a malicious archive containing null characters (NUL bytes) in its metadata. When this archive is processed, the unstripped null characters can cause the application to terminate unexpectedly, leading to a Denial of Service (DoS).", "issued": "2026-07-08T15:20:29Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59875 https://bugzilla.redhat.com/show_bug.cgi?id=2498115 https://www.cve.org/CVERecord?id=CVE-2026-59875 https://nvd.nist.gov/vuln/detail/CVE-2026-59875 https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3 https://github.com/isaacs/node-tar/releases/tag/v7.5.17 https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59875.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EL8NcQMQeTnwBw9iCSC+yA==": { "id": "EL8NcQMQeTnwBw9iCSC+yA==", "updater": "rhel-vex", "name": "CVE-2026-48619", "description": "A flaw was found in Node.js. A malicious server can exploit the HTTP/2 client by sending an unlimited number of ORIGIN frames. This can lead to an Out of Memory error on the client, resulting in a denial of service.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48619 https://bugzilla.redhat.com/show_bug.cgi?id=2493325 https://www.cve.org/CVERecord?id=CVE-2026-48619 https://nvd.nist.gov/vuln/detail/CVE-2026-48619 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48619.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EOZFP6ki76xUja7Br+mpEw==": { "id": "EOZFP6ki76xUja7Br+mpEw==", "updater": "rhel-vex", "name": "CVE-2026-9678", "description": "A flaw was found in Undici. The cache interceptor in shared-cache mode incorrectly classifies certain responses as cacheable due to improper handling of whitespace-padded Cache-Control header field names. This vulnerability allows an unauthenticated attacker to access authenticated user data from the cache, leading to information disclosure. This occurs when both authenticated and unauthenticated requests resolve to the same cache key.", "issued": "2026-06-17T17:04:09Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9678 https://bugzilla.redhat.com/show_bug.cgi?id=2490000 https://www.cve.org/CVERecord?id=CVE-2026-9678 https://nvd.nist.gov/vuln/detail/CVE-2026-9678 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9678.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EQB0ZSi1/BHyuX6FPsfCrA==": { "id": "EQB0ZSi1/BHyuX6FPsfCrA==", "updater": "rhel-vex", "name": "CVE-2026-12151", "description": "A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.", "issued": "2026-06-17T16:05:38Z", "links": "https://access.redhat.com/security/cve/CVE-2026-12151 https://bugzilla.redhat.com/show_bug.cgi?id=2489980 https://www.cve.org/CVERecord?id=CVE-2026-12151 https://nvd.nist.gov/vuln/detail/CVE-2026-12151 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EUdYVqG8WVFrguzTJcoB9w==": { "id": "EUdYVqG8WVFrguzTJcoB9w==", "updater": "rhel-vex", "name": "CVE-2026-6238", "description": "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.", "issued": "2026-04-28T16:43:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6238 https://bugzilla.redhat.com/show_bug.cgi?id=2463539 https://www.cve.org/CVERecord?id=CVE-2026-6238 https://nvd.nist.gov/vuln/detail/CVE-2026-6238 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34069 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6238.json https://access.redhat.com/errata/RHSA-2026:42952", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-274.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EmYlXCkWzU0dM5AZphsDzw==": { "id": "EmYlXCkWzU0dM5AZphsDzw==", "updater": "rhel-vex", "name": "CVE-2026-42768", "description": "A flaw was found in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim's private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application's error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42768 https://bugzilla.redhat.com/show_bug.cgi?id=2481892 https://www.cve.org/CVERecord?id=CVE-2026-42768 https://nvd.nist.gov/vuln/detail/CVE-2026-42768 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42768.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ep1W9j+OJARAHSERuL7J7Q==": { "id": "Ep1W9j+OJARAHSERuL7J7Q==", "updater": "rhel-vex", "name": "CVE-2026-34182", "description": "A flaw was found in OpenSSL's Cryptographic Message Services (CMS) AuthEnvelopedData processing. An on-path attacker can exploit insufficient input validation on cipher and tag length fields by sending specially crafted CMS messages. This can lead to the forging of messages or bypassing integrity validation. Consequently, an attacker may achieve key-equivalent functionality for a given CMS recipient.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34182 https://bugzilla.redhat.com/show_bug.cgi?id=2481884 https://www.cve.org/CVERecord?id=CVE-2026-34182 https://nvd.nist.gov/vuln/detail/CVE-2026-34182 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34182.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ez8lHT2uV9Tf9vJC/T4WXg==": { "id": "Ez8lHT2uV9Tf9vJC/T4WXg==", "updater": "rhel-vex", "name": "CVE-2026-4426", "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.", "issued": "2026-03-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4426 https://bugzilla.redhat.com/show_bug.cgi?id=2449010 https://www.cve.org/CVERecord?id=CVE-2026-4426 https://nvd.nist.gov/vuln/detail/CVE-2026-4426 https://github.com/libarchive/libarchive/pull/2897 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4426.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "F8lGQFeTGfg63gSPRvjBBA==": { "id": "F8lGQFeTGfg63gSPRvjBBA==", "updater": "rhel-vex", "name": "CVE-2026-48935", "description": "A flaw was found in Node.js. The Permission API allows a local user to modify file metadata on paths that have been explicitly set as read-only. This can lead to unauthorized changes in file properties, impacting the integrity of the file system.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48935 https://bugzilla.redhat.com/show_bug.cgi?id=2493329 https://www.cve.org/CVERecord?id=CVE-2026-48935 https://nvd.nist.gov/vuln/detail/CVE-2026-48935 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48935.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FQwXyPZ+oHyxQZ9RBQXbpw==": { "id": "FQwXyPZ+oHyxQZ9RBQXbpw==", "updater": "rhel-vex", "name": "CVE-2025-13034", "description": "A flaw was found in curl. When configured to use public key pinning with QUIC connections and GnuTLS, and with standard certificate verification explicitly disabled, curl could bypass the intended public key check. This oversight allows a malicious server to impersonate a legitimate one, potentially leading to unauthorized access or information disclosure due to a failure in verifying the server's identity.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-13034 https://bugzilla.redhat.com/show_bug.cgi?id=2426406 https://www.cve.org/CVERecord?id=CVE-2025-13034 https://nvd.nist.gov/vuln/detail/CVE-2025-13034 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13034.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FeNPPUXNvPHMFZ28E13Mog==": { "id": "FeNPPUXNvPHMFZ28E13Mog==", "updater": "rhel-vex", "name": "CVE-2026-48934", "description": "A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48934 https://bugzilla.redhat.com/show_bug.cgi?id=2493332 https://www.cve.org/CVERecord?id=CVE-2026-48934 https://nvd.nist.gov/vuln/detail/CVE-2026-48934 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48934.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GAn7gWUe2pFr7PbwechqxA==": { "id": "GAn7gWUe2pFr7PbwechqxA==", "updater": "rhel-vex", "name": "CVE-2025-30258", "description": "A flaw was found in GnuPG. In affected versions, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, leading to a verification denial of service.", "issued": "2025-03-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-30258 https://bugzilla.redhat.com/show_bug.cgi?id=2353427 https://www.cve.org/CVERecord?id=CVE-2025-30258 https://nvd.nist.gov/vuln/detail/CVE-2025-30258 https://dev.gnupg.org/T7527 https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158 https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-30258.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GoTAJ6nke0a3zoxJ8lkaAg==": { "id": "GoTAJ6nke0a3zoxJ8lkaAg==", "updater": "rhel-vex", "name": "CVE-2026-45446", "description": "A flaw was found in OpenSSL. The implementations of AES-SIV (Advanced Encryption Standard - SIV) and AES-GCM-SIV (Advanced Encryption Standard - Galois/Counter Mode - SIV) incorrectly process authentication tags for empty messages. This vulnerability allows a remote attacker to forge empty messages with arbitrary Additional Authenticated Data (AAD) in applications that utilize these specific cipher modes within custom protocols and do not properly handle zero-length ciphertexts. This could lead to unauthorized data manipulation.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-45446 https://bugzilla.redhat.com/show_bug.cgi?id=2481897 https://www.cve.org/CVERecord?id=CVE-2026-45446 https://nvd.nist.gov/vuln/detail/CVE-2026-45446 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45446.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "H1wshPoazj8pmzsnWAztZA==": { "id": "H1wshPoazj8pmzsnWAztZA==", "updater": "rhel-vex", "name": "CVE-2026-6276", "description": "A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intended for the first host to the second host, resulting in a cookie leak. This issue is categorized as an Origin Validation Error (CWE-346). Exploitation typically requires specific debugging configurations.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6276 https://bugzilla.redhat.com/show_bug.cgi?id=2461203 https://www.cve.org/CVERecord?id=CVE-2026-6276 https://nvd.nist.gov/vuln/detail/CVE-2026-6276 https://curl.se/docs/CVE-2026-6276.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6276.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HVxGZgwvlrVpgAxKx4gRlA==": { "id": "HVxGZgwvlrVpgAxKx4gRlA==", "updater": "rhel-vex", "name": "CVE-2026-13149", "description": "A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.", "issued": "2026-06-30T08:30:34Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13149 https://bugzilla.redhat.com/show_bug.cgi?id=2494813 https://www.cve.org/CVERecord?id=CVE-2026-13149 https://nvd.nist.gov/vuln/detail/CVE-2026-13149 https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754 https://www.npmjs.com/package/brace-expansion https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HwrQV7Eq97lmWod0H+Mywg==": { "id": "HwrQV7Eq97lmWod0H+Mywg==", "updater": "rhel-vex", "name": "CVE-2026-42769", "description": "A flaw was found in the Certificate Management Protocol (CMP) implementation within OpenSSL. An attacker with existing Registration Authority (RA) level credentials could exploit an error in the certificate verification process during a Root Certificate Authority (CA) key update. This vulnerability allows the attacker to replace the root CA certificate for CMP clients with a fraudulent one. The primary consequence is an escalation of privileges, enabling the attacker to gain control equivalent to the root CA.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42769 https://bugzilla.redhat.com/show_bug.cgi?id=2481893 https://www.cve.org/CVERecord?id=CVE-2026-42769 https://nvd.nist.gov/vuln/detail/CVE-2026-42769 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42769.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HxI42iSjURjRki+uV6q/9w==": { "id": "HxI42iSjURjRki+uV6q/9w==", "updater": "rhel-vex", "name": "CVE-2024-0232", "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.", "issued": "2023-10-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-0232 https://bugzilla.redhat.com/show_bug.cgi?id=2243754 https://www.cve.org/CVERecord?id=CVE-2024-0232 https://nvd.nist.gov/vuln/detail/CVE-2024-0232 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0232.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IDIT7Gfu8E9A+NfUxEcAbQ==": { "id": "IDIT7Gfu8E9A+NfUxEcAbQ==", "updater": "rhel-vex", "name": "CVE-2026-42768", "description": "A flaw was found in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim's private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application's error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42768 https://bugzilla.redhat.com/show_bug.cgi?id=2481892 https://www.cve.org/CVERecord?id=CVE-2026-42768 https://nvd.nist.gov/vuln/detail/CVE-2026-42768 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42768.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IFUwSX5dX69QHRHfvOeQDg==": { "id": "IFUwSX5dX69QHRHfvOeQDg==", "updater": "rhel-vex", "name": "CVE-2026-6429", "description": "A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6429 https://bugzilla.redhat.com/show_bug.cgi?id=2461205 https://www.cve.org/CVERecord?id=CVE-2026-6429 https://nvd.nist.gov/vuln/detail/CVE-2026-6429 https://curl.se/docs/CVE-2026-6429.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6429.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "J/M93jueASHywmph2g+HMg==": { "id": "J/M93jueASHywmph2g+HMg==", "updater": "rhel-vex", "name": "CVE-2026-48619", "description": "A flaw was found in Node.js. A malicious server can exploit the HTTP/2 client by sending an unlimited number of ORIGIN frames. This can lead to an Out of Memory error on the client, resulting in a denial of service.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48619 https://bugzilla.redhat.com/show_bug.cgi?id=2493325 https://www.cve.org/CVERecord?id=CVE-2026-48619 https://nvd.nist.gov/vuln/detail/CVE-2026-48619 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48619.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "J1e16b0P6Tp2x5sVgsqutQ==": { "id": "J1e16b0P6Tp2x5sVgsqutQ==", "updater": "rhel-vex", "name": "CVE-2026-48615", "description": "A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48615 https://bugzilla.redhat.com/show_bug.cgi?id=2493335 https://www.cve.org/CVERecord?id=CVE-2026-48615 https://nvd.nist.gov/vuln/detail/CVE-2026-48615 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48615.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JYnbFl5uln18531ZOk6t8g==": { "id": "JYnbFl5uln18531ZOk6t8g==", "updater": "rhel-vex", "name": "CVE-2026-45446", "description": "A flaw was found in OpenSSL. The implementations of AES-SIV (Advanced Encryption Standard - SIV) and AES-GCM-SIV (Advanced Encryption Standard - Galois/Counter Mode - SIV) incorrectly process authentication tags for empty messages. This vulnerability allows a remote attacker to forge empty messages with arbitrary Additional Authenticated Data (AAD) in applications that utilize these specific cipher modes within custom protocols and do not properly handle zero-length ciphertexts. This could lead to unauthorized data manipulation.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-45446 https://bugzilla.redhat.com/show_bug.cgi?id=2481897 https://www.cve.org/CVERecord?id=CVE-2026-45446 https://nvd.nist.gov/vuln/detail/CVE-2026-45446 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45446.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Kqq2xlybjD/tOLmQWu2xPw==": { "id": "Kqq2xlybjD/tOLmQWu2xPw==", "updater": "rhel-vex", "name": "CVE-2025-5918", "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5918 https://bugzilla.redhat.com/show_bug.cgi?id=2370877 https://www.cve.org/CVERecord?id=CVE-2025-5918 https://nvd.nist.gov/vuln/detail/CVE-2025-5918 https://github.com/libarchive/libarchive/pull/2584 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5918.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "L1NHjBKVcGa4hqzsfSCCQg==": { "id": "L1NHjBKVcGa4hqzsfSCCQg==", "updater": "rhel-vex", "name": "CVE-2026-34180", "description": "A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34180 https://bugzilla.redhat.com/show_bug.cgi?id=2481881 https://www.cve.org/CVERecord?id=CVE-2026-34180 https://nvd.nist.gov/vuln/detail/CVE-2026-34180 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34180.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LiIvRwi7+1nAVErMH0hoaQ==": { "id": "LiIvRwi7+1nAVErMH0hoaQ==", "updater": "rhel-vex", "name": "CVE-2025-5278", "description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.", "issued": "2025-05-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5278 https://bugzilla.redhat.com/show_bug.cgi?id=2368764 https://www.cve.org/CVERecord?id=CVE-2025-5278 https://nvd.nist.gov/vuln/detail/CVE-2025-5278 https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633 https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5278.json https://access.redhat.com/errata/RHSA-2026:28911", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "coreutils-single", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:8.32-41.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "M293c+QguJ/aaYP3cMwfyQ==": { "id": "M293c+QguJ/aaYP3cMwfyQ==", "updater": "rhel-vex", "name": "CVE-2026-28388", "description": "A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-28388 https://bugzilla.redhat.com/show_bug.cgi?id=2451097 https://www.cve.org/CVERecord?id=CVE-2026-28388 https://nvd.nist.gov/vuln/detail/CVE-2026-28388 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28388.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MDVosfib/bnNAm4m647vLA==": { "id": "MDVosfib/bnNAm4m647vLA==", "updater": "rhel-vex", "name": "CVE-2026-48934", "description": "A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48934 https://bugzilla.redhat.com/show_bug.cgi?id=2493332 https://www.cve.org/CVERecord?id=CVE-2026-48934 https://nvd.nist.gov/vuln/detail/CVE-2026-48934 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48934.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MEeKHFVdv0EwpaMPKCy3Sw==": { "id": "MEeKHFVdv0EwpaMPKCy3Sw==", "updater": "rhel-vex", "name": "CVE-2026-48619", "description": "A flaw was found in Node.js. A malicious server can exploit the HTTP/2 client by sending an unlimited number of ORIGIN frames. This can lead to an Out of Memory error on the client, resulting in a denial of service.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48619 https://bugzilla.redhat.com/show_bug.cgi?id=2493325 https://www.cve.org/CVERecord?id=CVE-2026-48619 https://nvd.nist.gov/vuln/detail/CVE-2026-48619 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48619.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MciappbjqbiRE2dg7PbMSg==": { "id": "MciappbjqbiRE2dg7PbMSg==", "updater": "rhel-vex", "name": "CVE-2026-48933", "description": "A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48933 https://bugzilla.redhat.com/show_bug.cgi?id=2493331 https://www.cve.org/CVERecord?id=CVE-2026-48933 https://nvd.nist.gov/vuln/detail/CVE-2026-48933 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "N5EbMRV7FNySo/Sn3CmU+w==": { "id": "N5EbMRV7FNySo/Sn3CmU+w==", "updater": "rhel-vex", "name": "CVE-2026-11525", "description": "A flaw was found in undici. When undici processes Set-Cookie headers, it incorrectly interprets the SameSite attribute, accepting partial matches instead of exact ones. This allows a malicious server to downgrade a cookie's SameSite policy to a less secure setting, potentially leading to unintended information disclosure or a weakening of security protections for the user.", "issued": "2026-06-17T17:31:03Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11525 https://bugzilla.redhat.com/show_bug.cgi?id=2490008 https://www.cve.org/CVERecord?id=CVE-2026-11525 https://nvd.nist.gov/vuln/detail/CVE-2026-11525 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11525.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NF/ewEROjeKYjnb1lHH2iw==": { "id": "NF/ewEROjeKYjnb1lHH2iw==", "updater": "rhel-vex", "name": "CVE-2026-34183", "description": "A flaw was found in OpenSSL's QUIC PATH_CHALLENGE handler. A remote attacker can exploit this vulnerability by flooding a QUIC client or server with specially crafted PATH_CHALLENGE frames. This leads to unbounded memory allocation within the local QUIC stack, as the system continuously allocates PATH_RESPONSE frames without them being acknowledged. The primary consequence is a Denial of Service (DoS), causing the affected application to terminate abnormally due to memory exhaustion.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34183 https://bugzilla.redhat.com/show_bug.cgi?id=2481885 https://www.cve.org/CVERecord?id=CVE-2026-34183 https://nvd.nist.gov/vuln/detail/CVE-2026-34183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34183.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NfiEOtFyxMslIq3QwoTtjQ==": { "id": "NfiEOtFyxMslIq3QwoTtjQ==", "updater": "rhel-vex", "name": "CVE-2026-59874", "description": "A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.", "issued": "2026-07-08T15:23:47Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59874 https://bugzilla.redhat.com/show_bug.cgi?id=2498116 https://www.cve.org/CVERecord?id=CVE-2026-59874 https://nvd.nist.gov/vuln/detail/CVE-2026-59874 https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59874.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Nh6DgKTo1EEcTUg+VgZK9Q==": { "id": "Nh6DgKTo1EEcTUg+VgZK9Q==", "updater": "rhel-vex", "name": "CVE-2026-48934", "description": "A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48934 https://bugzilla.redhat.com/show_bug.cgi?id=2493332 https://www.cve.org/CVERecord?id=CVE-2026-48934 https://nvd.nist.gov/vuln/detail/CVE-2026-48934 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48934.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NrATYvL+2i2gY4ol+szT+g==": { "id": "NrATYvL+2i2gY4ol+szT+g==", "updater": "rhel-vex", "name": "CVE-2026-48934", "description": "A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48934 https://bugzilla.redhat.com/show_bug.cgi?id=2493332 https://www.cve.org/CVERecord?id=CVE-2026-48934 https://nvd.nist.gov/vuln/detail/CVE-2026-48934 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48934.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NrTzMmbWyM5UeSvnQVNLOg==": { "id": "NrTzMmbWyM5UeSvnQVNLOg==", "updater": "rhel-vex", "name": "CVE-2026-0988", "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0988 https://bugzilla.redhat.com/show_bug.cgi?id=2429886 https://www.cve.org/CVERecord?id=CVE-2026-0988 https://nvd.nist.gov/vuln/detail/CVE-2026-0988 https://gitlab.gnome.org/GNOME/glib/-/issues/3851 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0988.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O3XylFvGObsPmzTrCuhV8A==": { "id": "O3XylFvGObsPmzTrCuhV8A==", "updater": "rhel-vex", "name": "CVE-2026-14164", "description": "A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.", "issued": "2026-05-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-14164 https://bugzilla.redhat.com/show_bug.cgi?id=2493411 https://www.cve.org/CVERecord?id=CVE-2026-14164 https://nvd.nist.gov/vuln/detail/CVE-2026-14164 https://github.com/libarchive/libarchive/issues/3069 https://github.com/libarchive/libarchive/pull/3071 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14164.json https://access.redhat.com/errata/RHSA-2026:52674", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:3.5.3-11.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O912x64ev1faikrIaaOp6w==": { "id": "O912x64ev1faikrIaaOp6w==", "updater": "rhel-vex", "name": "CVE-2026-9678", "description": "A flaw was found in Undici. The cache interceptor in shared-cache mode incorrectly classifies certain responses as cacheable due to improper handling of whitespace-padded Cache-Control header field names. This vulnerability allows an unauthenticated attacker to access authenticated user data from the cache, leading to information disclosure. This occurs when both authenticated and unauthenticated requests resolve to the same cache key.", "issued": "2026-06-17T17:04:09Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9678 https://bugzilla.redhat.com/show_bug.cgi?id=2490000 https://www.cve.org/CVERecord?id=CVE-2026-9678 https://nvd.nist.gov/vuln/detail/CVE-2026-9678 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9678.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OB+gdUis8HhIN+YuJZ0d3w==": { "id": "OB+gdUis8HhIN+YuJZ0d3w==", "updater": "rhel-vex", "name": "CVE-2026-6733", "description": "A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici's HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.", "issued": "2026-06-17T17:14:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6733 https://bugzilla.redhat.com/show_bug.cgi?id=2490006 https://www.cve.org/CVERecord?id=CVE-2026-6733 https://nvd.nist.gov/vuln/detail/CVE-2026-6733 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 https://hackerone.com/reports/3582376 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6733.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OXJFeTFLsi8lSYgzBz58BA==": { "id": "OXJFeTFLsi8lSYgzBz58BA==", "updater": "rhel-vex", "name": "CVE-2026-12151", "description": "A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.", "issued": "2026-06-17T16:05:38Z", "links": "https://access.redhat.com/security/cve/CVE-2026-12151 https://bugzilla.redhat.com/show_bug.cgi?id=2489980 https://www.cve.org/CVERecord?id=CVE-2026-12151 https://nvd.nist.gov/vuln/detail/CVE-2026-12151 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Pi9su0FguY3j1GBpXhwKIA==": { "id": "Pi9su0FguY3j1GBpXhwKIA==", "updater": "rhel-vex", "name": "CVE-2026-9678", "description": "A flaw was found in Undici. The cache interceptor in shared-cache mode incorrectly classifies certain responses as cacheable due to improper handling of whitespace-padded Cache-Control header field names. This vulnerability allows an unauthenticated attacker to access authenticated user data from the cache, leading to information disclosure. This occurs when both authenticated and unauthenticated requests resolve to the same cache key.", "issued": "2026-06-17T17:04:09Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9678 https://bugzilla.redhat.com/show_bug.cgi?id=2490000 https://www.cve.org/CVERecord?id=CVE-2026-9678 https://nvd.nist.gov/vuln/detail/CVE-2026-9678 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9678.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Pza9Y2xtH9MChVMkZwgw2A==": { "id": "Pza9Y2xtH9MChVMkZwgw2A==", "updater": "rhel-vex", "name": "CVE-2024-7264", "description": "A flaw was found in libcurl, where libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the length of the *time fraction*, leading to a `strlen()` performed on a pointer to a heap buffer area that is not purposely NULL terminated.", "issued": "2024-07-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-7264 https://bugzilla.redhat.com/show_bug.cgi?id=2301888 https://www.cve.org/CVERecord?id=CVE-2024-7264 https://nvd.nist.gov/vuln/detail/CVE-2024-7264 https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-7264.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Qi/s8gqjz2kgI+pAtQ5t9w==": { "id": "Qi/s8gqjz2kgI+pAtQ5t9w==", "updater": "rhel-vex", "name": "CVE-2026-6733", "description": "A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici's HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.", "issued": "2026-06-17T17:14:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6733 https://bugzilla.redhat.com/show_bug.cgi?id=2490006 https://www.cve.org/CVERecord?id=CVE-2026-6733 https://nvd.nist.gov/vuln/detail/CVE-2026-6733 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 https://hackerone.com/reports/3582376 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6733.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QmXO38HGjUD9lc3XwducGg==": { "id": "QmXO38HGjUD9lc3XwducGg==", "updater": "rhel-vex", "name": "CVE-2026-42338", "description": "A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user's browser.", "issued": "2026-05-12T19:43:16Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42338 https://bugzilla.redhat.com/show_bug.cgi?id=2476810 https://www.cve.org/CVERecord?id=CVE-2026-42338 https://nvd.nist.gov/vuln/detail/CVE-2026-42338 https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QskDoDnTSvrQeDXklM4YOw==": { "id": "QskDoDnTSvrQeDXklM4YOw==", "updater": "rhel-vex", "name": "CVE-2026-4105", "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.", "issued": "2026-03-13T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4105 https://bugzilla.redhat.com/show_bug.cgi?id=2447262 https://www.cve.org/CVERecord?id=CVE-2026-4105 https://nvd.nist.gov/vuln/detail/CVE-2026-4105 https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4105.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Qvw0/zOlMy3n6XUCrN6SmQ==": { "id": "Qvw0/zOlMy3n6XUCrN6SmQ==", "updater": "rhel-vex", "name": "CVE-2026-42338", "description": "A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user's browser.", "issued": "2026-05-12T19:43:16Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42338 https://bugzilla.redhat.com/show_bug.cgi?id=2476810 https://www.cve.org/CVERecord?id=CVE-2026-42338 https://nvd.nist.gov/vuln/detail/CVE-2026-42338 https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R5XnexvMFgBiw/v8sY0BOA==": { "id": "R5XnexvMFgBiw/v8sY0BOA==", "updater": "rhel-vex", "name": "CVE-2026-40553", "description": "A flaw was found in gawk. A buffer overflow vulnerability exists in the `ftype()` routine, located in the `extension/readdir.c` program file. This vulnerability could allow an attacker to crash the program, resulting in a denial of service. It may also potentially lead to arbitrary code execution, though this has not been definitively confirmed.", "issued": "2026-07-13T12:07:56Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40553 https://bugzilla.redhat.com/show_bug.cgi?id=2499657 https://www.cve.org/CVERecord?id=CVE-2026-40553 https://nvd.nist.gov/vuln/detail/CVE-2026-40553 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40553.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RHShqbO2hqcBNPYbKDg/3A==": { "id": "RHShqbO2hqcBNPYbKDg/3A==", "updater": "rhel-vex", "name": "CVE-2026-6732", "description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.", "issued": "2026-04-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6732 https://bugzilla.redhat.com/show_bug.cgi?id=2461300 https://www.cve.org/CVERecord?id=CVE-2026-6732 https://nvd.nist.gov/vuln/detail/CVE-2026-6732 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097 https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6732.json", "severity": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RI2wKrfD1EyE3/UfHBEmcA==": { "id": "RI2wKrfD1EyE3/UfHBEmcA==", "updater": "rhel-vex", "name": "CVE-2026-42338", "description": "A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user's browser.", "issued": "2026-05-12T19:43:16Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42338 https://bugzilla.redhat.com/show_bug.cgi?id=2476810 https://www.cve.org/CVERecord?id=CVE-2026-42338 https://nvd.nist.gov/vuln/detail/CVE-2026-42338 https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Rk5ia3x816rxtSUtbpOMnw==": { "id": "Rk5ia3x816rxtSUtbpOMnw==", "updater": "rhel-vex", "name": "CVE-2026-18839", "description": "An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.", "issued": "2026-08-05T18:56:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-18839 https://bugzilla.redhat.com/show_bug.cgi?id=2511010 https://www.cve.org/CVERecord?id=CVE-2026-18839 https://nvd.nist.gov/vuln/detail/CVE-2026-18839 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18839.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "popt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "S0PFhlHzk3DOoPuq+7jmPA==": { "id": "S0PFhlHzk3DOoPuq+7jmPA==", "updater": "rhel-vex", "name": "CVE-2026-8932", "description": "A flaw was found in curl. The libcurl library, used for transferring data with URLs, could improperly reuse existing network connections. This occurred even when changes to mutual Transport Layer Security (mTLS) settings, particularly those for client certificates, should have prevented such reuse. This issue could lead to a security feature bypass, where a client might use a connection with an unintended or weaker security configuration, potentially compromising the integrity or confidentiality of data.", "issued": "2026-07-03T06:16:30Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8932 https://bugzilla.redhat.com/show_bug.cgi?id=2496759 https://www.cve.org/CVERecord?id=CVE-2026-8932 https://nvd.nist.gov/vuln/detail/CVE-2026-8932 https://curl.se/docs/CVE-2026-8932.html https://curl.se/docs/CVE-2026-8932.json https://hackerone.com/reports/3733910 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8932.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "S5Dzz9cigoJDCj8s5UcT0g==": { "id": "S5Dzz9cigoJDCj8s5UcT0g==", "updater": "rhel-vex", "name": "CVE-2022-41409", "description": "A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack.", "issued": "2023-07-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-41409 https://bugzilla.redhat.com/show_bug.cgi?id=2260814 https://www.cve.org/CVERecord?id=CVE-2022-41409 https://nvd.nist.gov/vuln/detail/CVE-2022-41409 https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35 https://github.com/PCRE2Project/pcre2/issues/141 https://github.com/advisories/GHSA-4qfx-v7wh-3q4j https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-41409.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "pcre2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SGRK/IsCkjX097oRuDhiEQ==": { "id": "SGRK/IsCkjX097oRuDhiEQ==", "updater": "rhel-vex", "name": "CVE-2025-6170", "description": "A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.", "issued": "2025-06-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-6170 https://bugzilla.redhat.com/show_bug.cgi?id=2372952 https://www.cve.org/CVERecord?id=CVE-2025-6170 https://nvd.nist.gov/vuln/detail/CVE-2025-6170 https://gitlab.gnome.org/GNOME/libxml2/-/issues/941 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6170.json https://access.redhat.com/errata/RHSA-2026:39317", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.13-14.el9_8.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SIuaHC7QSLhT9Coo7Xm2hA==": { "id": "SIuaHC7QSLhT9Coo7Xm2hA==", "updater": "rhel-vex", "name": "CVE-2026-48928", "description": "A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48928 https://bugzilla.redhat.com/show_bug.cgi?id=2493333 https://www.cve.org/CVERecord?id=CVE-2026-48928 https://nvd.nist.gov/vuln/detail/CVE-2026-48928 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48928.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "T1g7X8ESyY5xnqSayytC4w==": { "id": "T1g7X8ESyY5xnqSayytC4w==", "updater": "rhel-vex", "name": "CVE-2026-56391", "description": "A flaw was found in GNU coreutils uniq. When processing specially crafted multibyte input with the --check-chars option, an attacker can trigger an out-of-bounds read. This vulnerability can lead to a denial of service (DoS) due to an application crash and potentially expose sensitive information from adjacent memory.", "issued": "2026-07-24T07:44:45Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56391 https://bugzilla.redhat.com/show_bug.cgi?id=2506691 https://www.cve.org/CVERecord?id=CVE-2026-56391 https://nvd.nist.gov/vuln/detail/CVE-2026-56391 https://cert.pl/en/posts/2026/07/CVE-2026-56391 https://git.savannah.gnu.org/cgit/coreutils.git/ https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56391.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "T76LK9MUa3lwsxSAw540ZA==": { "id": "T76LK9MUa3lwsxSAw540ZA==", "updater": "rhel-vex", "name": "CVE-2026-9678", "description": "A flaw was found in Undici. The cache interceptor in shared-cache mode incorrectly classifies certain responses as cacheable due to improper handling of whitespace-padded Cache-Control header field names. This vulnerability allows an unauthenticated attacker to access authenticated user data from the cache, leading to information disclosure. This occurs when both authenticated and unauthenticated requests resolve to the same cache key.", "issued": "2026-06-17T17:04:09Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9678 https://bugzilla.redhat.com/show_bug.cgi?id=2490000 https://www.cve.org/CVERecord?id=CVE-2026-9678 https://nvd.nist.gov/vuln/detail/CVE-2026-9678 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9678.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "T7eVCD5Gwe0DXPZP59mQUQ==": { "id": "T7eVCD5Gwe0DXPZP59mQUQ==", "updater": "rhel-vex", "name": "CVE-2026-48928", "description": "A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48928 https://bugzilla.redhat.com/show_bug.cgi?id=2493333 https://www.cve.org/CVERecord?id=CVE-2026-48928 https://nvd.nist.gov/vuln/detail/CVE-2026-48928 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48928.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TFhgbPsd17URo8rNJh9SWQ==": { "id": "TFhgbPsd17URo8rNJh9SWQ==", "updater": "rhel-vex", "name": "CVE-2026-42767", "description": "A flaw was found in OpenSSL. An attacker controlling a Certificate Management Protocol (CMP) server, or acting as a man-in-the-middle, could craft a malicious CMP response. This response, containing a Certificate Request Message Format (CRMF) CertRepMessage with a specific malformed EncryptedValue structure, would trigger a NULL pointer dereference in the OpenSSL CMP client. This vulnerability leads to a crash of the application, resulting in a Denial of Service (DoS).", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42767 https://bugzilla.redhat.com/show_bug.cgi?id=2481891 https://www.cve.org/CVERecord?id=CVE-2026-42767 https://nvd.nist.gov/vuln/detail/CVE-2026-42767 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42767.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TL19l7Dr/wLwmp6malQ4FQ==": { "id": "TL19l7Dr/wLwmp6malQ4FQ==", "updater": "rhel-vex", "name": "CVE-2026-48619", "description": "A flaw was found in Node.js. A malicious server can exploit the HTTP/2 client by sending an unlimited number of ORIGIN frames. This can lead to an Out of Memory error on the client, resulting in a denial of service.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48619 https://bugzilla.redhat.com/show_bug.cgi?id=2493325 https://www.cve.org/CVERecord?id=CVE-2026-48619 https://nvd.nist.gov/vuln/detail/CVE-2026-48619 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48619.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TSYnGqVe9WLIg9cR9McW7A==": { "id": "TSYnGqVe9WLIg9cR9McW7A==", "updater": "rhel-vex", "name": "CVE-2026-59873", "description": "A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.", "issued": "2026-07-08T15:22:40Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59873 https://bugzilla.redhat.com/show_bug.cgi?id=2498120 https://www.cve.org/CVERecord?id=CVE-2026-59873 https://nvd.nist.gov/vuln/detail/CVE-2026-59873 https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3 https://github.com/isaacs/node-tar/releases/tag/v7.5.19 https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59873.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Teb2ue8GsbLkJUoUyGyGsA==": { "id": "Teb2ue8GsbLkJUoUyGyGsA==", "updater": "rhel-vex", "name": "CVE-2026-34180", "description": "A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34180 https://bugzilla.redhat.com/show_bug.cgi?id=2481881 https://www.cve.org/CVERecord?id=CVE-2026-34180 https://nvd.nist.gov/vuln/detail/CVE-2026-34180 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34180.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TvusqX9NwPqfJWjNoF5ThA==": { "id": "TvusqX9NwPqfJWjNoF5ThA==", "updater": "rhel-vex", "name": "CVE-2026-42770", "description": "A flaw was found in OpenSSL. A malicious peer can exploit this vulnerability by presenting a specially crafted DHX (X9.42) peer key. Due to improper validation of the peer key's subgroup membership, an attacker can recover the victim's private key after a small number of key exchange attempts. This information disclosure can lead to unauthorized access or further compromise of affected systems.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42770 https://bugzilla.redhat.com/show_bug.cgi?id=2481894 https://www.cve.org/CVERecord?id=CVE-2026-42770 https://nvd.nist.gov/vuln/detail/CVE-2026-42770 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42770.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TwbA7fBttKRHAyCkVC4IDQ==": { "id": "TwbA7fBttKRHAyCkVC4IDQ==", "updater": "rhel-vex", "name": "CVE-2026-5450", "description": "A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.", "issued": "2026-04-20T20:55:41Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5450 https://bugzilla.redhat.com/show_bug.cgi?id=2459853 https://www.cve.org/CVERecord?id=CVE-2026-5450 https://nvd.nist.gov/vuln/detail/CVE-2026-5450 https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5450.json https://access.redhat.com/errata/RHSA-2026:33226", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-272.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "U6rJ6LmaVlYRjI8Lq/aM/A==": { "id": "U6rJ6LmaVlYRjI8Lq/aM/A==", "updater": "rhel-vex", "name": "CVE-2026-58011", "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.", "issued": "2026-03-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58011 https://bugzilla.redhat.com/show_bug.cgi?id=2492245 https://www.cve.org/CVERecord?id=CVE-2026-58011 https://nvd.nist.gov/vuln/detail/CVE-2026-58011 https://gitlab.gnome.org/GNOME/glib/-/issues/3917 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58011.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UwZunDPz4Z/GxKWN3p1+/Q==": { "id": "UwZunDPz4Z/GxKWN3p1+/Q==", "updater": "rhel-vex", "name": "CVE-2026-15588", "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.", "issued": "2026-07-12T10:10:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-15588 https://bugzilla.redhat.com/show_bug.cgi?id=2499675 https://www.cve.org/CVERecord?id=CVE-2026-15588 https://nvd.nist.gov/vuln/detail/CVE-2026-15588 https://gitlab.gnome.org/GNOME/glib/-/issues/3985 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15588.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VHPIyM/Zt8Ma4iUgT7UsMw==": { "id": "VHPIyM/Zt8Ma4iUgT7UsMw==", "updater": "rhel-vex", "name": "CVE-2026-45445", "description": "A flaw was found in OpenSSL. Applications that use the AES-OCB encryption method with a specific one-shot interface (EVP_Cipher()) will have their provided Initialization Vector (IV) silently discarded. This leads to the same internal cryptographic value being used repeatedly, which compromises the confidentiality of encrypted data. Additionally, this issue allows for the universal forgery of authentication tags, undermining the integrity of communications.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-45445 https://bugzilla.redhat.com/show_bug.cgi?id=2481896 https://www.cve.org/CVERecord?id=CVE-2026-45445 https://nvd.nist.gov/vuln/detail/CVE-2026-45445 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45445.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VJENPcmZwV+YJWnk88f2ug==": { "id": "VJENPcmZwV+YJWnk88f2ug==", "updater": "rhel-vex", "name": "CVE-2026-9149", "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).", "issued": "2026-05-20T22:19:32Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9149 https://bugzilla.redhat.com/show_bug.cgi?id=2460380 https://www.cve.org/CVERecord?id=CVE-2026-9149 https://nvd.nist.gov/vuln/detail/CVE-2026-9149 https://github.com/openSUSE/libsolv/pull/617 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9149.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libsolv", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VWEbeFnFOHy1IkG21b5a5g==": { "id": "VWEbeFnFOHy1IkG21b5a5g==", "updater": "rhel-vex", "name": "CVE-2023-30571", "description": "A vulnerability was found in libarchive. This issue can cause a race condition in a multi-threaded use of archive_write_disk_header() on posix based systems, which could allow implicit directory creation with permissions 777, without sticky bit, which means any low privileged user on the system can delete and rename files inside those directories.", "issued": "2023-05-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-30571 https://bugzilla.redhat.com/show_bug.cgi?id=2210921 https://www.cve.org/CVERecord?id=CVE-2023-30571 https://nvd.nist.gov/vuln/detail/CVE-2023-30571 https://access.redhat.com/solutions/7033331 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-30571.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VYGbkY0i6P3tRJd9mM1wNg==": { "id": "VYGbkY0i6P3tRJd9mM1wNg==", "updater": "rhel-vex", "name": "CVE-2026-1489", "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1489 https://bugzilla.redhat.com/show_bug.cgi?id=2433348 https://www.cve.org/CVERecord?id=CVE-2026-1489 https://nvd.nist.gov/vuln/detail/CVE-2026-1489 https://gitlab.gnome.org/GNOME/glib/-/issues/3872 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1489.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VpM36keMJ87mG4yZ97wQdw==": { "id": "VpM36keMJ87mG4yZ97wQdw==", "updater": "rhel-vex", "name": "CVE-2026-48933", "description": "A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48933 https://bugzilla.redhat.com/show_bug.cgi?id=2493331 https://www.cve.org/CVERecord?id=CVE-2026-48933 https://nvd.nist.gov/vuln/detail/CVE-2026-48933 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WjQCog+GPmCa3VQIGXKhRg==": { "id": "WjQCog+GPmCa3VQIGXKhRg==", "updater": "rhel-vex", "name": "CVE-2026-58010", "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses \u003e instead of \u003e=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.", "issued": "2026-03-26T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58010 https://bugzilla.redhat.com/show_bug.cgi?id=2492243 https://www.cve.org/CVERecord?id=CVE-2026-58010 https://nvd.nist.gov/vuln/detail/CVE-2026-58010 https://gitlab.gnome.org/GNOME/glib/-/issues/3915 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58010.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "X4Ym25zfqcH7/samBN+yPw==": { "id": "X4Ym25zfqcH7/samBN+yPw==", "updater": "rhel-vex", "name": "CVE-2026-5545", "description": "A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5545 https://bugzilla.redhat.com/show_bug.cgi?id=2461204 https://www.cve.org/CVERecord?id=CVE-2026-5545 https://nvd.nist.gov/vuln/detail/CVE-2026-5545 https://curl.se/docs/CVE-2026-5545.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5545.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "X7DmUVoCri5i6vdYVBBgXg==": { "id": "X7DmUVoCri5i6vdYVBBgXg==", "updater": "rhel-vex", "name": "CVE-2026-1965", "description": "A flaw was found in curl. When an application uses libcurl to make multiple Negotiate-authenticated HTTP or HTTPS requests to the same server with different credentials, libcurl may incorrectly reuse an existing connection. This logical error can cause a subsequent request to be sent using the authentication of a previous user, leading to an authentication bypass.", "issued": "2026-03-11T10:08:52Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1965 https://bugzilla.redhat.com/show_bug.cgi?id=2446448 https://www.cve.org/CVERecord?id=CVE-2026-1965 https://nvd.nist.gov/vuln/detail/CVE-2026-1965 https://curl.se/docs/CVE-2026-1965.html https://curl.se/docs/CVE-2026-1965.json https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1965.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "X8OJykaOJlN5EhVA7Y11uQ==": { "id": "X8OJykaOJlN5EhVA7Y11uQ==", "updater": "rhel-vex", "name": "CVE-2026-40467", "description": "A flaw was found in gawk. A Use After Free vulnerability exists in the do_getline_redir() routine within the io.c program file. This vulnerability can be triggered by an attacker, potentially leading to a system crash and causing a Denial of Service (DoS).", "issued": "2026-07-13T12:07:52Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40467 https://bugzilla.redhat.com/show_bug.cgi?id=2499658 https://www.cve.org/CVERecord?id=CVE-2026-40467 https://nvd.nist.gov/vuln/detail/CVE-2026-40467 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40467.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XPUXyp+BOEJyEGOgXafi8Q==": { "id": "XPUXyp+BOEJyEGOgXafi8Q==", "updater": "rhel-vex", "name": "CVE-2022-27943", "description": "A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service.", "issued": "2022-03-26T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-27943 https://bugzilla.redhat.com/show_bug.cgi?id=2071728 https://www.cve.org/CVERecord?id=CVE-2022-27943 https://nvd.nist.gov/vuln/detail/CVE-2022-27943 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-27943.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gcc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XPfYdQhyLnN89+qpSA6LWg==": { "id": "XPfYdQhyLnN89+qpSA6LWg==", "updater": "rhel-vex", "name": "CVE-2026-45447", "description": "A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-45447 https://bugzilla.redhat.com/show_bug.cgi?id=2481898 https://www.cve.org/CVERecord?id=CVE-2026-45447 https://nvd.nist.gov/vuln/detail/CVE-2026-45447 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XwLJYEytIMCdc6/A4MTJHg==": { "id": "XwLJYEytIMCdc6/A4MTJHg==", "updater": "rhel-vex", "name": "CVE-2026-5958", "description": "A Time-of-Check Time-of-Use (TOCTOU) race condition was found in GNU sed. When the -i (in-place) and --follow-symlinks options are used together, sed resolves the symlink but reopens the path for writing. An attacker with write access to the directory containing the symlink can swap it between the check and the open operations. If a privileged user executes sed in this manner on a path influenced by the attacker, it can lead to arbitrary file overwrites and potential privilege escalation.", "issued": "2026-04-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5958 https://bugzilla.redhat.com/show_bug.cgi?id=2458960 https://www.cve.org/CVERecord?id=CVE-2026-5958 https://nvd.nist.gov/vuln/detail/CVE-2026-5958 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5958.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "sed", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Y1YZsYV7ls1vsluhREpXlw==": { "id": "Y1YZsYV7ls1vsluhREpXlw==", "updater": "rhel-vex", "name": "CVE-2026-48618", "description": "A flaw was found in Node.js. This flaw involves a mismatch in how Node.js handles TLS (Transport Layer Security) hostnames and unicode dot separators during authentication. This mismatch can lead to a wildcard-depth authentication bypass. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access and confidentiality impact.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48618 https://bugzilla.redhat.com/show_bug.cgi?id=2493337 https://www.cve.org/CVERecord?id=CVE-2026-48618 https://nvd.nist.gov/vuln/detail/CVE-2026-48618 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", "normalized_severity": "High", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Y3fno6fRSl46BTZQlReNKg==": { "id": "Y3fno6fRSl46BTZQlReNKg==", "updater": "rhel-vex", "name": "CVE-2026-34181", "description": "A flaw was found in OpenSSL. This vulnerability allows a remote attacker to forge PKCS#12 (Public-Key Cryptography Standards #12) files that use Password-Based Message Authentication Code 1 (PBMAC1) with short HMAC (Hash-based Message Authentication Code) keys. This can lead to a service accepting attacker-controlled certificates and private keys with a 1 in 256 probability, potentially enabling impersonation.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34181 https://bugzilla.redhat.com/show_bug.cgi?id=2481882 https://www.cve.org/CVERecord?id=CVE-2026-34181 https://nvd.nist.gov/vuln/detail/CVE-2026-34181 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34181.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YSP3jWIJP4TspvpKDx/wvA==": { "id": "YSP3jWIJP4TspvpKDx/wvA==", "updater": "rhel-vex", "name": "CVE-2026-58016", "description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.", "issued": "2026-04-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58016 https://bugzilla.redhat.com/show_bug.cgi?id=2492257 https://www.cve.org/CVERecord?id=CVE-2026-58016 https://nvd.nist.gov/vuln/detail/CVE-2026-58016 https://gitlab.gnome.org/GNOME/glib/-/issues/3932 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58016.json https://access.redhat.com/errata/RHSA-2026:42089", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "glib2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.68.4-19.el9_8.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ywdulqdw8k75jjL2qb8gPg==": { "id": "Ywdulqdw8k75jjL2qb8gPg==", "updater": "rhel-vex", "name": "CVE-2026-5704", "description": "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.", "issued": "2026-04-06T13:36:20Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5704 https://bugzilla.redhat.com/show_bug.cgi?id=2455360 https://www.cve.org/CVERecord?id=CVE-2026-5704 https://nvd.nist.gov/vuln/detail/CVE-2026-5704 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5704.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YwrNcgB1VRavvqQXhCICXg==": { "id": "YwrNcgB1VRavvqQXhCICXg==", "updater": "rhel-vex", "name": "CVE-2026-5435", "description": "A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.", "issued": "2026-04-28T11:58:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-common", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-274.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z4+dN9Ywyw4meaJMaZos5w==": { "id": "Z4+dN9Ywyw4meaJMaZos5w==", "updater": "rhel-vex", "name": "CVE-2026-59874", "description": "A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.", "issued": "2026-07-08T15:23:47Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59874 https://bugzilla.redhat.com/show_bug.cgi?id=2498116 https://www.cve.org/CVERecord?id=CVE-2026-59874 https://nvd.nist.gov/vuln/detail/CVE-2026-59874 https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59874.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.1.14-1.module+el9.8.0+24540+c30b2ffe", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZLsYJB10R11Jj/NYuhNkpA==": { "id": "ZLsYJB10R11Jj/NYuhNkpA==", "updater": "rhel-vex", "name": "CVE-2026-42338", "description": "A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user's browser.", "issued": "2026-05-12T19:43:16Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42338 https://bugzilla.redhat.com/show_bug.cgi?id=2476810 https://www.cve.org/CVERecord?id=CVE-2026-42338 https://nvd.nist.gov/vuln/detail/CVE-2026-42338 https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZMqtUXBs3IUyb3eHhTEM+Q==": { "id": "ZMqtUXBs3IUyb3eHhTEM+Q==", "updater": "rhel-vex", "name": "CVE-2026-5928", "description": "A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.", "issued": "2026-04-20T20:37:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5928 https://bugzilla.redhat.com/show_bug.cgi?id=2459854 https://www.cve.org/CVERecord?id=CVE-2026-5928 https://nvd.nist.gov/vuln/detail/CVE-2026-5928 https://sourceware.org/bugzilla/show_bug.cgi?id=33998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5928.json https://access.redhat.com/errata/RHSA-2026:42952", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-274.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZZZOb80ipC9wC85x9cRVjA==": { "id": "ZZZOb80ipC9wC85x9cRVjA==", "updater": "rhel-vex", "name": "CVE-2026-48615", "description": "A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48615 https://bugzilla.redhat.com/show_bug.cgi?id=2493335 https://www.cve.org/CVERecord?id=CVE-2026-48615 https://nvd.nist.gov/vuln/detail/CVE-2026-48615 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48615.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aJsQ4a3gp8/jsNBVC56QHw==": { "id": "aJsQ4a3gp8/jsNBVC56QHw==", "updater": "rhel-vex", "name": "CVE-2026-48930", "description": "A flaw was found in Node.js. This vulnerability in the TLS (Transport Layer Security) hostname handling allows embedded null characters in hostnames. This can lead to silent authority rebinding, potentially enabling an attacker to redirect network traffic to an unintended server and disclose sensitive information.", "issued": "2026-06-26T01:14:37Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48930 https://bugzilla.redhat.com/show_bug.cgi?id=2493326 https://www.cve.org/CVERecord?id=CVE-2026-48930 https://nvd.nist.gov/vuln/detail/CVE-2026-48930 https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e https://hackerone.com/reports/3656716 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48930.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aOUfuyvyyWEe7Z1IZT+fGw==": { "id": "aOUfuyvyyWEe7Z1IZT+fGw==", "updater": "rhel-vex", "name": "CVE-2026-34743", "description": "A flaw was found in XZ Utils. When the `lzma_index_decoder()` function processes an empty index, and a subsequent `lzma_index_append()` operation is performed, insufficient memory is allocated. This can lead to a buffer overflow, potentially causing a denial of service (DoS) for affected systems.", "issued": "2026-04-02T18:36:37Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34743 https://bugzilla.redhat.com/show_bug.cgi?id=2454589 https://www.cve.org/CVERecord?id=CVE-2026-34743 https://nvd.nist.gov/vuln/detail/CVE-2026-34743 https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87 https://github.com/tukaani-project/xz/releases/tag/v5.8.3 https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34743.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "xz", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ajT6YifLzju5PlaUiX+EvA==": { "id": "ajT6YifLzju5PlaUiX+EvA==", "updater": "rhel-vex", "name": "CVE-2026-11850", "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len \u003c 2, triggering the underflow when the KDC or kadmind reads principal data.", "issued": "2026-06-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11850 https://bugzilla.redhat.com/show_bug.cgi?id=2459970 https://www.cve.org/CVERecord?id=CVE-2026-11850 https://nvd.nist.gov/vuln/detail/CVE-2026-11850 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11850.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "krb5", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ayJ94QRlWYBn8mXMxBDr+Q==": { "id": "ayJ94QRlWYBn8mXMxBDr+Q==", "updater": "rhel-vex", "name": "CVE-2026-11525", "description": "A flaw was found in undici. When undici processes Set-Cookie headers, it incorrectly interprets the SameSite attribute, accepting partial matches instead of exact ones. This allows a malicious server to downgrade a cookie's SameSite policy to a less secure setting, potentially leading to unintended information disclosure or a weakening of security protections for the user.", "issued": "2026-06-17T17:31:03Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11525 https://bugzilla.redhat.com/show_bug.cgi?id=2490008 https://www.cve.org/CVERecord?id=CVE-2026-11525 https://nvd.nist.gov/vuln/detail/CVE-2026-11525 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11525.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bk6ikdg+f6vAFzgypr0cOw==": { "id": "bk6ikdg+f6vAFzgypr0cOw==", "updater": "rhel-vex", "name": "CVE-2026-48618", "description": "A flaw was found in Node.js. This flaw involves a mismatch in how Node.js handles TLS (Transport Layer Security) hostnames and unicode dot separators during authentication. This mismatch can lead to a wildcard-depth authentication bypass. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access and confidentiality impact.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48618 https://bugzilla.redhat.com/show_bug.cgi?id=2493337 https://www.cve.org/CVERecord?id=CVE-2026-48618 https://nvd.nist.gov/vuln/detail/CVE-2026-48618 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "br+ShorUFea/O+vyZNDWZQ==": { "id": "br+ShorUFea/O+vyZNDWZQ==", "updater": "rhel-vex", "name": "CVE-2024-34459", "description": "A flaw was found in the xmllint program distributed by the libxml2 package. A buffer over-read in the xmlHTMLPrintFileContext function in the xmllint.c file may be triggered when a crafted file is processed with the xmllint program using the `--htmlout` command line option, causing an application crash and resulting in a denial of service.", "issued": "2024-05-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-34459 https://bugzilla.redhat.com/show_bug.cgi?id=2280532 https://www.cve.org/CVERecord?id=CVE-2024-34459 https://nvd.nist.gov/vuln/detail/CVE-2024-34459 https://gitlab.gnome.org/GNOME/libxml2/-/issues/720 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-34459.json https://access.redhat.com/errata/RHSA-2026:28254", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.9.13-14.el9_8.1", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bugTfOdgCaATW4vTnuXTSQ==": { "id": "bugTfOdgCaATW4vTnuXTSQ==", "updater": "rhel-vex", "name": "CVE-2025-70873", "description": "A flaw was found in SQLite. This information disclosure vulnerability exists within the zipfile extension, specifically in the zipfileInflate function. A remote attacker could exploit this by providing a specially crafted ZIP file. Successful exploitation could lead to the disclosure of sensitive heap memory information.", "issued": "2026-03-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-70873 https://bugzilla.redhat.com/show_bug.cgi?id=2447086 https://www.cve.org/CVERecord?id=CVE-2025-70873 https://nvd.nist.gov/vuln/detail/CVE-2025-70873 https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054 https://sqlite.org/forum/forumpost/761eac3c82 https://sqlite.org/src/info/3d459f1fb1bd1b5e https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-70873.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "c76DQiDMr2npmMChLqBaow==": { "id": "c76DQiDMr2npmMChLqBaow==", "updater": "rhel-vex", "name": "CVE-2026-48928", "description": "A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48928 https://bugzilla.redhat.com/show_bug.cgi?id=2493333 https://www.cve.org/CVERecord?id=CVE-2026-48928 https://nvd.nist.gov/vuln/detail/CVE-2026-48928 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48928.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cQ4uQyL9nbrYK9Ka1PjEaQ==": { "id": "cQ4uQyL9nbrYK9Ka1PjEaQ==", "updater": "rhel-vex", "name": "CVE-2026-59873", "description": "A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.", "issued": "2026-07-08T15:22:40Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59873 https://bugzilla.redhat.com/show_bug.cgi?id=2498120 https://www.cve.org/CVERecord?id=CVE-2026-59873 https://nvd.nist.gov/vuln/detail/CVE-2026-59873 https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3 https://github.com/isaacs/node-tar/releases/tag/v7.5.19 https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59873.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cQHSxL+ZfKCYmJnTVIzcRw==": { "id": "cQHSxL+ZfKCYmJnTVIzcRw==", "updater": "rhel-vex", "name": "CVE-2026-48615", "description": "A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48615 https://bugzilla.redhat.com/show_bug.cgi?id=2493335 https://www.cve.org/CVERecord?id=CVE-2026-48615 https://nvd.nist.gov/vuln/detail/CVE-2026-48615 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48615.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cXB5uJOI3UJ7dOyNiQwFDg==": { "id": "cXB5uJOI3UJ7dOyNiQwFDg==", "updater": "rhel-vex", "name": "CVE-2021-46195", "description": "A flaw was discovered in the GNU libiberty library within the demangle_path() function in rust-demangle.c, as distributed in the GNU Compiler Collection (GCC). This flaw allows a crafted symbol to cause stack memory to be exhausted, leading to a crash.", "issued": "2021-01-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-46195 https://bugzilla.redhat.com/show_bug.cgi?id=2046300 https://www.cve.org/CVERecord?id=CVE-2021-46195 https://nvd.nist.gov/vuln/detail/CVE-2021-46195 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-46195.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gcc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ctALzLE36TiW3KdxIlF4Mw==": { "id": "ctALzLE36TiW3KdxIlF4Mw==", "updater": "rhel-vex", "name": "CVE-2026-8924", "description": "A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity.", "issued": "2026-07-03T06:15:04Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8924 https://bugzilla.redhat.com/show_bug.cgi?id=2496765 https://www.cve.org/CVERecord?id=CVE-2026-8924 https://nvd.nist.gov/vuln/detail/CVE-2026-8924 https://curl.se/docs/CVE-2026-8924.html https://curl.se/docs/CVE-2026-8924.json https://hackerone.com/reports/3733905 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8924.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d/522T+B/ARMNSG+3QfAWA==": { "id": "d/522T+B/ARMNSG+3QfAWA==", "updater": "rhel-vex", "name": "CVE-2026-22185", "description": "A flaw was found in OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load. When processing malformed input, a local attacker can exploit a heap buffer underflow vulnerability in the readline() function. This can lead to an out-of-bounds read, potentially causing a denial of service (DoS) and limited disclosure of heap memory contents.", "issued": "2026-01-07T20:26:30Z", "links": "https://access.redhat.com/security/cve/CVE-2026-22185 https://bugzilla.redhat.com/show_bug.cgi?id=2427679 https://www.cve.org/CVERecord?id=CVE-2026-22185 https://nvd.nist.gov/vuln/detail/CVE-2026-22185 https://seclists.org/fulldisclosure/2026/Jan/5 https://seclists.org/fulldisclosure/2026/Jan/8 https://www.openldap.org/ https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22185.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openldap", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d0nPfXoEZybRuV9TMDY3YQ==": { "id": "d0nPfXoEZybRuV9TMDY3YQ==", "updater": "rhel-vex", "name": "CVE-2026-6253", "description": "A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6253 https://bugzilla.redhat.com/show_bug.cgi?id=2461202 https://www.cve.org/CVERecord?id=CVE-2026-6253 https://nvd.nist.gov/vuln/detail/CVE-2026-6253 https://curl.se/docs/CVE-2026-6253.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6253.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d28O4EsS+H4v4JSsIykoOg==": { "id": "d28O4EsS+H4v4JSsIykoOg==", "updater": "rhel-vex", "name": "CVE-2026-48615", "description": "A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48615 https://bugzilla.redhat.com/show_bug.cgi?id=2493335 https://www.cve.org/CVERecord?id=CVE-2026-48615 https://nvd.nist.gov/vuln/detail/CVE-2026-48615 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48615.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d3Z1riL6AkoWkk27zYoWCw==": { "id": "d3Z1riL6AkoWkk27zYoWCw==", "updater": "rhel-vex", "name": "CVE-2026-58055", "description": "A flaw in nghttp2's nghttpx proxy allows a remote attacker to perform HTTP request smuggling and cross-client response-queue poisoning. This occurs because the proxy ambiguously forwards HTTP/1.1 Upgrade requests that contain a Content-Length header to reusable keep-alive backend connections.", "issued": "2026-06-28T01:32:57Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58055 https://bugzilla.redhat.com/show_bug.cgi?id=2493954 https://www.cve.org/CVERecord?id=CVE-2026-58055 https://nvd.nist.gov/vuln/detail/CVE-2026-58055 https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58055.json https://access.redhat.com/errata/RHSA-2026:54662", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libnghttp2", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.43.0-6.el9_8.2", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dDPwWBP+ziJTbpE/idIe+w==": { "id": "dDPwWBP+ziJTbpE/idIe+w==", "updater": "rhel-vex", "name": "CVE-2026-34181", "description": "A flaw was found in OpenSSL. This vulnerability allows a remote attacker to forge PKCS#12 (Public-Key Cryptography Standards #12) files that use Password-Based Message Authentication Code 1 (PBMAC1) with short HMAC (Hash-based Message Authentication Code) keys. This can lead to a service accepting attacker-controlled certificates and private keys with a 1 in 256 probability, potentially enabling impersonation.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34181 https://bugzilla.redhat.com/show_bug.cgi?id=2481882 https://www.cve.org/CVERecord?id=CVE-2026-34181 https://nvd.nist.gov/vuln/detail/CVE-2026-34181 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34181.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dKzgwwkG/spsYd8PVvrk6A==": { "id": "dKzgwwkG/spsYd8PVvrk6A==", "updater": "rhel-vex", "name": "CVE-2023-39804", "description": "A flaw was found in tar. This issue occurs when extended attributes are processed in PAX archives, and could allow an attacker to cause an application crash, resulting in a denial of service.", "issued": "2023-12-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-39804 https://bugzilla.redhat.com/show_bug.cgi?id=2254067 https://www.cve.org/CVERecord?id=CVE-2023-39804 https://nvd.nist.gov/vuln/detail/CVE-2023-39804 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-39804.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dz5oxhJicudEulHfFUUHJw==": { "id": "dz5oxhJicudEulHfFUUHJw==", "updater": "rhel-vex", "name": "CVE-2025-3360", "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.", "issued": "2025-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-3360 https://bugzilla.redhat.com/show_bug.cgi?id=2357754 https://www.cve.org/CVERecord?id=CVE-2025-3360 https://nvd.nist.gov/vuln/detail/CVE-2025-3360 https://gitlab.gnome.org/GNOME/glib/-/issues/3647 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-3360.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "e0/Fzu8wfMZp9zX32i9rMQ==": { "id": "e0/Fzu8wfMZp9zX32i9rMQ==", "updater": "rhel-vex", "name": "CVE-2026-27456", "description": "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.", "issued": "2026-04-03T21:23:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-27456 https://bugzilla.redhat.com/show_bug.cgi?id=2454956 https://www.cve.org/CVERecord?id=CVE-2026-27456 https://nvd.nist.gov/vuln/detail/CVE-2026-27456 https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4 https://github.com/util-linux/util-linux/releases/tag/v2.41.4 https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27456.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eaoaQZQXOAlAomwMnyNLSQ==": { "id": "eaoaQZQXOAlAomwMnyNLSQ==", "updater": "rhel-vex", "name": "CVE-2026-5435", "description": "A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.", "issued": "2026-04-28T11:58:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-274.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "egAiHhCEkMFVMFqpyh1hdw==": { "id": "egAiHhCEkMFVMFqpyh1hdw==", "updater": "rhel-vex", "name": "CVE-2026-6733", "description": "A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici's HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.", "issued": "2026-06-17T17:14:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6733 https://bugzilla.redhat.com/show_bug.cgi?id=2490006 https://www.cve.org/CVERecord?id=CVE-2026-6733 https://nvd.nist.gov/vuln/detail/CVE-2026-6733 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 https://hackerone.com/reports/3582376 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6733.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fPh6cJ7fj6ecJeD/S/iyJg==": { "id": "fPh6cJ7fj6ecJeD/S/iyJg==", "updater": "rhel-vex", "name": "CVE-2026-58015", "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.", "issued": "2026-04-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58015 https://bugzilla.redhat.com/show_bug.cgi?id=2492256 https://www.cve.org/CVERecord?id=CVE-2026-58015 https://nvd.nist.gov/vuln/detail/CVE-2026-58015 https://gitlab.gnome.org/GNOME/glib/-/issues/3931 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58015.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ffV5WUu4x4B5YykIdxqFhA==": { "id": "ffV5WUu4x4B5YykIdxqFhA==", "updater": "rhel-vex", "name": "CVE-2026-42764", "description": "A flaw was found in the OpenSSL QUIC (Quick UDP Internet Connections) server. A remote attacker could send a specially crafted QUIC initial packet with an invalid token. If the server's address validation is explicitly disabled, this could lead to a NULL pointer dereference, causing the server process to terminate abnormally and resulting in a Denial of Service (DoS).", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42764 https://bugzilla.redhat.com/show_bug.cgi?id=2481887 https://www.cve.org/CVERecord?id=CVE-2026-42764 https://nvd.nist.gov/vuln/detail/CVE-2026-42764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42764.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hUPR/bV/A80tipW3ZXwmTg==": { "id": "hUPR/bV/A80tipW3ZXwmTg==", "updater": "rhel-vex", "name": "CVE-2026-13149", "description": "A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.", "issued": "2026-06-30T08:30:34Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13149 https://bugzilla.redhat.com/show_bug.cgi?id=2494813 https://www.cve.org/CVERecord?id=CVE-2026-13149 https://nvd.nist.gov/vuln/detail/CVE-2026-13149 https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754 https://www.npmjs.com/package/brace-expansion https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.1.14-1.module+el9.8.0+24540+c30b2ffe", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hbenTywo0l7anle5/bJQBw==": { "id": "hbenTywo0l7anle5/bJQBw==", "updater": "rhel-vex", "name": "CVE-2026-34182", "description": "A flaw was found in OpenSSL's Cryptographic Message Services (CMS) AuthEnvelopedData processing. An on-path attacker can exploit insufficient input validation on cipher and tag length fields by sending specially crafted CMS messages. This can lead to the forging of messages or bypassing integrity validation. Consequently, an attacker may achieve key-equivalent functionality for a given CMS recipient.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34182 https://bugzilla.redhat.com/show_bug.cgi?id=2481884 https://www.cve.org/CVERecord?id=CVE-2026-34182 https://nvd.nist.gov/vuln/detail/CVE-2026-34182 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34182.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "i9sUrKKUObLH200e/JvjcA==": { "id": "i9sUrKKUObLH200e/JvjcA==", "updater": "rhel-vex", "name": "CVE-2026-59873", "description": "A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.", "issued": "2026-07-08T15:22:40Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59873 https://bugzilla.redhat.com/show_bug.cgi?id=2498120 https://www.cve.org/CVERecord?id=CVE-2026-59873 https://nvd.nist.gov/vuln/detail/CVE-2026-59873 https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3 https://github.com/isaacs/node-tar/releases/tag/v7.5.19 https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59873.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iF/o4aDbQf1DAw7R+LiVQw==": { "id": "iF/o4aDbQf1DAw7R+LiVQw==", "updater": "rhel-vex", "name": "CVE-2025-68972", "description": "A flaw was found in GnuPG. An adversary can exploit this vulnerability by crafting a signed message that includes a form feed character (\\f) at the end of a plaintext line. This allows the adversary to append additional, unsigned text to the message while the signature verification still reports success. This issue leads to an integrity bypass, potentially enabling the spoofing of signed communications.", "issued": "2025-12-27T22:52:30Z", "links": "https://access.redhat.com/security/cve/CVE-2025-68972 https://bugzilla.redhat.com/show_bug.cgi?id=2425646 https://www.cve.org/CVERecord?id=CVE-2025-68972 https://nvd.nist.gov/vuln/detail/CVE-2025-68972 https://gpg.fail/formfeed https://news.ycombinator.com/item?id=46404339 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68972.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iFdXYPdbzmitrrthD7u8yA==": { "id": "iFdXYPdbzmitrrthD7u8yA==", "updater": "rhel-vex", "name": "CVE-2026-59874", "description": "A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.", "issued": "2026-07-08T15:23:47Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59874 https://bugzilla.redhat.com/show_bug.cgi?id=2498116 https://www.cve.org/CVERecord?id=CVE-2026-59874 https://nvd.nist.gov/vuln/detail/CVE-2026-59874 https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59874.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iwe2PkNe91EUwDENn+pmew==": { "id": "iwe2PkNe91EUwDENn+pmew==", "updater": "rhel-vex", "name": "CVE-2026-40468", "description": "A flaw was found in gawk. An integer overflow vulnerability could allow a local attacker to cause memory exhaustion, leading to a denial of service. This flaw may also enable an attacker to corrupt gawk's internal memory, potentially leading to system instability.", "issued": "2026-07-13T12:07:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40468 https://bugzilla.redhat.com/show_bug.cgi?id=2499655 https://www.cve.org/CVERecord?id=CVE-2026-40468 https://nvd.nist.gov/vuln/detail/CVE-2026-40468 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40468.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ixc06f0H9vqMfsbwQSwwvA==": { "id": "ixc06f0H9vqMfsbwQSwwvA==", "updater": "rhel-vex", "name": "CVE-2023-32636", "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.", "issued": "2022-12-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-32636 https://bugzilla.redhat.com/show_bug.cgi?id=2211833 https://www.cve.org/CVERecord?id=CVE-2023-32636 https://nvd.nist.gov/vuln/detail/CVE-2023-32636 https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835 https://gitlab.gnome.org/GNOME/glib/-/issues/2841 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-32636.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "j9OVo/jK62GKOQBSgKgJGw==": { "id": "j9OVo/jK62GKOQBSgKgJGw==", "updater": "rhel-vex", "name": "CVE-2026-12151", "description": "A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.", "issued": "2026-06-17T16:05:38Z", "links": "https://access.redhat.com/security/cve/CVE-2026-12151 https://bugzilla.redhat.com/show_bug.cgi?id=2489980 https://www.cve.org/CVERecord?id=CVE-2026-12151 https://nvd.nist.gov/vuln/detail/CVE-2026-12151 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-full-i18n", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jiVVTQmOtKqVixv7agF/Hg==": { "id": "jiVVTQmOtKqVixv7agF/Hg==", "updater": "rhel-vex", "name": "CVE-2025-27113", "description": "A flaw was found in libxml2. This vulnerability allows a NULL pointer dereference, leading to a potential crash or denial of service via a crafted XML pattern.", "issued": "2025-02-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-27113 https://bugzilla.redhat.com/show_bug.cgi?id=2346410 https://www.cve.org/CVERecord?id=CVE-2025-27113 https://nvd.nist.gov/vuln/detail/CVE-2025-27113 https://gitlab.gnome.org/GNOME/libxml2/-/issues/861 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-27113.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jyKmIhGp11jpJBCY83RPQA==": { "id": "jyKmIhGp11jpJBCY83RPQA==", "updater": "rhel-vex", "name": "CVE-2026-13149", "description": "A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.", "issued": "2026-06-30T08:30:34Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13149 https://bugzilla.redhat.com/show_bug.cgi?id=2494813 https://www.cve.org/CVERecord?id=CVE-2026-13149 https://nvd.nist.gov/vuln/detail/CVE-2026-13149 https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754 https://www.npmjs.com/package/brace-expansion https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kDNo+1U3zj32TNGC/5DIKw==": { "id": "kDNo+1U3zj32TNGC/5DIKw==", "updater": "rhel-vex", "name": "CVE-2026-8286", "description": "A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.", "issued": "2026-07-03T06:14:17Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8286 https://bugzilla.redhat.com/show_bug.cgi?id=2496763 https://www.cve.org/CVERecord?id=CVE-2026-8286 https://nvd.nist.gov/vuln/detail/CVE-2026-8286 https://curl.se/docs/CVE-2026-8286.html https://curl.se/docs/CVE-2026-8286.json https://hackerone.com/reports/3718195 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8286.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kGC5RaOJSDDnqCSoiLqrIA==": { "id": "kGC5RaOJSDDnqCSoiLqrIA==", "updater": "rhel-vex", "name": "CVE-2026-54371", "description": "A flaw was found in the `attr` package. This vulnerability allows a local attacker to perform a symlink traversal attack by replacing a pathname component with a symbolic link - either during directory hierarchy traversal by `getfattr` or during backup restoration by `setfattr`, which reads and resolves full pathnames from backup files. In both cases, when these utilities are executed by a privileged process over a path controlled by the attacker, this can lead to local privilege escalation.", "issued": "2026-06-29T13:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-54371 https://bugzilla.redhat.com/show_bug.cgi?id=2490283 https://www.cve.org/CVERecord?id=CVE-2026-54371 https://nvd.nist.gov/vuln/detail/CVE-2026-54371 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "attr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kGY3woMWc1W36Wi2YstJ0Q==": { "id": "kGY3woMWc1W36Wi2YstJ0Q==", "updater": "rhel-vex", "name": "CVE-2026-6791", "description": "A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application.", "issued": "2026-08-10T18:41:25Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6791 https://bugzilla.redhat.com/show_bug.cgi?id=2513603 https://www.cve.org/CVERecord?id=CVE-2026-6791 https://nvd.nist.gov/vuln/detail/CVE-2026-6791 https://sourceware.org/bugzilla/show_bug.cgi?id=34091 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6791.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kR9Bs/gd2Qm09J0HnMmVzg==": { "id": "kR9Bs/gd2Qm09J0HnMmVzg==", "updater": "rhel-vex", "name": "CVE-2026-58014", "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58014 https://bugzilla.redhat.com/show_bug.cgi?id=2492255 https://www.cve.org/CVERecord?id=CVE-2026-58014 https://nvd.nist.gov/vuln/detail/CVE-2026-58014 https://gitlab.gnome.org/GNOME/glib/-/issues/3930 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58014.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "klH60uFrR0WkawaSlcOEKg==": { "id": "klH60uFrR0WkawaSlcOEKg==", "updater": "rhel-vex", "name": "CVE-2026-1484", "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1484 https://bugzilla.redhat.com/show_bug.cgi?id=2433259 https://www.cve.org/CVERecord?id=CVE-2026-1484 https://nvd.nist.gov/vuln/detail/CVE-2026-1484 https://gitlab.gnome.org/GNOME/glib/-/issues/3870 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1484.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kvWVhRPjc0HYeWvbQJGJEg==": { "id": "kvWVhRPjc0HYeWvbQJGJEg==", "updater": "rhel-vex", "name": "CVE-2026-59873", "description": "A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.", "issued": "2026-07-08T15:22:40Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59873 https://bugzilla.redhat.com/show_bug.cgi?id=2498120 https://www.cve.org/CVERecord?id=CVE-2026-59873 https://nvd.nist.gov/vuln/detail/CVE-2026-59873 https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3 https://github.com/isaacs/node-tar/releases/tag/v7.5.19 https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59873.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.1.14-1.module+el9.8.0+24540+c30b2ffe", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "l6IrI73Pg+lrisEtcgX+0Q==": { "id": "l6IrI73Pg+lrisEtcgX+0Q==", "updater": "rhel-vex", "name": "CVE-2026-3784", "description": "A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user.", "issued": "2026-03-11T10:09:21Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3784 https://bugzilla.redhat.com/show_bug.cgi?id=2446449 https://www.cve.org/CVERecord?id=CVE-2026-3784 https://nvd.nist.gov/vuln/detail/CVE-2026-3784 http://www.openwall.com/lists/oss-security/2026/03/11/3 https://curl.se/docs/CVE-2026-3784.html https://curl.se/docs/CVE-2026-3784.json https://hackerone.com/reports/3584903 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3784.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lFfYg6015iTLGI5pZVMU7w==": { "id": "lFfYg6015iTLGI5pZVMU7w==", "updater": "rhel-vex", "name": "CVE-2026-58012", "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.", "issued": "2026-03-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58012 https://bugzilla.redhat.com/show_bug.cgi?id=2492247 https://www.cve.org/CVERecord?id=CVE-2026-58012 https://nvd.nist.gov/vuln/detail/CVE-2026-58012 https://gitlab.gnome.org/GNOME/glib/-/issues/3918 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58012.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lQBARBTddFvexevUD04GZA==": { "id": "lQBARBTddFvexevUD04GZA==", "updater": "rhel-vex", "name": "CVE-2026-5745", "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5745 https://bugzilla.redhat.com/show_bug.cgi?id=2455921 https://www.cve.org/CVERecord?id=CVE-2026-5745 https://nvd.nist.gov/vuln/detail/CVE-2026-5745 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5745.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lzB4zyDZ+L/0TgHu+34IeA==": { "id": "lzB4zyDZ+L/0TgHu+34IeA==", "updater": "rhel-vex", "name": "CVE-2026-41989", "description": "A flaw was found in Libgcrypt. A remote attacker could exploit this vulnerability by sending crafted Elliptic Curve Diffie-Hellman (ECDH) ciphertext to the `gcry_pk_decrypt` function. This can lead to a heap-based buffer overflow, potentially causing a denial of service (DoS) condition.", "issued": "2026-04-23T04:30:26Z", "links": "https://access.redhat.com/security/cve/CVE-2026-41989 https://bugzilla.redhat.com/show_bug.cgi?id=2461063 https://www.cve.org/CVERecord?id=CVE-2026-41989 https://nvd.nist.gov/vuln/detail/CVE-2026-41989 https://dev.gnupg.org/T8211 https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html https://www.openwall.com/lists/oss-security/2026/04/21/1 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41989.json https://access.redhat.com/errata/RHSA-2026:50147", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:1.10.0-13.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mINycH+x60PTfgPLuT1gJw==": { "id": "mINycH+x60PTfgPLuT1gJw==", "updater": "rhel-vex", "name": "CVE-2026-42767", "description": "A flaw was found in OpenSSL. An attacker controlling a Certificate Management Protocol (CMP) server, or acting as a man-in-the-middle, could craft a malicious CMP response. This response, containing a Certificate Request Message Format (CRMF) CertRepMessage with a specific malformed EncryptedValue structure, would trigger a NULL pointer dereference in the OpenSSL CMP client. This vulnerability leads to a crash of the application, resulting in a Denial of Service (DoS).", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42767 https://bugzilla.redhat.com/show_bug.cgi?id=2481891 https://www.cve.org/CVERecord?id=CVE-2026-42767 https://nvd.nist.gov/vuln/detail/CVE-2026-42767 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42767.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mJw+LvAbCoVMIOZXCXNFpg==": { "id": "mJw+LvAbCoVMIOZXCXNFpg==", "updater": "rhel-vex", "name": "CVE-2025-5916", "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5916 https://bugzilla.redhat.com/show_bug.cgi?id=2370872 https://www.cve.org/CVERecord?id=CVE-2025-5916 https://nvd.nist.gov/vuln/detail/CVE-2025-5916 https://github.com/libarchive/libarchive/pull/2568 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5916.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mNXETDKAQUXFDVp1hgY7fQ==": { "id": "mNXETDKAQUXFDVp1hgY7fQ==", "updater": "rhel-vex", "name": "CVE-2026-5435", "description": "A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.", "issued": "2026-04-28T11:58:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5435 https://bugzilla.redhat.com/show_bug.cgi?id=2463465 https://www.cve.org/CVERecord?id=CVE-2026-5435 https://nvd.nist.gov/vuln/detail/CVE-2026-5435 https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u https://sourceware.org/bugzilla/show_bug.cgi?id=34033 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5435.json https://access.redhat.com/errata/RHSA-2026:42952", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc-minimal-langpack", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.34-274.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mZCCwO//htsOIXazj/SeOw==": { "id": "mZCCwO//htsOIXazj/SeOw==", "updater": "rhel-vex", "name": "CVE-2026-31789", "description": "A flaw was found in OpenSSL. This vulnerability, a heap buffer overflow, affects 32-bit systems when processing an unusually large X.509 certificate. If an application or service attempts to print or log such a specially crafted certificate, it could lead to a system crash or potentially allow an attacker to execute arbitrary code. This issue is considered low severity due to the specific conditions required for exploitation, including the need for an extremely large certificate and a 32-bit operating environment.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-31789 https://bugzilla.redhat.com/show_bug.cgi?id=2451095 https://www.cve.org/CVERecord?id=CVE-2026-31789 https://nvd.nist.gov/vuln/detail/CVE-2026-31789 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31789.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mgY0OXX1J12mJy1iNllE3A==": { "id": "mgY0OXX1J12mJy1iNllE3A==", "updater": "rhel-vex", "name": "CVE-2026-45447", "description": "A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-45447 https://bugzilla.redhat.com/show_bug.cgi?id=2481898 https://www.cve.org/CVERecord?id=CVE-2026-45447 https://nvd.nist.gov/vuln/detail/CVE-2026-45447 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "High", "package": { "id": "", "name": "openssl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mllkaOQAaJYNZpdIF7Bkbw==": { "id": "mllkaOQAaJYNZpdIF7Bkbw==", "updater": "rhel-vex", "name": "CVE-2024-9681", "description": "A vulnerability was found in curl. When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than intended.", "issued": "2024-11-06T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-9681 https://bugzilla.redhat.com/show_bug.cgi?id=2322969 https://www.cve.org/CVERecord?id=CVE-2024-9681 https://nvd.nist.gov/vuln/detail/CVE-2024-9681 https://curl.se/docs/CVE-2024-9681.html https://hackerone.com/reports/2764830 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-9681.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "o/v8DGswQXGkB45uD8rRUw==": { "id": "o/v8DGswQXGkB45uD8rRUw==", "updater": "rhel-vex", "name": "CVE-2026-15028", "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.", "issued": "2026-07-08T10:10:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-15028 https://bugzilla.redhat.com/show_bug.cgi?id=2497970 https://www.cve.org/CVERecord?id=CVE-2026-15028 https://nvd.nist.gov/vuln/detail/CVE-2026-15028 https://github.com/libarchive/libarchive/issues/3251 https://github.com/libarchive/libarchive/pull/3253 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15028.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oGYbR6FNz1KIQ8VJiypCZg==": { "id": "oGYbR6FNz1KIQ8VJiypCZg==", "updater": "rhel-vex", "name": "CVE-2026-48930", "description": "A flaw was found in Node.js. This vulnerability in the TLS (Transport Layer Security) hostname handling allows embedded null characters in hostnames. This can lead to silent authority rebinding, potentially enabling an attacker to redirect network traffic to an unintended server and disclose sensitive information.", "issued": "2026-06-26T01:14:37Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48930 https://bugzilla.redhat.com/show_bug.cgi?id=2493326 https://www.cve.org/CVERecord?id=CVE-2026-48930 https://nvd.nist.gov/vuln/detail/CVE-2026-48930 https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e https://hackerone.com/reports/3656716 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48930.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "p0umWDpPMiOz8HPGPopybw==": { "id": "p0umWDpPMiOz8HPGPopybw==", "updater": "rhel-vex", "name": "CVE-2026-11525", "description": "A flaw was found in undici. When undici processes Set-Cookie headers, it incorrectly interprets the SameSite attribute, accepting partial matches instead of exact ones. This allows a malicious server to downgrade a cookie's SameSite policy to a less secure setting, potentially leading to unintended information disclosure or a weakening of security protections for the user.", "issued": "2026-06-17T17:31:03Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11525 https://bugzilla.redhat.com/show_bug.cgi?id=2490008 https://www.cve.org/CVERecord?id=CVE-2026-11525 https://nvd.nist.gov/vuln/detail/CVE-2026-11525 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11525.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pOKoOa+tppgNwBAEgYrxlg==": { "id": "pOKoOa+tppgNwBAEgYrxlg==", "updater": "rhel-vex", "name": "CVE-2026-48618", "description": "A flaw was found in Node.js. This flaw involves a mismatch in how Node.js handles TLS (Transport Layer Security) hostnames and unicode dot separators during authentication. This mismatch can lead to a wildcard-depth authentication bypass. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access and confidentiality impact.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48618 https://bugzilla.redhat.com/show_bug.cgi?id=2493337 https://www.cve.org/CVERecord?id=CVE-2026-48618 https://nvd.nist.gov/vuln/detail/CVE-2026-48618 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", "normalized_severity": "High", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pU8Z0LfIMQCZLgwp2Yn90g==": { "id": "pU8Z0LfIMQCZLgwp2Yn90g==", "updater": "rhel-vex", "name": "CVE-2026-48928", "description": "A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48928 https://bugzilla.redhat.com/show_bug.cgi?id=2493333 https://www.cve.org/CVERecord?id=CVE-2026-48928 https://nvd.nist.gov/vuln/detail/CVE-2026-48928 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48928.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "poe+ZOEeV2eDvTqSL2bcHA==": { "id": "poe+ZOEeV2eDvTqSL2bcHA==", "updater": "rhel-vex", "name": "CVE-2026-18508", "description": "A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.", "issued": "2026-07-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-18508 https://bugzilla.redhat.com/show_bug.cgi?id=2509843 https://www.cve.org/CVERecord?id=CVE-2026-18508 https://nvd.nist.gov/vuln/detail/CVE-2026-18508 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18508.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qFIYjZJeFnLAVC7lR0n6oQ==": { "id": "qFIYjZJeFnLAVC7lR0n6oQ==", "updater": "rhel-vex", "name": "CVE-2026-0989", "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested \u003cinclude\u003e directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0989 https://bugzilla.redhat.com/show_bug.cgi?id=2429933 https://www.cve.org/CVERecord?id=CVE-2026-0989 https://nvd.nist.gov/vuln/detail/CVE-2026-0989 https://gitlab.gnome.org/GNOME/libxml2/-/issues/998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0989.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qFnCm62d/bnijdlwZoRQeQ==": { "id": "qFnCm62d/bnijdlwZoRQeQ==", "updater": "rhel-vex", "name": "CVE-2026-48933", "description": "A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48933 https://bugzilla.redhat.com/show_bug.cgi?id=2493331 https://www.cve.org/CVERecord?id=CVE-2026-48933 https://nvd.nist.gov/vuln/detail/CVE-2026-48933 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qIUMlexpn07c5Ly85v5AjQ==": { "id": "qIUMlexpn07c5Ly85v5AjQ==", "updater": "rhel-vex", "name": "CVE-2026-6368", "description": "A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS).", "issued": "2026-08-10T18:40:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6368 https://bugzilla.redhat.com/show_bug.cgi?id=2513608 https://www.cve.org/CVERecord?id=CVE-2026-6368 https://nvd.nist.gov/vuln/detail/CVE-2026-6368 https://sourceware.org/bugzilla/show_bug.cgi?id=34090 https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6368.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qh5gUahI9nge5StfpD2Efg==": { "id": "qh5gUahI9nge5StfpD2Efg==", "updater": "rhel-vex", "name": "CVE-2026-42770", "description": "A flaw was found in OpenSSL. A malicious peer can exploit this vulnerability by presenting a specially crafted DHX (X9.42) peer key. Due to improper validation of the peer key's subgroup membership, an attacker can recover the victim's private key after a small number of key exchange attempts. This information disclosure can lead to unauthorized access or further compromise of affected systems.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42770 https://bugzilla.redhat.com/show_bug.cgi?id=2481894 https://www.cve.org/CVERecord?id=CVE-2026-42770 https://nvd.nist.gov/vuln/detail/CVE-2026-42770 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42770.json https://access.redhat.com/errata/RHSA-2026:25239", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl-libs", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "1:3.5.5-4.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qkPjlqaV2EZ52NAHd/IgfQ==": { "id": "qkPjlqaV2EZ52NAHd/IgfQ==", "updater": "rhel-vex", "name": "CVE-2026-11525", "description": "A flaw was found in undici. When undici processes Set-Cookie headers, it incorrectly interprets the SameSite attribute, accepting partial matches instead of exact ones. This allows a malicious server to downgrade a cookie's SameSite policy to a less secure setting, potentially leading to unintended information disclosure or a weakening of security protections for the user.", "issued": "2026-06-17T17:31:03Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11525 https://bugzilla.redhat.com/show_bug.cgi?id=2490008 https://www.cve.org/CVERecord?id=CVE-2026-11525 https://nvd.nist.gov/vuln/detail/CVE-2026-11525 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11525.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rT7Zl5hqfT/SFXkQlgRUqg==": { "id": "rT7Zl5hqfT/SFXkQlgRUqg==", "updater": "rhel-vex", "name": "CVE-2026-12151", "description": "A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.", "issued": "2026-06-17T16:05:38Z", "links": "https://access.redhat.com/security/cve/CVE-2026-12151 https://bugzilla.redhat.com/show_bug.cgi?id=2489980 https://www.cve.org/CVERecord?id=CVE-2026-12151 https://nvd.nist.gov/vuln/detail/CVE-2026-12151 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "npm", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rhaCfU7pM1FgApTAw4PpPA==": { "id": "rhaCfU7pM1FgApTAw4PpPA==", "updater": "rhel-vex", "name": "CVE-2026-18739", "description": "A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.", "issued": "2026-08-03T18:46:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-18739 https://bugzilla.redhat.com/show_bug.cgi?id=2510737 https://www.cve.org/CVERecord?id=CVE-2026-18739 https://nvd.nist.gov/vuln/detail/CVE-2026-18739 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18739.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "popt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rmKqD8ZR5vrHqnZkFulqdg==": { "id": "rmKqD8ZR5vrHqnZkFulqdg==", "updater": "rhel-vex", "name": "CVE-2025-64118", "description": "A flaw was found in node-tar, a Tar utility for Node.js. This vulnerability allows a local attacker to potentially disclose sensitive information. When the .t (or .list) function is used with { sync: true } to read tar entry contents, and the tar file is concurrently modified on disk to a smaller size, the function may return uninitialized memory contents. This could lead to the exposure of arbitrary data.", "issued": "2025-10-30T17:50:20Z", "links": "https://access.redhat.com/security/cve/CVE-2025-64118 https://bugzilla.redhat.com/show_bug.cgi?id=2407440 https://www.cve.org/CVERecord?id=CVE-2025-64118 https://nvd.nist.gov/vuln/detail/CVE-2025-64118 https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d https://github.com/isaacs/node-tar/issues/445 https://github.com/isaacs/node-tar/pull/446 https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-64118.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rqKN8+22i5Wi/U+pG39tNg==": { "id": "rqKN8+22i5Wi/U+pG39tNg==", "updater": "rhel-vex", "name": "CVE-2026-13757", "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.", "issued": "2026-06-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13757 https://bugzilla.redhat.com/show_bug.cgi?id=2494556 https://www.cve.org/CVERecord?id=CVE-2026-13757 https://nvd.nist.gov/vuln/detail/CVE-2026-13757 https://github.com/advisories/GHSA-p2wm-69qx-x25w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13757.json https://access.redhat.com/errata/RHSA-2026:49667", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "p11-kit-trust", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:0.26.4-1.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "smB1yCGhBb8gDhPAER7odg==": { "id": "smB1yCGhBb8gDhPAER7odg==", "updater": "rhel-vex", "name": "CVE-2025-14524", "description": "A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14524 https://bugzilla.redhat.com/show_bug.cgi?id=2426407 https://www.cve.org/CVERecord?id=CVE-2025-14524 https://nvd.nist.gov/vuln/detail/CVE-2025-14524 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14524.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sqtLRwfRzV6y9srK/2QK2Q==": { "id": "sqtLRwfRzV6y9srK/2QK2Q==", "updater": "rhel-vex", "name": "CVE-2026-9547", "description": "A flaw was found in curl. When a libcurl-based application uses SCP:// or SFTP:// for transfers and employs the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This occurs if the server's host key type differs from the one stored in the known_hosts file. The callback mechanism fails to enforce the host key restriction, enabling a connection to an untrusted server and risking a man-in-the-middle attack.", "issued": "2026-07-03T06:18:44Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9547 https://bugzilla.redhat.com/show_bug.cgi?id=2496758 https://www.cve.org/CVERecord?id=CVE-2026-9547 https://nvd.nist.gov/vuln/detail/CVE-2026-9547 https://curl.se/docs/CVE-2026-9547.html https://curl.se/docs/CVE-2026-9547.json https://hackerone.com/reports/3751712 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9547.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "svCt47J2Zwa45xj8gn3U/w==": { "id": "svCt47J2Zwa45xj8gn3U/w==", "updater": "rhel-vex", "name": "CVE-2026-1485", "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1485 https://bugzilla.redhat.com/show_bug.cgi?id=2433325 https://www.cve.org/CVERecord?id=CVE-2026-1485 https://nvd.nist.gov/vuln/detail/CVE-2026-1485 https://gitlab.gnome.org/GNOME/glib/-/issues/3871 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1485.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sykv+pGN4TXggZNIwL/H4g==": { "id": "sykv+pGN4TXggZNIwL/H4g==", "updater": "rhel-vex", "name": "CVE-2025-5915", "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5915 https://bugzilla.redhat.com/show_bug.cgi?id=2370865 https://www.cve.org/CVERecord?id=CVE-2025-5915 https://nvd.nist.gov/vuln/detail/CVE-2025-5915 https://github.com/libarchive/libarchive/pull/2599 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5915.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tUTc+tWHx1wVpIbeqTmR0w==": { "id": "tUTc+tWHx1wVpIbeqTmR0w==", "updater": "rhel-vex", "name": "CVE-2026-59874", "description": "A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.", "issued": "2026-07-08T15:23:47Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59874 https://bugzilla.redhat.com/show_bug.cgi?id=2498116 https://www.cve.org/CVERecord?id=CVE-2026-59874 https://nvd.nist.gov/vuln/detail/CVE-2026-59874 https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 https://github.com/isaacs/node-tar/releases/tag/v7.5.18 https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59874.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tbhLz74i3ShwS72WbIsoOA==": { "id": "tbhLz74i3ShwS72WbIsoOA==", "updater": "rhel-vex", "name": "CVE-2023-50495", "description": "A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry().", "issued": "2023-12-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-50495 https://bugzilla.redhat.com/show_bug.cgi?id=2254244 https://www.cve.org/CVERecord?id=CVE-2023-50495 https://nvd.nist.gov/vuln/detail/CVE-2023-50495 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-50495.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "txqyo4HZxt82KZ1LFkOAcA==": { "id": "txqyo4HZxt82KZ1LFkOAcA==", "updater": "rhel-vex", "name": "CVE-2026-13149", "description": "A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.", "issued": "2026-06-30T08:30:34Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13149 https://bugzilla.redhat.com/show_bug.cgi?id=2494813 https://www.cve.org/CVERecord?id=CVE-2026-13149 https://nvd.nist.gov/vuln/detail/CVE-2026-13149 https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754 https://www.npmjs.com/package/brace-expansion https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json https://access.redhat.com/errata/RHSA-2026:47058", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-2.module+el9.8.0+24538+3f176d52", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "u0cs09LPRVEEfen4PHM6gA==": { "id": "u0cs09LPRVEEfen4PHM6gA==", "updater": "rhel-vex", "name": "CVE-2026-0990", "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0990 https://bugzilla.redhat.com/show_bug.cgi?id=2429959 https://www.cve.org/CVERecord?id=CVE-2026-0990 https://nvd.nist.gov/vuln/detail/CVE-2026-0990 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0990.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uaetuJImncB6wudykQLpEA==": { "id": "uaetuJImncB6wudykQLpEA==", "updater": "rhel-vex", "name": "CVE-2025-1632", "description": "A flaw was found in the bsdunzip utility of libarchive. In affected versions, a specially crafted file may trigger a null pointer dereference. This issue can lead to an application crash or other unexpected behavior. This bug does not compromise the integrity or availability of the base system.", "issued": "2025-02-24T13:31:08Z", "links": "https://access.redhat.com/security/cve/CVE-2025-1632 https://bugzilla.redhat.com/show_bug.cgi?id=2347309 https://www.cve.org/CVERecord?id=CVE-2025-1632 https://nvd.nist.gov/vuln/detail/CVE-2025-1632 https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc https://vuldb.com/?ctiid.296619 https://vuldb.com/?id.296619 https://vuldb.com/?submit.496460 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1632.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vH+nziLZjIpD4JaIkhx3FA==": { "id": "vH+nziLZjIpD4JaIkhx3FA==", "updater": "rhel-vex", "name": "CVE-2026-51298", "description": "A flaw was found in SQLite. A remote attacker could exploit a use-after-free vulnerability in the JSON extraction function. This occurs when the program attempts to access memory after it has been freed, specifically within the `JsonParse` object. Successful exploitation of this vulnerability can lead to a service crash and a denial of service (DoS) for affected systems.", "issued": "2026-07-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-51298 https://bugzilla.redhat.com/show_bug.cgi?id=2507556 https://www.cve.org/CVERecord?id=CVE-2026-51298 https://nvd.nist.gov/vuln/detail/CVE-2026-51298 https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51298 https://github.com/sqlite/sqlite/blob/master/src/json.c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-51298.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vMgggE6Cjv/N2Jk4Dk6FYw==": { "id": "vMgggE6Cjv/N2Jk4Dk6FYw==", "updater": "rhel-vex", "name": "CVE-2026-11856", "description": "A flaw was found in curl. When `libcurl` performs a transfer to an HTTP origin using Digest authentication and then reuses the same connection handle for a subsequent transfer to a different origin, it may incorrectly send the authentication header intended for the first origin to the second. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data.", "issued": "2026-07-03T06:13:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11856 https://bugzilla.redhat.com/show_bug.cgi?id=2496767 https://www.cve.org/CVERecord?id=CVE-2026-11856 https://nvd.nist.gov/vuln/detail/CVE-2026-11856 https://curl.se/docs/CVE-2026-11856.html https://curl.se/docs/CVE-2026-11856.json https://hackerone.com/reports/3793260 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11856.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vlyMilfR3CdKSdc7LxNzEQ==": { "id": "vlyMilfR3CdKSdc7LxNzEQ==", "updater": "rhel-vex", "name": "CVE-2026-54369", "description": "A flaw was found in the `acl` package, specifically within its `libacl` pathname-based functions. A local attacker could exploit this vulnerability by using a symbolic link to replace a pathname component. This could allow the attacker to redirect access control list (ACL) read or write operations to arbitrary files or directories, leading to unauthorized manipulation of ACLs and ultimately local privilege escalation.", "issued": "2026-06-29T13:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-54369 https://bugzilla.redhat.com/show_bug.cgi?id=2490277 https://www.cve.org/CVERecord?id=CVE-2026-54369 https://nvd.nist.gov/vuln/detail/CVE-2026-54369 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json https://access.redhat.com/errata/RHSA-2026:42736", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "libacl", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|i686|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:2.4.0-1.el9_8", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vnI8VBZMnSK/Spr6qFIUOA==": { "id": "vnI8VBZMnSK/Spr6qFIUOA==", "updater": "rhel-vex", "name": "CVE-2026-4873", "description": "A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass the TLS requirement, leading to the transmission of sensitive information in cleartext. This vulnerability, categorized as Cleartext Transmission of Sensitive Information (CWE-319), results in information disclosure.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4873 https://bugzilla.redhat.com/show_bug.cgi?id=2461200 https://www.cve.org/CVERecord?id=CVE-2026-4873 https://nvd.nist.gov/vuln/detail/CVE-2026-4873 https://curl.se/docs/CVE-2026-4873.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4873.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "w4jLCE7e/XkliXylkG5u7w==": { "id": "w4jLCE7e/XkliXylkG5u7w==", "updater": "rhel-vex", "name": "CVE-2026-48935", "description": "A flaw was found in Node.js. The Permission API allows a local user to modify file metadata on paths that have been explicitly set as read-only. This can lead to unauthorized changes in file properties, impacting the integrity of the file system.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48935 https://bugzilla.redhat.com/show_bug.cgi?id=2493329 https://www.cve.org/CVERecord?id=CVE-2026-48935 https://nvd.nist.gov/vuln/detail/CVE-2026-48935 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48935.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs-libs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "w9lQNTxKVhHzOO3haJvINg==": { "id": "w9lQNTxKVhHzOO3haJvINg==", "updater": "rhel-vex", "name": "CVE-2026-48618", "description": "A flaw was found in Node.js. This flaw involves a mismatch in how Node.js handles TLS (Transport Layer Security) hostnames and unicode dot separators during authentication. This mismatch can lead to a wildcard-depth authentication bypass. An attacker could exploit this to bypass intended security boundaries, potentially leading to unauthorized access and confidentiality impact.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48618 https://bugzilla.redhat.com/show_bug.cgi?id=2493337 https://www.cve.org/CVERecord?id=CVE-2026-48618 https://nvd.nist.gov/vuln/detail/CVE-2026-48618 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", "normalized_severity": "High", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xC8Y7thfNSAfn5daCQFvgQ==": { "id": "xC8Y7thfNSAfn5daCQFvgQ==", "updater": "rhel-vex", "name": "CVE-2026-7168", "description": "A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user.", "issued": "2026-05-13T08:29:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-7168 https://bugzilla.redhat.com/show_bug.cgi?id=2476979 https://www.cve.org/CVERecord?id=CVE-2026-7168 https://nvd.nist.gov/vuln/detail/CVE-2026-7168 http://www.openwall.com/lists/oss-security/2026/04/29/14 https://curl.se/docs/CVE-2026-7168.html https://curl.se/docs/CVE-2026-7168.json https://hackerone.com/reports/3697719 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7168.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xWYQ4aF7Ip3LaKJQzDwx1A==": { "id": "xWYQ4aF7Ip3LaKJQzDwx1A==", "updater": "rhel-vex", "name": "CVE-2026-48935", "description": "A flaw was found in Node.js. The Permission API allows a local user to modify file metadata on paths that have been explicitly set as read-only. This can lead to unauthorized changes in file properties, impacting the integrity of the file system.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48935 https://bugzilla.redhat.com/show_bug.cgi?id=2493329 https://www.cve.org/CVERecord?id=CVE-2026-48935 https://nvd.nist.gov/vuln/detail/CVE-2026-48935 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48935.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xvCKE5h7HgdGkBMwA/kPeg==": { "id": "xvCKE5h7HgdGkBMwA/kPeg==", "updater": "rhel-vex", "name": "CVE-2026-42338", "description": "A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user's browser.", "issued": "2026-05-12T19:43:16Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42338 https://bugzilla.redhat.com/show_bug.cgi?id=2476810 https://www.cve.org/CVERecord?id=CVE-2026-42338 https://nvd.nist.gov/vuln/detail/CVE-2026-42338 https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "nodejs", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "aarch64|ppc64le|s390x|src|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "1:22.23.1-1.module+el9.8.0+24457+996af7aa", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xxrOMZzPk7ETmnvrIjBo0A==": { "id": "xxrOMZzPk7ETmnvrIjBo0A==", "updater": "rhel-vex", "name": "CVE-2025-60753", "description": "A vulnerability in apply_substitution() function in libarchive's bsdtar allows crafted -s substitution rules to repeatedly match a zero-length substring and append replacements without advancing the input pointer. When the rule uses the global /g flag (or an explicitly empty pattern), this leads to unbounded output allocation and eventual process OOM (Denial of Service). Upgrade to libarchive 3.8.1 or apply a patch that prevents zero-length match loops or rejects empty patterns.", "issued": "2025-11-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-60753 https://bugzilla.redhat.com/show_bug.cgi?id=2412648 https://www.cve.org/CVERecord?id=CVE-2025-60753 https://nvd.nist.gov/vuln/detail/CVE-2025-60753 https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753 https://github.com/libarchive/libarchive/issues/2725 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-60753.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "y6oEGtDp1H5C2csZKAF6bQ==": { "id": "y6oEGtDp1H5C2csZKAF6bQ==", "updater": "rhel-vex", "name": "CVE-2026-11979", "description": "A flaw was found in libxml2, specifically within the xmlcatalog utility when operating in shell mode. An attacker can exploit multiple stack-based buffer overflows by providing an excessively long input line. This leads to memory corruption, which may cause the application to crash or potentially allow the attacker to execute arbitrary code within the context of the xmlcatalog process.", "issued": "2026-06-29T13:21:42Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11979 https://bugzilla.redhat.com/show_bug.cgi?id=2494191 https://www.cve.org/CVERecord?id=CVE-2026-11979 https://nvd.nist.gov/vuln/detail/CVE-2026-11979 https://cert.pl/en/posts/2026/06/CVE-2026-11979 https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11979.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ybC5m+3Nw0ZONnhlgz4G1g==": { "id": "ybC5m+3Nw0ZONnhlgz4G1g==", "updater": "rhel-vex", "name": "CVE-2026-48934", "description": "A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.", "issued": "2026-06-26T01:14:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-48934 https://bugzilla.redhat.com/show_bug.cgi?id=2493332 https://www.cve.org/CVERecord?id=CVE-2026-48934 https://nvd.nist.gov/vuln/detail/CVE-2026-48934 https://nodejs.org/en/blog/vulnerability/june-2026-security-releases https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48934.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ymKqobod4xPivmLT/iq9oQ==": { "id": "ymKqobod4xPivmLT/iq9oQ==", "updater": "rhel-vex", "name": "CVE-2026-41990", "description": "A flaw was found in Libgcrypt. During Dilithium signing operations, the library fails to perform a bounds check when writing to a static array. While the data involved is not directly controlled by an attacker, this vulnerability could lead to memory corruption, potentially resulting in a denial of service (DoS) or affecting data integrity.", "issued": "2026-04-23T04:39:04Z", "links": "https://access.redhat.com/security/cve/CVE-2026-41990 https://bugzilla.redhat.com/show_bug.cgi?id=2461068 https://www.cve.org/CVERecord?id=CVE-2026-41990 https://nvd.nist.gov/vuln/detail/CVE-2026-41990 https://dev.gnupg.org/T8208 https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html https://www.openwall.com/lists/oss-security/2026/04/21/1 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41990.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yzZzF1vLZmeTiLJMgY7W0Q==": { "id": "yzZzF1vLZmeTiLJMgY7W0Q==", "updater": "rhel-vex", "name": "CVE-2025-7039", "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.", "issued": "2025-07-02T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-7039 https://bugzilla.redhat.com/show_bug.cgi?id=2392423 https://www.cve.org/CVERecord?id=CVE-2025-7039 https://nvd.nist.gov/vuln/detail/CVE-2025-7039 https://gitlab.gnome.org/GNOME/glib/-/issues/3716 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-7039.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zJ+YLx5SZJWkzNaTpINTcw==": { "id": "zJ+YLx5SZJWkzNaTpINTcw==", "updater": "rhel-vex", "name": "CVE-2026-9678", "description": "A flaw was found in Undici. The cache interceptor in shared-cache mode incorrectly classifies certain responses as cacheable due to improper handling of whitespace-padded Cache-Control header field names. This vulnerability allows an unauthenticated attacker to access authenticated user data from the cache, leading to information disclosure. This occurs when both authenticated and unauthenticated requests resolve to the same cache key.", "issued": "2026-06-17T17:04:09Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9678 https://bugzilla.redhat.com/show_bug.cgi?id=2490000 https://www.cve.org/CVERecord?id=CVE-2026-9678 https://nvd.nist.gov/vuln/detail/CVE-2026-9678 https://cna.openjsf.org/security-advisories.html https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9678.json https://access.redhat.com/errata/RHSA-2026:35892", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nodejs-nodemon", "version": "", "kind": "binary", "normalized_version": "", "module": "nodejs:22", "arch": "noarch|src", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:9:*:appstream:*:*:*:*:*" }, "fixed_in_version": "0:3.0.1-1.module+el9.8.0+24156+bb41d456", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zqGJegkbTlVqcHBa6HtRTQ==": { "id": "zqGJegkbTlVqcHBa6HtRTQ==", "updater": "rhel-vex", "name": "CVE-2025-14017", "description": "A flaw was found in curl. When performing multi-threaded LDAPS (Lightweight Directory Access Protocol Secure) transfers, changes to Transport Layer Security (TLS) options in one thread could inadvertently apply globally, affecting other concurrent transfers. This could lead to unintended security posture changes, such as disabling certificate verification for other threads. This vulnerability can result in a security bypass, where expected security checks are not performed.", "issued": "2026-01-08T10:07:05Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14017 https://bugzilla.redhat.com/show_bug.cgi?id=2427870 https://www.cve.org/CVERecord?id=CVE-2025-14017 https://nvd.nist.gov/vuln/detail/CVE-2025-14017 https://curl.se/docs/CVE-2025-14017.html https://curl.se/docs/CVE-2025-14017.json https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14017.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:9:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false } }, "package_vulnerabilities": { "+lY+UUpyo/55vgqUUOuejg==": [ "ayJ94QRlWYBn8mXMxBDr+Q==", "1r+syFhyATToDtkOkMLqDw==", "4XO5TL/zvh/gBT0sz3RSYw==", "i9sUrKKUObLH200e/JvjcA==", "Qvw0/zOlMy3n6XUCrN6SmQ==", "0u4nnKNMeZ58/8R+sWLPSQ==", "CfMK+8nnfjDlpiJ86nDqnQ==", "OB+gdUis8HhIN+YuJZ0d3w==", "VpM36keMJ87mG4yZ97wQdw==", "9v8e/1gKgcwShm3I7m4SiQ==", "Pi9su0FguY3j1GBpXhwKIA==", "d28O4EsS+H4v4JSsIykoOg==", "j9OVo/jK62GKOQBSgKgJGw==", "FeNPPUXNvPHMFZ28E13Mog==", "3zxG1J6bDKAhZ9wlUE9Y4g==", "bk6ikdg+f6vAFzgypr0cOw==" ], "/Jp1+jxuGVB8kf+IVvkLrQ==": [ "/DjJHQ4LUqD/kDDEZQnGMQ==", "E9ztZ/MyJW/b90Qruzzb/A==", "+81WHs4+NlxNNP8OWMLJ2g==", "3xFSeDOxGkdisnqW9w6B+Q==", "Ywdulqdw8k75jjL2qb8gPg==", "poe+ZOEeV2eDvTqSL2bcHA==", "dKzgwwkG/spsYd8PVvrk6A==", "rmKqD8ZR5vrHqnZkFulqdg==", "BrupyHHgUisGe91mdtTkog==" ], "/L1kFEoHZTukrNTCQLypFQ==": [ "aOUfuyvyyWEe7Z1IZT+fGw==" ], "/T3unXthUSp/zJaVYpuQfQ==": [ "sqtLRwfRzV6y9srK/2QK2Q==", "IFUwSX5dX69QHRHfvOeQDg==", "X7DmUVoCri5i6vdYVBBgXg==", "l6IrI73Pg+lrisEtcgX+0Q==", "mllkaOQAaJYNZpdIF7Bkbw==", "FQwXyPZ+oHyxQZ9RBQXbpw==", "Cpn7PI6CgTg1FJ1Ijp4TIQ==", "vMgggE6Cjv/N2Jk4Dk6FYw==", "6rEIsdyQtCC456AuGwgsDQ==", "+TrS27bZKgEeir9pISurnQ==", "3UNcgW64Eji4iyY2ZDB1cg==", "ctALzLE36TiW3KdxIlF4Mw==", "8MfvwX+dRI6Qt2H+x71rZg==", "d0nPfXoEZybRuV9TMDY3YQ==", "xC8Y7thfNSAfn5daCQFvgQ==", "X4Ym25zfqcH7/samBN+yPw==", "zqGJegkbTlVqcHBa6HtRTQ==", "/rrV/dLSeVDaHUnAvPeh7A==", "6+rn6nrQrafYloJtAeJ2Bg==", "smB1yCGhBb8gDhPAER7odg==", "S0PFhlHzk3DOoPuq+7jmPA==", "H1wshPoazj8pmzsnWAztZA==", "Pza9Y2xtH9MChVMkZwgw2A==", "vnI8VBZMnSK/Spr6qFIUOA==", "kDNo+1U3zj32TNGC/5DIKw==" ], "2daNj17YVWGx0KV9TCa6Ag==": [ "ChVC4WOnGJkEsPC5QHmS4Q==" ], "2gCbp4kt+cF44NF/LqukDg==": [ "S5Dzz9cigoJDCj8s5UcT0g==" ], "40CUjHKsWI2oXBGOxO5+Kg==": [ "1I5Zdk3zr6CO9kf+WEea4Q==", "76eg4nI+WwZq6jvunMGVEQ==", "YwrNcgB1VRavvqQXhCICXg==", "8hlo60BBnOd97TpyGOfaLA==", "qIUMlexpn07c5Ly85v5AjQ==", "kGY3woMWc1W36Wi2YstJ0Q==" ], "4iqV8aUHNk1o4YJaOnnBOg==": [ "e0/Fzu8wfMZp9zX32i9rMQ==", "7CfySs4FmTkWgJPjEar4eg==" ], "5JAFUJWmy04+T6x2oJw2jg==": [ "qFIYjZJeFnLAVC7lR0n6oQ==", "DTApvRZh1HJD5XbbpU3ahw==", "/Q70+j219nLwNP4Phg4sag==", "8kndQj/aRn+NNJdGVP9v4g==", "u0cs09LPRVEEfen4PHM6gA==", "jiVVTQmOtKqVixv7agF/Hg==", "y6oEGtDp1H5C2csZKAF6bQ==", "RHShqbO2hqcBNPYbKDg/3A==", "8ZCpE1M7eqNdy615aO2gLQ==", "br+ShorUFea/O+vyZNDWZQ==", "SGRK/IsCkjX097oRuDhiEQ==" ], "7mDaaxs3ev+uNEDYC97U3Q==": [ "1npmxgSnoYj2MyAhQMaE7g==" ], "933bwLexZewNfaJWrKZAJw==": [ "LiIvRwi7+1nAVErMH0hoaQ==", "T1g7X8ESyY5xnqSayytC4w==", "7KIsr/dNSaeE3wdgBYfrgQ==" ], "9wWP1WdTrVCykiUHcmStWw==": [ "922No9XwoInf4IDk2/SEuA==", "VJENPcmZwV+YJWnk88f2ug==", "0q4mJ3RDNOZ/qRqKXOz7Tg==" ], "AYWPcXxdUay0d/qxFjyxxA==": [ "lQBARBTddFvexevUD04GZA==", "Kqq2xlybjD/tOLmQWu2xPw==", "xxrOMZzPk7ETmnvrIjBo0A==", "/GP9UYzgnUNp/vOMMDf7mw==", "sykv+pGN4TXggZNIwL/H4g==", "Ez8lHT2uV9Tf9vJC/T4WXg==", "76mWuVYhbmIFsc4DNorK9A==", "uaetuJImncB6wudykQLpEA==", "o/v8DGswQXGkB45uD8rRUw==", "mJw+LvAbCoVMIOZXCXNFpg==", "VWEbeFnFOHy1IkG21b5a5g==", "O3XylFvGObsPmzTrCuhV8A==" ], "DU6/TA2uNulT+q7hBfw/2w==": [ "qIUMlexpn07c5Ly85v5AjQ==", "kGY3woMWc1W36Wi2YstJ0Q==", "8gSzZr+GPWdWrD28SEc1Pg==", "/pEYCNwBz8VXiXwXl+mS3w==", "eaoaQZQXOAlAomwMnyNLSQ==", "ZMqtUXBs3IUyb3eHhTEM+Q==" ], "E+86APTf07XmsaHw75dOYQ==": [ "XwLJYEytIMCdc6/A4MTJHg==" ], "EsA7Dv6B+IUQ6wmp9oBkLA==": [ "e0/Fzu8wfMZp9zX32i9rMQ==", "7CfySs4FmTkWgJPjEar4eg==" ], "HKlRsQZtXaa3HoNDv500tg==": [ "2w9brA/+oZ5OEdpav+Dkzw==", "+R/6bpHEFR4SpBeguCorTQ==" ], "I5cVace6fizyXVtumzW7pg==": [ "d3Z1riL6AkoWkk27zYoWCw==" ], "Lwqn0aweLQLZmo12VvYcog==": [ "Rk5ia3x816rxtSUtbpOMnw==", "rhaCfU7pM1FgApTAw4PpPA==" ], "MA8EMjMpjkzMuD4Zo1clCg==": [ "ajT6YifLzju5PlaUiX+EvA==" ], "NSiprMdkK5/5pxuNNJOh2A==": [ "+R/6bpHEFR4SpBeguCorTQ==", "2eh/JThmMghcGbhP7jHOJw==" ], "OCIjbR16ktOEiFK36r0WNw==": [ "AzUHhCngmr5YuLLD/fQQEA==" ], "P5Om9zCJ/QZ+hnrEvj6fGw==": [ "ymKqobod4xPivmLT/iq9oQ==", "lzB4zyDZ+L/0TgHu+34IeA==" ], "PIk2BBAWexCFofMi5q03RA==": [ "S5Dzz9cigoJDCj8s5UcT0g==" ], "PvRYqRcexo7w5I906InQwA==": [ "cXB5uJOI3UJ7dOyNiQwFDg==", "XPUXyp+BOEJyEGOgXafi8Q==" ], "QBTcpn4pqa+eJ8D8UVEiVg==": [ "sqtLRwfRzV6y9srK/2QK2Q==", "IFUwSX5dX69QHRHfvOeQDg==", "X7DmUVoCri5i6vdYVBBgXg==", "l6IrI73Pg+lrisEtcgX+0Q==", "mllkaOQAaJYNZpdIF7Bkbw==", "FQwXyPZ+oHyxQZ9RBQXbpw==", "Cpn7PI6CgTg1FJ1Ijp4TIQ==", "vMgggE6Cjv/N2Jk4Dk6FYw==", "6rEIsdyQtCC456AuGwgsDQ==", "+TrS27bZKgEeir9pISurnQ==", "3UNcgW64Eji4iyY2ZDB1cg==", "ctALzLE36TiW3KdxIlF4Mw==", "8MfvwX+dRI6Qt2H+x71rZg==", "d0nPfXoEZybRuV9TMDY3YQ==", "xC8Y7thfNSAfn5daCQFvgQ==", "X4Ym25zfqcH7/samBN+yPw==", "zqGJegkbTlVqcHBa6HtRTQ==", "/rrV/dLSeVDaHUnAvPeh7A==", "6+rn6nrQrafYloJtAeJ2Bg==", "smB1yCGhBb8gDhPAER7odg==", "S0PFhlHzk3DOoPuq+7jmPA==", "H1wshPoazj8pmzsnWAztZA==", "Pza9Y2xtH9MChVMkZwgw2A==", "vnI8VBZMnSK/Spr6qFIUOA==", "kDNo+1U3zj32TNGC/5DIKw==" ], "RcZCiT+ycHJQmpV3/FuYsw==": [ "qkPjlqaV2EZ52NAHd/IgfQ==", "+p1B+LZP5hvhPeU88puOfg==", "HVxGZgwvlrVpgAxKx4gRlA==", "TSYnGqVe9WLIg9cR9McW7A==", "RI2wKrfD1EyE3/UfHBEmcA==", "c76DQiDMr2npmMChLqBaow==", "MEeKHFVdv0EwpaMPKCy3Sw==", "egAiHhCEkMFVMFqpyh1hdw==", "Bl8VfXimE6raefu05cOS8w==", "iFdXYPdbzmitrrthD7u8yA==", "T76LK9MUa3lwsxSAw540ZA==", "4aJ6IaFsuGhRpz+mkfUGqQ==", "rT7Zl5hqfT/SFXkQlgRUqg==", "Nh6DgKTo1EEcTUg+VgZK9Q==", "F8lGQFeTGfg63gSPRvjBBA==", "pOKoOa+tppgNwBAEgYrxlg==" ], "S8p9UGak1oycptcpYp/1eg==": [ "d/522T+B/ARMNSG+3QfAWA==" ], "SUb+Lyjw6FDmZnaJmfkg2w==": [ "5VGw1oph7DgrzGqxDXSJIA==" ], "T1283MiUUtcDMYRJTXeZzA==": [ "dDPwWBP+ziJTbpE/idIe+w==", "AGwkok3hPLMsQFqdif59+w==", "/s8Q0HsneAZhk9Mgclm/OA==", "HwrQV7Eq97lmWod0H+Mywg==", "L1NHjBKVcGa4hqzsfSCCQg==", "/9MMSCBwxCiKjJobh+tDpw==", "NF/ewEROjeKYjnb1lHH2iw==", "2fFhV4f06vNDz4aMbkPOZA==", "D4G1BWjcvupPxJokCdnHGA==", "qh5gUahI9nge5StfpD2Efg==", "GoTAJ6nke0a3zoxJ8lkaAg==", "XPfYdQhyLnN89+qpSA6LWg==", "ffV5WUu4x4B5YykIdxqFhA==", "Ep1W9j+OJARAHSERuL7J7Q==", "mINycH+x60PTfgPLuT1gJw==", "IDIT7Gfu8E9A+NfUxEcAbQ==", "2TDjlt2gAEWsLyBBPigFYw==", "5BksN0izCeDRrtFMsNCyvg==", "6hAQW3vY9ZA/8datv1rY4g==", "0E1VjQWdmolR9lr9ElIZZQ==", "M293c+QguJ/aaYP3cMwfyQ==", "mZCCwO//htsOIXazj/SeOw==", "41OUTxSbBLQGne4TzJuTQg==" ], "U+4qCFcZOyPHsmmdD44CrQ==": [ "TwbA7fBttKRHAyCkVC4IDQ==", "EUdYVqG8WVFrguzTJcoB9w==", "mNXETDKAQUXFDVp1hgY7fQ==", "07xwapz2PAAGV6vMF10zQw==", "qIUMlexpn07c5Ly85v5AjQ==", "kGY3woMWc1W36Wi2YstJ0Q==" ], "VS7DY+9FnbHX9Fem83CwXQ==": [ "C2yGNOteTOSf1Z3ep0DvHQ==", "45NlEwqpAAjjjCgRktdWjA==", "hUPR/bV/A80tipW3ZXwmTg==", "kvWVhRPjc0HYeWvbQJGJEg==", "ZLsYJB10R11Jj/NYuhNkpA==", "pU8Z0LfIMQCZLgwp2Yn90g==", "EL8NcQMQeTnwBw9iCSC+yA==", "+8vzuOrwVwjhz/n9cpNEEQ==", "qFnCm62d/bnijdlwZoRQeQ==", "Z4+dN9Ywyw4meaJMaZos5w==", "zJ+YLx5SZJWkzNaTpINTcw==", "ZZZOb80ipC9wC85x9cRVjA==", "EQB0ZSi1/BHyuX6FPsfCrA==", "ybC5m+3Nw0ZONnhlgz4G1g==", "/7Wi/I65INeazWgOf1LTAg==", "w9lQNTxKVhHzOO3haJvINg==" ], "W7uBqJb8l9AhSXjNg1JZQg==": [ "tbhLz74i3ShwS72WbIsoOA==" ], "XG5+bW8np2NedSy/od6z8Q==": [ "vlyMilfR3CdKSdc7LxNzEQ==" ], "Xa5h200SIiVSiheE2PRVIg==": [ "p0umWDpPMiOz8HPGPopybw==", "aJsQ4a3gp8/jsNBVC56QHw==", "jyKmIhGp11jpJBCY83RPQA==", "0hc+Z9xWtVy4dEgLyf7GUQ==", "QmXO38HGjUD9lc3XwducGg==", "T7eVCD5Gwe0DXPZP59mQUQ==", "TL19l7Dr/wLwmp6malQ4FQ==", "Qi/s8gqjz2kgI+pAtQ5t9w==", "MciappbjqbiRE2dg7PbMSg==", "tUTc+tWHx1wVpIbeqTmR0w==", "O912x64ev1faikrIaaOp6w==", "J1e16b0P6Tp2x5sVgsqutQ==", "71C1Nt6KoL1+Dpr0rTxWwA==", "MDVosfib/bnNAm4m647vLA==", "w4jLCE7e/XkliXylkG5u7w==", "+Kc8jbRzLLDVqPaeFngWtQ==" ], "XaWKjZmgTSvC2q3B/R5UNg==": [ "HxI42iSjURjRki+uV6q/9w==", "vH+nziLZjIpD4JaIkhx3FA==", "bugTfOdgCaATW4vTnuXTSQ==" ], "bvKQIfHp90JS+LiY5WtU+w==": [ "kR9Bs/gd2Qm09J0HnMmVzg==", "lFfYg6015iTLGI5pZVMU7w==", "WjQCog+GPmCa3VQIGXKhRg==", "U6rJ6LmaVlYRjI8Lq/aM/A==", "fPh6cJ7fj6ecJeD/S/iyJg==", "dz5oxhJicudEulHfFUUHJw==", "svCt47J2Zwa45xj8gn3U/w==", "NrTzMmbWyM5UeSvnQVNLOg==", "5JPRWlHhzvwdgcYt2OnpZg==", "+DR5Qfe30tw0byM4w3zykQ==", "ixc06f0H9vqMfsbwQSwwvA==", "VYGbkY0i6P3tRJd9mM1wNg==", "yzZzF1vLZmeTiLJMgY7W0Q==", "UwZunDPz4Z/GxKWN3p1+/Q==", "klH60uFrR0WkawaSlcOEKg==", "YSP3jWIJP4TspvpKDx/wvA==" ], "dC9CoYt17eaqinGSVCfCxw==": [ "kGC5RaOJSDDnqCSoiLqrIA==" ], "eF21TL12/odJlvaq9Hsuzg==": [ "rqKN8+22i5Wi/U+pG39tNg==" ], "enagVWadN12gI5iPYugyvg==": [ "AUiFITCnRjRxctzqqbDeeA==", "iF/o4aDbQf1DAw7R+LiVQw==", "9iigvnuYDaC8UzcOIDLjIQ==", "2F6XtsAYpNWm5w+Rwl/tuQ==", "GAn7gWUe2pFr7PbwechqxA==" ], "ewbqmzgK8Rzf739yT7IKUQ==": [ "tbhLz74i3ShwS72WbIsoOA==" ], "icCOAW3YxkHDgnEa2cteSA==": [ "N5EbMRV7FNySo/Sn3CmU+w==", "oGYbR6FNz1KIQ8VJiypCZg==", "txqyo4HZxt82KZ1LFkOAcA==", "cQ4uQyL9nbrYK9Ka1PjEaQ==", "xvCKE5h7HgdGkBMwA/kPeg==", "SIuaHC7QSLhT9Coo7Xm2hA==", "J/M93jueASHywmph2g+HMg==", "9DXLRStQLAgyQnNJqYTJEA==", "4kuxrTpUDtZ3uFOEEztq9g==", "NfiEOtFyxMslIq3QwoTtjQ==", "EOZFP6ki76xUja7Br+mpEw==", "cQHSxL+ZfKCYmJnTVIzcRw==", "OXJFeTFLsi8lSYgzBz58BA==", "NrATYvL+2i2gY4ol+szT+g==", "xWYQ4aF7Ip3LaKJQzDwx1A==", "Y1YZsYV7ls1vsluhREpXlw==" ], "jEnEXZsP79wPnGLwBratuQ==": [ "2TDjlt2gAEWsLyBBPigFYw==", "5BksN0izCeDRrtFMsNCyvg==", "6hAQW3vY9ZA/8datv1rY4g==", "0E1VjQWdmolR9lr9ElIZZQ==", "M293c+QguJ/aaYP3cMwfyQ==", "mZCCwO//htsOIXazj/SeOw==", "41OUTxSbBLQGne4TzJuTQg==", "Y3fno6fRSl46BTZQlReNKg==", "BXYBFOm74zXwzmdOdyNhzA==", "VHPIyM/Zt8Ma4iUgT7UsMw==", "DW2DUdu8ljrldYoM7Mprtg==", "Teb2ue8GsbLkJUoUyGyGsA==", "+20onLS/dWLg9saGZqMvvA==", "5mdxwKcXZHEqEguvWMJQ3w==", "DsZp+BRVz/OTV0jFXHylmA==", "2Apbu80O6R41VOd2ICqODw==", "TvusqX9NwPqfJWjNoF5ThA==", "JYnbFl5uln18531ZOk6t8g==", "mgY0OXX1J12mJy1iNllE3A==", "40wPd5q9E1sRluf3JeA8hw==", "hbenTywo0l7anle5/bJQBw==", "TFhgbPsd17URo8rNJh9SWQ==", "EmYlXCkWzU0dM5AZphsDzw==" ], "r13jqXkPJ02PeUmrpJHnSA==": [ "cXB5uJOI3UJ7dOyNiQwFDg==", "XPUXyp+BOEJyEGOgXafi8Q==" ], "rY/kE/V4JnxYoqV+lmc9mg==": [ "X8OJykaOJlN5EhVA7Y11uQ==", "DDxCHnX+kCqcRQj9b90/cg==", "R5XnexvMFgBiw/v8sY0BOA==", "iwe2PkNe91EUwDENn+pmew==" ], "s4D0cbFr4JfjY5l1vCuuXQ==": [ "e0/Fzu8wfMZp9zX32i9rMQ==", "7CfySs4FmTkWgJPjEar4eg==" ], "wJ6UaBi74Z5N+nH3gNGPKQ==": [ "QskDoDnTSvrQeDXklM4YOw==" ], "wtWstARWoVJ6Jhp1LsdM3w==": [ "e0/Fzu8wfMZp9zX32i9rMQ==", "7CfySs4FmTkWgJPjEar4eg==" ] }, "enrichments": { "message/vnd.clair.map.vulnerability; enricher=clair.cvss schema=https://csrc.nist.gov/schema/nvd/api/2.0/cve_api_json_2.0.schema": [ { "+81WHs4+NlxNNP8OWMLJ2g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "+Kc8jbRzLLDVqPaeFngWtQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "+TrS27bZKgEeir9pISurnQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "+p1B+LZP5hvhPeU88puOfg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "/Q70+j219nLwNP4Phg4sag==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "0E1VjQWdmolR9lr9ElIZZQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0hc+Z9xWtVy4dEgLyf7GUQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0u4nnKNMeZ58/8R+sWLPSQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "1npmxgSnoYj2MyAhQMaE7g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1r+syFhyATToDtkOkMLqDw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "2fFhV4f06vNDz4aMbkPOZA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "3xFSeDOxGkdisnqW9w6B+Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "45NlEwqpAAjjjCgRktdWjA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "4aJ6IaFsuGhRpz+mkfUGqQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "5JPRWlHhzvwdgcYt2OnpZg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "76mWuVYhbmIFsc4DNorK9A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.0, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7CfySs4FmTkWgJPjEar4eg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8kndQj/aRn+NNJdGVP9v4g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9iigvnuYDaC8UzcOIDLjIQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9v8e/1gKgcwShm3I7m4SiQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "AUiFITCnRjRxctzqqbDeeA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "BrupyHHgUisGe91mdtTkog==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "CfMK+8nnfjDlpiJ86nDqnQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "DDxCHnX+kCqcRQj9b90/cg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "DsZp+BRVz/OTV0jFXHylmA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EL8NcQMQeTnwBw9iCSC+yA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GAn7gWUe2pFr7PbwechqxA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "H1wshPoazj8pmzsnWAztZA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "HxI42iSjURjRki+uV6q/9w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "J/M93jueASHywmph2g+HMg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "J1e16b0P6Tp2x5sVgsqutQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "Kqq2xlybjD/tOLmQWu2xPw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H", "baseScore": 6.6, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "M293c+QguJ/aaYP3cMwfyQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MEeKHFVdv0EwpaMPKCy3Sw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "NfiEOtFyxMslIq3QwoTtjQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Pza9Y2xtH9MChVMkZwgw2A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "QmXO38HGjUD9lc3XwducGg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "Qvw0/zOlMy3n6XUCrN6SmQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "R5XnexvMFgBiw/v8sY0BOA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "RHShqbO2hqcBNPYbKDg/3A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "RI2wKrfD1EyE3/UfHBEmcA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "S5Dzz9cigoJDCj8s5UcT0g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "SGRK/IsCkjX097oRuDhiEQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "baseScore": 2.5, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "SIuaHC7QSLhT9Coo7Xm2hA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "T7eVCD5Gwe0DXPZP59mQUQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "TL19l7Dr/wLwmp6malQ4FQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "TSYnGqVe9WLIg9cR9McW7A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "U6rJ6LmaVlYRjI8Lq/aM/A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VJENPcmZwV+YJWnk88f2ug==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VWEbeFnFOHy1IkG21b5a5g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "WjQCog+GPmCa3VQIGXKhRg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "X4Ym25zfqcH7/samBN+yPw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "X8OJykaOJlN5EhVA7Y11uQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XPUXyp+BOEJyEGOgXafi8Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Y1YZsYV7ls1vsluhREpXlw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "YSP3jWIJP4TspvpKDx/wvA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Ywdulqdw8k75jjL2qb8gPg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "Z4+dN9Ywyw4meaJMaZos5w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ZLsYJB10R11Jj/NYuhNkpA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "ZZZOb80ipC9wC85x9cRVjA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "aJsQ4a3gp8/jsNBVC56QHw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "aOUfuyvyyWEe7Z1IZT+fGw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "bk6ikdg+f6vAFzgypr0cOw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "c76DQiDMr2npmMChLqBaow==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "cQ4uQyL9nbrYK9Ka1PjEaQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "cQHSxL+ZfKCYmJnTVIzcRw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "cXB5uJOI3UJ7dOyNiQwFDg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "d28O4EsS+H4v4JSsIykoOg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "fPh6cJ7fj6ecJeD/S/iyJg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "i9sUrKKUObLH200e/JvjcA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "iF/o4aDbQf1DAw7R+LiVQw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "iFdXYPdbzmitrrthD7u8yA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "iwe2PkNe91EUwDENn+pmew==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "ixc06f0H9vqMfsbwQSwwvA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jiVVTQmOtKqVixv7agF/Hg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kR9Bs/gd2Qm09J0HnMmVzg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", "baseScore": 8.6, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "kvWVhRPjc0HYeWvbQJGJEg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "lFfYg6015iTLGI5pZVMU7w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mJw+LvAbCoVMIOZXCXNFpg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H", "baseScore": 5.6, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mZCCwO//htsOIXazj/SeOw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "mllkaOQAaJYNZpdIF7Bkbw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "LOW" } ], "oGYbR6FNz1KIQ8VJiypCZg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "pOKoOa+tppgNwBAEgYrxlg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "pU8Z0LfIMQCZLgwp2Yn90g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "tUTc+tWHx1wVpIbeqTmR0w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "tbhLz74i3ShwS72WbIsoOA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uaetuJImncB6wudykQLpEA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "w9lQNTxKVhHzOO3haJvINg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "xC8Y7thfNSAfn5daCQFvgQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "xvCKE5h7HgdGkBMwA/kPeg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "y6oEGtDp1H5C2csZKAF6bQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ] } ] }, "PackageNotVulnerable": {} }