Running clair-action on amd64 image manifest... 2026/08/13 05:30:46 INFO matchers created matcher.aws-matcher=https://pkg.go.dev/github.com/quay/claircore/aws matcher.suse=https://pkg.go.dev/github.com/quay/claircore/suse matcher.java-maven=https://pkg.go.dev/github.com/quay/claircore/java matcher.photon=https://pkg.go.dev/github.com/quay/claircore/photon matcher.python=https://pkg.go.dev/github.com/quay/claircore/python matcher.rhel=https://pkg.go.dev/github.com/quay/claircore/rhel matcher.gobin=https://pkg.go.dev/github.com/quay/claircore/gobin matcher.oracle=https://pkg.go.dev/github.com/quay/claircore/oracle matcher.alpine-matcher=https://pkg.go.dev/github.com/quay/claircore/alpine matcher.debian-matcher=https://pkg.go.dev/github.com/quay/claircore/debian matcher.rhel-container-matcher=https://pkg.go.dev/github.com/quay/claircore/rhel/rhcc matcher.ruby-gem=https://pkg.go.dev/github.com/quay/claircore/ruby matcher.ubuntu-matcher=https://pkg.go.dev/github.com/quay/claircore/ubuntu 2026/08/13 05:30:46 INFO vex factory configured base_url=https://security.access.redhat.com/data/csaf/v2/vex/ compressed_file_timeout=2m0s 2026/08/13 05:30:46 INFO libvuln initialized 2026/08/13 05:30:46 INFO registered configured scanners 2026/08/13 05:30:46 INFO constructing 2026/08/13 05:30:46 INFO index request start 2026/08/13 05:30:46 INFO starting scan 2026/08/13 05:30:46 INFO manifest to be scanned 2026/08/13 05:30:46 INFO layers fetch start 2026/08/13 05:30:49 INFO layers fetch success 2026/08/13 05:30:49 INFO layers fetch done 2026/08/13 05:30:49 INFO layers scan start 2026/08/13 05:30:49 WARN rpm source packages always record 0 epoch; this may cause incorrect matching see-also="https://github.com/rpm-software-management/rpm/issues/2796 https://github.com/rpm-software-management/rpm/discussions/3703 https://github.com/rpm-software-management/rpm/pull/3755" 2026/08/13 05:30:49 INFO found buildinfo Dockerfile path=root/buildinfo/Dockerfile-ubi8-openjdk-17-runtime-1.23-5 2026/08/13 05:30:50 INFO layers scan done 2026/08/13 05:30:50 INFO starting index manifest 2026/08/13 05:30:50 INFO finishing scan 2026/08/13 05:30:50 INFO manifest successfully scanned 2026/08/13 05:30:50 INFO index request done { "manifest_hash": "sha256:d3ab7bb68ad26ab64acaea01921dfc1f80f95a207bbc3226eccdcaec9eb283f7", "packages": { "+XM+s3niWaEk1U5jnR5DpA==": { "id": "+XM+s3niWaEk1U5jnR5DpA==", "name": "libyaml", "version": "0.1.7-5.el8", "kind": "binary", "source": { "id": "", "name": "libyaml", "version": "0.1.7-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "+Xr7HyTxXf0c8jLaUyo3xA==": { "id": "+Xr7HyTxXf0c8jLaUyo3xA==", "name": "libidn2", "version": "2.2.0-1.el8", "kind": "binary", "source": { "id": "", "name": "libidn2", "version": "2.2.0-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "+hvIC0Et/RtHi7EAFCmfEw==": { "id": "+hvIC0Et/RtHi7EAFCmfEw==", "name": "file-libs", "version": "5.33-27.el8_10", "kind": "binary", "source": { "id": "", "name": "file", "version": "5.33-27.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "+qrxjVH7Im8eBfrz4h4P/w==": { "id": "+qrxjVH7Im8eBfrz4h4P/w==", "name": "shadow-utils", "version": "2:4.6-23.el8_10", "kind": "binary", "source": { "id": "", "name": "shadow-utils", "version": "4.6-23.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "1gormAsAjMuks2JveQRd0Q==": { "id": "1gormAsAjMuks2JveQRd0Q==", "name": "gobject-introspection", "version": "1.56.1-1.el8", "kind": "binary", "source": { "id": "", "name": "gobject-introspection", "version": "1.56.1-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "2gKctomQ2vBMxlyAOjcc7g==": { "id": "2gKctomQ2vBMxlyAOjcc7g==", "name": "sed", "version": "4.5-5.el8_10", "kind": "binary", "source": { "id": "", "name": "sed", "version": "4.5-5.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "3+d+oaGDGj9g2+1RFZjY5A==": { "id": "3+d+oaGDGj9g2+1RFZjY5A==", "name": "gmp", "version": "1:6.1.2-11.el8", "kind": "binary", "source": { "id": "", "name": "gmp", "version": "6.1.2-11.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "3jI2apoRMNGhHa141Q5dlQ==": { "id": "3jI2apoRMNGhHa141Q5dlQ==", "name": "libksba", "version": "1.3.5-9.el8_7", "kind": "binary", "source": { "id": "", "name": "libksba", "version": "1.3.5-9.el8_7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "3uSX4NgBxQvC8LEk48QoOQ==": { "id": "3uSX4NgBxQvC8LEk48QoOQ==", "name": "cyrus-sasl-lib", "version": "2.1.27-6.el8_5", "kind": "binary", "source": { "id": "", "name": "cyrus-sasl", "version": "2.1.27-6.el8_5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "4+CwJaQ8b1eMPAoQX4kL+A==": { "id": "4+CwJaQ8b1eMPAoQX4kL+A==", "name": "ubi8/openjdk-17-runtime", "version": "1.23-5", "kind": "binary", "source": { "id": "p7tNYPUXLVhWy6vBQfT6hA==", "name": "openjdk-17-runtime-ubi8-container", "version": "1.23-5", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1.23.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1.23.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "45rvgYmy022Tx6fVWfking==": { "id": "45rvgYmy022Tx6fVWfking==", "name": "publicsuffix-list-dafsa", "version": "20180723-1.el8", "kind": "binary", "source": { "id": "", "name": "publicsuffix-list", "version": "20180723-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "4sG4bBloak5Sz907ZDRs6Q==": { "id": "4sG4bBloak5Sz907ZDRs6Q==", "name": "libnsl2", "version": "1.2.0-2.20180605git4a062cf.el8", "kind": "binary", "source": { "id": "", "name": "libnsl2", "version": "1.2.0-2.20180605git4a062cf.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "5Md0+J4/AY7tfKpid0Vbew==": { "id": "5Md0+J4/AY7tfKpid0Vbew==", "name": "javapackages-filesystem", "version": "5.3.0-1.module+el8+2447+6f56d9a6", "kind": "binary", "source": { "id": "", "name": "javapackages-tools", "version": "5.3.0-1.module+el8+2447+6f56d9a6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "module": "javapackages-runtime:201801", "arch": "noarch", "cpe": "", "detector": null }, "5U8sNbKx0xZsaHcVt4MmxA==": { "id": "5U8sNbKx0xZsaHcVt4MmxA==", "name": "chkconfig", "version": "1.19.2-1.el8", "kind": "binary", "source": { "id": "", "name": "chkconfig", "version": "1.19.2-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "6TosRb2Tsu+lux2SVlDfZw==": { "id": "6TosRb2Tsu+lux2SVlDfZw==", "name": "python3-libs", "version": "3.6.8-77.el8_10", "kind": "binary", "source": { "id": "", "name": "python3", "version": "3.6.8-77.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "7/rWOzofNr4yV+C5oOgcRQ==": { "id": "7/rWOzofNr4yV+C5oOgcRQ==", "name": "tzdata-java", "version": "2026b-1.el8", "kind": "binary", "source": { "id": "", "name": "tzdata", "version": "2026b-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "7ImMeyXZ75qIGtloaQtHNw==": { "id": "7ImMeyXZ75qIGtloaQtHNw==", "name": "libxml2", "version": "2.9.7-21.el8_10.6", "kind": "binary", "source": { "id": "", "name": "libxml2", "version": "2.9.7-21.el8_10.6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "7WjsyjO4dyAYyLB4UAj3bQ==": { "id": "7WjsyjO4dyAYyLB4UAj3bQ==", "name": "openssl-libs", "version": "1:1.1.1k-17.el8_6", "kind": "binary", "source": { "id": "", "name": "openssl", "version": "1.1.1k-17.el8_6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "9uhqFNTCJ7/bpzSlc7qCaQ==": { "id": "9uhqFNTCJ7/bpzSlc7qCaQ==", "name": "libgcrypt", "version": "1.8.5-7.el8_6", "kind": "binary", "source": { "id": "", "name": "libgcrypt", "version": "1.8.5-7.el8_6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "ACY3djwkey7ZIXbd0V+Giw==": { "id": "ACY3djwkey7ZIXbd0V+Giw==", "name": "nss-sysinit", "version": "3.112.0-8.el8_10", "kind": "binary", "source": { "id": "", "name": "nss", "version": "3.112.0-8.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "AiPN0MTxzb2TnXiQF7zMVg==": { "id": "AiPN0MTxzb2TnXiQF7zMVg==", "name": "ubi8/openjdk-17-runtime", "version": "1786598906", "kind": "ancestry", "source": { "id": "zq37oCfqwm2d5LV97XrO8Q==", "name": "ubi8/openjdk-17-runtime", "version": "1786598906", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "rhctag:1786598906.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "rhctag:1786598906.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "AuC6XQzcU/5tB4luIfjLFg==": { "id": "AuC6XQzcU/5tB4luIfjLFg==", "name": "elfutils-libelf", "version": "0.190-2.el8", "kind": "binary", "source": { "id": "", "name": "elfutils", "version": "0.190-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "AzR13YeWt5QuEhdGyJ1bsQ==": { "id": "AzR13YeWt5QuEhdGyJ1bsQ==", "name": "glibc", "version": "2.28-251.el8_10.40", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.28-251.el8_10.40", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "AziZ1oGI+oDXVPzldKNj+w==": { "id": "AziZ1oGI+oDXVPzldKNj+w==", "name": "openldap", "version": "2.4.46-21.el8_10", "kind": "binary", "source": { "id": "", "name": "openldap", "version": "2.4.46-21.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "BC2SLYOMYLcx8DhgPt8T+w==": { "id": "BC2SLYOMYLcx8DhgPt8T+w==", "name": "dbus-libs", "version": "1:1.12.8-28.el8_10", "kind": "binary", "source": { "id": "", "name": "dbus", "version": "1.12.8-28.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "BbZqfCvuyJyaO67Dr03HHg==": { "id": "BbZqfCvuyJyaO67Dr03HHg==", "name": "glib2", "version": "2.56.4-170.el8_10", "kind": "binary", "source": { "id": "", "name": "glib2", "version": "2.56.4-170.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "BmK1zIjr5KsuOODCYwxRCw==": { "id": "BmK1zIjr5KsuOODCYwxRCw==", "name": "libpsl", "version": "0.20.2-6.el8", "kind": "binary", "source": { "id": "", "name": "libpsl", "version": "0.20.2-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "CP6fmHsRon29d9dGmAC8yQ==": { "id": "CP6fmHsRon29d9dGmAC8yQ==", "name": "nss-softokn", "version": "3.112.0-8.el8_10", "kind": "binary", "source": { "id": "", "name": "nss", "version": "3.112.0-8.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "CUMXU+cfm9pjhlqh7KtdUQ==": { "id": "CUMXU+cfm9pjhlqh7KtdUQ==", "name": "systemd-libs", "version": "239-82.el8_10.17", "kind": "binary", "source": { "id": "", "name": "systemd", "version": "239-82.el8_10.17", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "CbqHQON08ZsUvPS9XDaTFA==": { "id": "CbqHQON08ZsUvPS9XDaTFA==", "name": "rpm", "version": "4.14.3-32.el8_10", "kind": "binary", "source": { "id": "", "name": "rpm", "version": "4.14.3-32.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Cklbj7Y2kf3vqxqc0m1GHQ==": { "id": "Cklbj7Y2kf3vqxqc0m1GHQ==", "name": "librhsm", "version": "0.0.3-5.el8", "kind": "binary", "source": { "id": "", "name": "librhsm", "version": "0.0.3-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "D/ASdBsgxLNlG5Q8U7UPsQ==": { "id": "D/ASdBsgxLNlG5Q8U7UPsQ==", "name": "rootfiles", "version": "8.1-22.el8", "kind": "binary", "source": { "id": "", "name": "rootfiles", "version": "8.1-22.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "D9iJYSwBt2n6JCuuNo2fKg==": { "id": "D9iJYSwBt2n6JCuuNo2fKg==", "name": "audit-libs", "version": "3.1.2-1.el8_10.1", "kind": "binary", "source": { "id": "", "name": "audit", "version": "3.1.2-1.el8_10.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "DMo4b1Un6YxynFkb5aEmow==": { "id": "DMo4b1Un6YxynFkb5aEmow==", "name": "io.github.stuartwdouglas.hacbs-test.simple:simple-jdk8", "version": "1.2.4", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "cpe": "", "detector": null }, "DV119Dw0W4RdsbJkdoHU9w==": { "id": "DV119Dw0W4RdsbJkdoHU9w==", "name": "curl", "version": "7.61.1-34.el8_10.11", "kind": "binary", "source": { "id": "", "name": "curl", "version": "7.61.1-34.el8_10.11", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "DgyhtZBcSIlVmY6xC8s1mA==": { "id": "DgyhtZBcSIlVmY6xC8s1mA==", "name": "coreutils-single", "version": "8.30-17.el8_10", "kind": "binary", "source": { "id": "", "name": "coreutils", "version": "8.30-17.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Dmgfuk4/ZGW2Pjrf3pzOwg==": { "id": "Dmgfuk4/ZGW2Pjrf3pzOwg==", "name": "nss-util", "version": "3.112.0-8.el8_10", "kind": "binary", "source": { "id": "", "name": "nss", "version": "3.112.0-8.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "DrRsA7ihemgW3wIHNdisag==": { "id": "DrRsA7ihemgW3wIHNdisag==", "name": "tzdata", "version": "2026b-1.el8", "kind": "binary", "source": { "id": "", "name": "tzdata", "version": "2026b-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "EiNiLT8ulizCzEWcybhizQ==": { "id": "EiNiLT8ulizCzEWcybhizQ==", "name": "lz4-libs", "version": "1.8.3-5.el8_10", "kind": "binary", "source": { "id": "", "name": "lz4", "version": "1.8.3-5.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "EoUwdHBtRhmxCfWNwlaMOg==": { "id": "EoUwdHBtRhmxCfWNwlaMOg==", "name": "ubi8/ubi-minimal", "version": "1784730910", "kind": "binary", "source": { "id": "Fvsb4f5LSINVZCKXD4/zpA==", "name": "ubi8/ubi-minimal", "version": "1784730910", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1784730910.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1784730910.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "F7AOP7tK5AfUXV1g9iTzFA==": { "id": "F7AOP7tK5AfUXV1g9iTzFA==", "name": "mpfr", "version": "3.1.6-1.el8", "kind": "binary", "source": { "id": "", "name": "mpfr", "version": "3.1.6-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "FS5/DAbDsXWURU9onlACPA==": { "id": "FS5/DAbDsXWURU9onlACPA==", "name": "alsa-lib", "version": "1.2.10-2.el8", "kind": "binary", "source": { "id": "", "name": "alsa-lib", "version": "1.2.10-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Fvsb4f5LSINVZCKXD4/zpA==": { "id": "Fvsb4f5LSINVZCKXD4/zpA==", "name": "ubi8/ubi-minimal", "version": "1784730910", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1784730910.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "GLKhGblbPbPbtDKwfpCv5A==": { "id": "GLKhGblbPbPbtDKwfpCv5A==", "name": "filesystem", "version": "3.8-6.el8", "kind": "binary", "source": { "id": "", "name": "filesystem", "version": "3.8-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Gg1Q6hponuT1eSJHwaJ83w==": { "id": "Gg1Q6hponuT1eSJHwaJ83w==", "name": "libcap-ng", "version": "0.7.11-1.el8", "kind": "binary", "source": { "id": "", "name": "libcap-ng", "version": "0.7.11-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "HMIoZ/TKrKhxI1rD26qmpw==": { "id": "HMIoZ/TKrKhxI1rD26qmpw==", "name": "json-c", "version": "0.13.1-3.el8", "kind": "binary", "source": { "id": "", "name": "json-c", "version": "0.13.1-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "HkK1gu6fZUcneyvc1Nl+Ig==": { "id": "HkK1gu6fZUcneyvc1Nl+Ig==", "name": "io.github.stuartwdouglas.hacbs-test.shaded:shaded-jdk11", "version": "1.9", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "cpe": "", "detector": null }, "IzLcxZDtcvtJR5Gwdq9HDg==": { "id": "IzLcxZDtcvtJR5Gwdq9HDg==", "name": "libattr", "version": "2.4.48-3.el8", "kind": "binary", "source": { "id": "", "name": "attr", "version": "2.4.48-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "J34PJ2GThOWZuKVgFIoieA==": { "id": "J34PJ2GThOWZuKVgFIoieA==", "name": "zlib", "version": "1.2.11-25.el8", "kind": "binary", "source": { "id": "", "name": "zlib", "version": "1.2.11-25.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "JNDNKhJbFTSevs7EALfE9A==": { "id": "JNDNKhJbFTSevs7EALfE9A==", "name": "p11-kit", "version": "0.23.22-2.el8", "kind": "binary", "source": { "id": "", "name": "p11-kit", "version": "0.23.22-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "K6Euqji9wJy/jvFfJGKBDw==": { "id": "K6Euqji9wJy/jvFfJGKBDw==", "name": "libacl", "version": "2.4.0-1.el8_10", "kind": "binary", "source": { "id": "", "name": "acl", "version": "2.4.0-1.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "KYSXsdsObSOPb3/iOOdbDw==": { "id": "KYSXsdsObSOPb3/iOOdbDw==", "name": "nss-softokn-freebl", "version": "3.112.0-8.el8_10", "kind": "binary", "source": { "id": "", "name": "nss", "version": "3.112.0-8.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "LXiVkIlXLq/usMYIwCTH8Q==": { "id": "LXiVkIlXLq/usMYIwCTH8Q==", "name": "libsmartcols", "version": "2.32.1-48.el8_10", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.32.1-48.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "LbxcyGOx/WnGZlMK7you6A==": { "id": "LbxcyGOx/WnGZlMK7you6A==", "name": "io.github.stuartwdouglas.hacbs-test.simple:simple-jdk17", "version": "0.1.2", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "cpe": "", "detector": null }, "N1RbIRo2SyHosQefv+skDw==": { "id": "N1RbIRo2SyHosQefv+skDw==", "name": "gawk", "version": "4.2.1-4.el8", "kind": "binary", "source": { "id": "", "name": "gawk", "version": "4.2.1-4.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "N3ZaMrNJKoumMpaY0smlMQ==": { "id": "N3ZaMrNJKoumMpaY0smlMQ==", "name": "sqlite-libs", "version": "3.26.0-20.el8_10", "kind": "binary", "source": { "id": "", "name": "sqlite", "version": "3.26.0-20.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "N5EuVcX6TPHBo7OPtax5uA==": { "id": "N5EuVcX6TPHBo7OPtax5uA==", "name": "crypto-policies-scripts", "version": "20230731-1.git3177e06.el8", "kind": "binary", "source": { "id": "", "name": "crypto-policies", "version": "20230731-1.git3177e06.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "NJbhst8VIOwst++ZzRP6tA==": { "id": "NJbhst8VIOwst++ZzRP6tA==", "name": "libpeas", "version": "1.22.0-6.el8", "kind": "binary", "source": { "id": "", "name": "libpeas", "version": "1.22.0-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "NguWV8S6YQYvQsGQDJm2Rg==": { "id": "NguWV8S6YQYvQsGQDJm2Rg==", "name": "ncurses-base", "version": "6.1-10.20180224.el8", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.1-10.20180224.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "NsvPyDc//39XTuXcn3j2uQ==": { "id": "NsvPyDc//39XTuXcn3j2uQ==", "name": "gdbm", "version": "1:1.18-2.el8", "kind": "binary", "source": { "id": "", "name": "gdbm", "version": "1.18-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "ORsDK2A5479NPB0r01PoXQ==": { "id": "ORsDK2A5479NPB0r01PoXQ==", "name": "libcurl", "version": "7.61.1-34.el8_10.11", "kind": "binary", "source": { "id": "", "name": "curl", "version": "7.61.1-34.el8_10.11", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "P5Se4zJpr8ZUwZNUojfuzA==": { "id": "P5Se4zJpr8ZUwZNUojfuzA==", "name": "libxcrypt", "version": "4.1.1-6.el8", "kind": "binary", "source": { "id": "", "name": "libxcrypt", "version": "4.1.1-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "P5UTXxqhA6R98OWY7h85rQ==": { "id": "P5UTXxqhA6R98OWY7h85rQ==", "name": "libarchive", "version": "3.3.3-7.el8_10", "kind": "binary", "source": { "id": "", "name": "libarchive", "version": "3.3.3-7.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "PYGQE1Mr52aqIP4tEB4VSw==": { "id": "PYGQE1Mr52aqIP4tEB4VSw==", "name": "nss", "version": "3.112.0-8.el8_10", "kind": "binary", "source": { "id": "", "name": "nss", "version": "3.112.0-8.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "PcSVlceQ6PCKCKw9Y7o89w==": { "id": "PcSVlceQ6PCKCKw9Y7o89w==", "name": "expat", "version": "2.5.0-2.el8_10", "kind": "binary", "source": { "id": "", "name": "expat", "version": "2.5.0-2.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Q0uPb/t/3IQ8GEwlv/J3Cw==": { "id": "Q0uPb/t/3IQ8GEwlv/J3Cw==", "name": "libmount", "version": "2.32.1-48.el8_10", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.32.1-48.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "QC6e3OaV78mjs678tGU2KQ==": { "id": "QC6e3OaV78mjs678tGU2KQ==", "name": "libssh", "version": "0.9.6-16.el8_10", "kind": "binary", "source": { "id": "", "name": "libssh", "version": "0.9.6-16.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "QXEDMSZisv5SUXtJo7Fs5g==": { "id": "QXEDMSZisv5SUXtJo7Fs5g==", "name": "gpgme", "version": "1.13.1-12.el8", "kind": "binary", "source": { "id": "", "name": "gpgme", "version": "1.13.1-12.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "RRWuvyUdhwGbBo2a/Ra1hw==": { "id": "RRWuvyUdhwGbBo2a/Ra1hw==", "name": "libselinux", "version": "2.9-11.el8_10", "kind": "binary", "source": { "id": "", "name": "libselinux", "version": "2.9-11.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "RtlxSleee0sHxodv8Zav/g==": { "id": "RtlxSleee0sHxodv8Zav/g==", "name": "cups-libs", "version": "1:2.2.6-68.el8_10", "kind": "binary", "source": { "id": "", "name": "cups", "version": "2.2.6-68.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "RtrzwDgrQgu9S5B72s2sww==": { "id": "RtrzwDgrQgu9S5B72s2sww==", "name": "libunistring", "version": "0.9.9-3.el8", "kind": "binary", "source": { "id": "", "name": "libunistring", "version": "0.9.9-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "TARQvmsLVC/S1fQD1jO4Xw==": { "id": "TARQvmsLVC/S1fQD1jO4Xw==", "name": "gdbm-libs", "version": "1:1.18-2.el8", "kind": "binary", "source": { "id": "", "name": "gdbm", "version": "1.18-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "TpA/hV9k8pWHhLODuSJ+Zg==": { "id": "TpA/hV9k8pWHhLODuSJ+Zg==", "name": "glibc-minimal-langpack", "version": "2.28-251.el8_10.40", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.28-251.el8_10.40", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "USWNn71p+k059dbiu5HDEA==": { "id": "USWNn71p+k059dbiu5HDEA==", "name": "libassuan", "version": "2.5.1-3.el8", "kind": "binary", "source": { "id": "", "name": "libassuan", "version": "2.5.1-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "UUZyda9G/ffvF6rJ5W1UnQ==": { "id": "UUZyda9G/ffvF6rJ5W1UnQ==", "name": "libstdc++", "version": "8.5.0-28.el8_10", "kind": "binary", "source": { "id": "", "name": "gcc", "version": "8.5.0-28.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Uy0rTKzcfvmCCFLkfEu6Rw==": { "id": "Uy0rTKzcfvmCCFLkfEu6Rw==", "name": "ubi8/ubi-minimal", "version": "1784730910", "kind": "ancestry", "source": { "id": "Fvsb4f5LSINVZCKXD4/zpA==", "name": "ubi8/ubi-minimal", "version": "1784730910", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1784730910.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1784730910.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "VT/lJKaSpr1RIIPMBOKV+A==": { "id": "VT/lJKaSpr1RIIPMBOKV+A==", "name": "gnutls", "version": "3.6.16-8.el8_10.6", "kind": "binary", "source": { "id": "", "name": "gnutls", "version": "3.6.16-8.el8_10.6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "VrCmPwuY69qW5jl9ctxOZg==": { "id": "VrCmPwuY69qW5jl9ctxOZg==", "name": "libtirpc", "version": "1.1.4-12.el8_10", "kind": "binary", "source": { "id": "", "name": "libtirpc", "version": "1.1.4-12.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "W66WOQ3v6r7mSn6+o7gaew==": { "id": "W66WOQ3v6r7mSn6+o7gaew==", "name": "popt", "version": "1.18-1.el8", "kind": "binary", "source": { "id": "", "name": "popt", "version": "1.18-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "YdkMQeor/R4f5UlWcv1fVA==": { "id": "YdkMQeor/R4f5UlWcv1fVA==", "name": "org.example:simple-java-project", "version": "1.0-SNAPSHOT", "kind": "binary", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "cpe": "", "detector": null }, "YjDcGmvP0/z8VqRiUvkhOQ==": { "id": "YjDcGmvP0/z8VqRiUvkhOQ==", "name": "gnupg2", "version": "2.2.20-4.el8_10", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.20-4.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "ZALhBg0G9taJfH1fvOjqNg==": { "id": "ZALhBg0G9taJfH1fvOjqNg==", "name": "libtasn1", "version": "4.13-6.el8_10", "kind": "binary", "source": { "id": "", "name": "libtasn1", "version": "4.13-6.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "Za0y7YiKRidyIBZNIzq/Ng==": { "id": "Za0y7YiKRidyIBZNIzq/Ng==", "name": "librepo", "version": "1.14.2-5.el8", "kind": "binary", "source": { "id": "", "name": "librepo", "version": "1.14.2-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "ar0do80Wlk1FaVvtx66g6Q==": { "id": "ar0do80Wlk1FaVvtx66g6Q==", "name": "brotli", "version": "1.0.6-4.el8_10", "kind": "binary", "source": { "id": "", "name": "brotli", "version": "1.0.6-4.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "auI8KtI6OozP7EAIr9UlQQ==": { "id": "auI8KtI6OozP7EAIr9UlQQ==", "name": "pcre2", "version": "10.32-3.el8_6", "kind": "binary", "source": { "id": "", "name": "pcre2", "version": "10.32-3.el8_6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "bWUdPEYmtshwdmuX5VapfQ==": { "id": "bWUdPEYmtshwdmuX5VapfQ==", "name": "libblkid", "version": "2.32.1-48.el8_10", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.32.1-48.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "bmxL3lydQy0yU8g1iBgovg==": { "id": "bmxL3lydQy0yU8g1iBgovg==", "name": "libsepol", "version": "2.9-3.el8", "kind": "binary", "source": { "id": "", "name": "libsepol", "version": "2.9-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "cXCMP7NdkMDf1+Rb1IEktQ==": { "id": "cXCMP7NdkMDf1+Rb1IEktQ==", "name": "libsemanage", "version": "2.9-12.el8_10", "kind": "binary", "source": { "id": "", "name": "libsemanage", "version": "2.9-12.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "dOBT1Qffq44NOVuk9chDyg==": { "id": "dOBT1Qffq44NOVuk9chDyg==", "name": "readline", "version": "7.0-10.el8", "kind": "binary", "source": { "id": "", "name": "readline", "version": "7.0-10.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "dOwQwVL1NxmF6ouACZklrQ==": { "id": "dOwQwVL1NxmF6ouACZklrQ==", "name": "p11-kit-trust", "version": "0.23.22-2.el8", "kind": "binary", "source": { "id": "", "name": "p11-kit", "version": "0.23.22-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "dSjxsaDISLUiFwRTCSO8Tg==": { "id": "dSjxsaDISLUiFwRTCSO8Tg==", "name": "crypto-policies", "version": "20230731-1.git3177e06.el8", "kind": "binary", "source": { "id": "", "name": "crypto-policies", "version": "20230731-1.git3177e06.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "dtGaxafuhIU1Ppty914fJw==": { "id": "dtGaxafuhIU1Ppty914fJw==", "name": "nspr", "version": "4.36.0-2.el8_10", "kind": "binary", "source": { "id": "", "name": "nspr", "version": "4.36.0-2.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "eQIyD5D8mIGfekk4SP2BeQ==": { "id": "eQIyD5D8mIGfekk4SP2BeQ==", "name": "libusbx", "version": "1.0.30-1.el8_10", "kind": "binary", "source": { "id": "", "name": "libusbx", "version": "1.0.30-1.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "eZ7CwFvwDCQu4vzKyuIZgA==": { "id": "eZ7CwFvwDCQu4vzKyuIZgA==", "name": "basesystem", "version": "11-5.el8", "kind": "binary", "source": { "id": "", "name": "basesystem", "version": "11-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "f/Al/eNlUhjEgKSV0J2z7w==": { "id": "f/Al/eNlUhjEgKSV0J2z7w==", "name": "python3-pip-wheel", "version": "9.0.3-24.el8", "kind": "binary", "source": { "id": "", "name": "python-pip", "version": "9.0.3-24.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "f1lteJj1IxLDbDb+BI8yjg==": { "id": "f1lteJj1IxLDbDb+BI8yjg==", "name": "ca-certificates", "version": "2025.2.80_v9.0.304-80.2.el8_10", "kind": "binary", "source": { "id": "", "name": "ca-certificates", "version": "2025.2.80_v9.0.304-80.2.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "g146nKetkX1f4hfH1b5RWA==": { "id": "g146nKetkX1f4hfH1b5RWA==", "name": "libdb", "version": "5.3.28-42.el8_4", "kind": "binary", "source": { "id": "", "name": "libdb", "version": "5.3.28-42.el8_4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "gMqsUnRclTj6iuxHCslNRA==": { "id": "gMqsUnRclTj6iuxHCslNRA==", "name": "libdnf", "version": "0.63.0-21.el8_10", "kind": "binary", "source": { "id": "", "name": "libdnf", "version": "0.63.0-21.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "gOaN4treTmKK7tU+N6AZ1w==": { "id": "gOaN4treTmKK7tU+N6AZ1w==", "name": "pcre", "version": "8.42-6.el8", "kind": "binary", "source": { "id": "", "name": "pcre", "version": "8.42-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "gtbMsmX05ZWh+bkM1Wprlw==": { "id": "gtbMsmX05ZWh+bkM1Wprlw==", "name": "bash", "version": "4.4.20-6.el8_10", "kind": "binary", "source": { "id": "", "name": "bash", "version": "4.4.20-6.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "h53SWWmMQUh4cLyBmYeNvw==": { "id": "h53SWWmMQUh4cLyBmYeNvw==", "name": "avahi-libs", "version": "0.7-27.el8_10.1", "kind": "binary", "source": { "id": "", "name": "avahi", "version": "0.7-27.el8_10.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "hSTTMcRX1DBcXc+8jKeg3Q==": { "id": "hSTTMcRX1DBcXc+8jKeg3Q==", "name": "libgcc", "version": "8.5.0-28.el8_10", "kind": "binary", "source": { "id": "", "name": "gcc", "version": "8.5.0-28.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "hcJqCsCpWm+XI9JT6ImS5g==": { "id": "hcJqCsCpWm+XI9JT6ImS5g==", "name": "nettle", "version": "3.4.1-7.el8", "kind": "binary", "source": { "id": "", "name": "nettle", "version": "3.4.1-7.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "isKqi8Xwt9MjwRVhU+6KzQ==": { "id": "isKqi8Xwt9MjwRVhU+6KzQ==", "name": "glibc-common", "version": "2.28-251.el8_10.40", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.28-251.el8_10.40", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "isPl2YxnCTfcLmUYH6Q0sA==": { "id": "isPl2YxnCTfcLmUYH6Q0sA==", "name": "libuuid", "version": "2.32.1-48.el8_10", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.32.1-48.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "jJ8GFze+u3yX6EECKEDlVA==": { "id": "jJ8GFze+u3yX6EECKEDlVA==", "name": "platform-python", "version": "3.6.8-77.el8_10", "kind": "binary", "source": { "id": "", "name": "python3", "version": "3.6.8-77.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "jmNxyfDM4IV/F4mrfNTfyg==": { "id": "jmNxyfDM4IV/F4mrfNTfyg==", "name": "setup", "version": "2.12.2-9.el8", "kind": "binary", "source": { "id": "", "name": "setup", "version": "2.12.2-9.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "jtdCxL/eH5JTPcKstKunJg==": { "id": "jtdCxL/eH5JTPcKstKunJg==", "name": "grep", "version": "3.1-6.el8", "kind": "binary", "source": { "id": "", "name": "grep", "version": "3.1-6.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "k4gCNgIfg7MM/e42ThRx2w==": { "id": "k4gCNgIfg7MM/e42ThRx2w==", "name": "libzstd", "version": "1.4.4-1.el8", "kind": "binary", "source": { "id": "", "name": "zstd", "version": "1.4.4-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "kwc9NYOQig+qWs5qmBRL/w==": { "id": "kwc9NYOQig+qWs5qmBRL/w==", "name": "ncurses-libs", "version": "6.1-10.20180224.el8", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.1-10.20180224.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "lEFbOzBTlWwCqC/ZbjJfgQ==": { "id": "lEFbOzBTlWwCqC/ZbjJfgQ==", "name": "python3-setuptools-wheel", "version": "39.2.0-9.el8_10", "kind": "binary", "source": { "id": "", "name": "python-setuptools", "version": "39.2.0-9.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "lU0MYRg2dg5wynl2dMGsgA==": { "id": "lU0MYRg2dg5wynl2dMGsgA==", "name": "xz-libs", "version": "5.2.4-4.el8_6", "kind": "binary", "source": { "id": "", "name": "xz", "version": "5.2.4-4.el8_6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "mAmp7BtGrfzV0HnAKw9sTw==": { "id": "mAmp7BtGrfzV0HnAKw9sTw==", "name": "libsigsegv", "version": "2.11-5.el8", "kind": "binary", "source": { "id": "", "name": "libsigsegv", "version": "2.11-5.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "mLwCNKs2wEtLWAiibtR4BQ==": { "id": "mLwCNKs2wEtLWAiibtR4BQ==", "name": "microdnf", "version": "3.8.0-2.el8", "kind": "binary", "source": { "id": "", "name": "microdnf", "version": "3.8.0-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "mkpeQMTn6iNiF+ShBe+oZg==": { "id": "mkpeQMTn6iNiF+ShBe+oZg==", "name": "libverto", "version": "0.3.2-2.el8", "kind": "binary", "source": { "id": "", "name": "libverto", "version": "0.3.2-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "mlTBgPgv44eBdmn7f2Thag==": { "id": "mlTBgPgv44eBdmn7f2Thag==", "name": "krb5-libs", "version": "1.18.2-34.el8_10", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.18.2-34.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "mtrWxjnWyzrIFOuHVeUG6g==": { "id": "mtrWxjnWyzrIFOuHVeUG6g==", "name": "tar", "version": "2:1.30-11.el8_10", "kind": "binary", "source": { "id": "", "name": "tar", "version": "1.30-11.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "nDtLoMnkuhspYDn7NZEcjw==": { "id": "nDtLoMnkuhspYDn7NZEcjw==", "name": "findutils", "version": "1:4.6.0-24.el8_10", "kind": "binary", "source": { "id": "", "name": "findutils", "version": "4.6.0-24.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "o4v1nyEgxKUJdf78CSzLEg==": { "id": "o4v1nyEgxKUJdf78CSzLEg==", "name": "libgpg-error", "version": "1.31-1.el8", "kind": "binary", "source": { "id": "", "name": "libgpg-error", "version": "1.31-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "oPxhGBL0xk+N4XwwxvflAQ==": { "id": "oPxhGBL0xk+N4XwwxvflAQ==", "name": "redhat-release", "version": "8.10-0.3.el8", "kind": "binary", "source": { "id": "", "name": "redhat-release", "version": "8.10-0.3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "p7tNYPUXLVhWy6vBQfT6hA==": { "id": "p7tNYPUXLVhWy6vBQfT6hA==", "name": "openjdk-17-runtime-ubi8-container", "version": "1.23-5", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1.23.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "p9tXHgTBVU/b3sTnwfubzg==": { "id": "p9tXHgTBVU/b3sTnwfubzg==", "name": "libdb-utils", "version": "5.3.28-42.el8_4", "kind": "binary", "source": { "id": "", "name": "libdb", "version": "5.3.28-42.el8_4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "pY2NT/GP1UxyOuAl2rKgCw==": { "id": "pY2NT/GP1UxyOuAl2rKgCw==", "name": "npth", "version": "1.5-4.el8", "kind": "binary", "source": { "id": "", "name": "npth", "version": "1.5-4.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "peUaHHW4E9Y6Nd8+gJR5cQ==": { "id": "peUaHHW4E9Y6Nd8+gJR5cQ==", "name": "libssh-config", "version": "0.9.6-16.el8_10", "kind": "binary", "source": { "id": "", "name": "libssh", "version": "0.9.6-16.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "r23nOnTJvuvXzj0P21ldlw==": { "id": "r23nOnTJvuvXzj0P21ldlw==", "name": "rpm-libs", "version": "4.14.3-32.el8_10", "kind": "binary", "source": { "id": "", "name": "rpm", "version": "4.14.3-32.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "rFsA2fU/SFo3JGOkxRURTQ==": { "id": "rFsA2fU/SFo3JGOkxRURTQ==", "name": "keyutils-libs", "version": "1.5.10-9.el8", "kind": "binary", "source": { "id": "", "name": "keyutils", "version": "1.5.10-9.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "s5qs8lj0/L/p9c08upXwSg==": { "id": "s5qs8lj0/L/p9c08upXwSg==", "name": "libsolv", "version": "0.7.20-7.el8_10", "kind": "binary", "source": { "id": "", "name": "libsolv", "version": "0.7.20-7.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "sMrsZHOrW8FfprPHZo6Jww==": { "id": "sMrsZHOrW8FfprPHZo6Jww==", "name": "libmodulemd", "version": "2.13.0-1.el8", "kind": "binary", "source": { "id": "", "name": "libmodulemd", "version": "2.13.0-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "sUhkiUesE2DHTU1IF7t+tw==": { "id": "sUhkiUesE2DHTU1IF7t+tw==", "name": "platform-python-setuptools", "version": "39.2.0-9.el8_10", "kind": "binary", "source": { "id": "", "name": "python-setuptools", "version": "39.2.0-9.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "teyVOt1iJyAfEH0z7JVBTQ==": { "id": "teyVOt1iJyAfEH0z7JVBTQ==", "name": "ubi8/openjdk-17-runtime", "version": "1786598906", "kind": "binary", "source": { "id": "zq37oCfqwm2d5LV97XrO8Q==", "name": "ubi8/openjdk-17-runtime", "version": "1786598906", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "rhctag:1786598906.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "rhctag:1786598906.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "trIX86+UkjuJsaeYfHvnYw==": { "id": "trIX86+UkjuJsaeYfHvnYw==", "name": "libnghttp2", "version": "1.33.0-6.el8_10.2", "kind": "binary", "source": { "id": "", "name": "nghttp2", "version": "1.33.0-6.el8_10.2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "u25cfo+Wn6RpzVY/kgcoGQ==": { "id": "u25cfo+Wn6RpzVY/kgcoGQ==", "name": "lksctp-tools", "version": "1.0.18-3.el8", "kind": "binary", "source": { "id": "", "name": "lksctp-tools", "version": "1.0.18-3.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "uCw7c1p0VzVV36rFL2/j4Q==": { "id": "uCw7c1p0VzVV36rFL2/j4Q==", "name": "bzip2-libs", "version": "1.0.6-28.el8_10", "kind": "binary", "source": { "id": "", "name": "bzip2", "version": "1.0.6-28.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "v/KoDsdxOHqLHd7du8yyWQ==": { "id": "v/KoDsdxOHqLHd7du8yyWQ==", "name": "lua-libs", "version": "5.3.4-12.el8", "kind": "binary", "source": { "id": "", "name": "lua", "version": "5.3.4-12.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "wJ4dAQ6SE4hHS42wVhzrWg==": { "id": "wJ4dAQ6SE4hHS42wVhzrWg==", "name": "java-17-openjdk-headless", "version": "1:17.0.20.0.8-1.1.el8", "kind": "binary", "source": { "id": "", "name": "java-17-openjdk", "version": "17.0.20.0.8-1.1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "wQToP4WURQ4/A8LQU1k5kA==": { "id": "wQToP4WURQ4/A8LQU1k5kA==", "name": "langpacks-en", "version": "1.0-12.el8", "kind": "binary", "source": { "id": "", "name": "langpacks", "version": "1.0-12.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "wpJmhjYJz5TYuh0mbRPs4Q==": { "id": "wpJmhjYJz5TYuh0mbRPs4Q==", "name": "info", "version": "6.5-7.el8", "kind": "binary", "source": { "id": "", "name": "texinfo", "version": "6.5-7.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "xDLbw0lNdZ2pSj9R8k9t6A==": { "id": "xDLbw0lNdZ2pSj9R8k9t6A==", "name": "copy-jdk-configs", "version": "4.0-2.el8", "kind": "binary", "source": { "id": "", "name": "copy-jdk-configs", "version": "4.0-2.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "noarch", "cpe": "", "detector": null }, "xTF9l16G3x26txeCsO9Bug==": { "id": "xTF9l16G3x26txeCsO9Bug==", "name": "json-glib", "version": "1.4.4-1.el8", "kind": "binary", "source": { "id": "", "name": "json-glib", "version": "1.4.4-1.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "xY/gcEds28iVWCynxOCw9g==": { "id": "xY/gcEds28iVWCynxOCw9g==", "name": "libcom_err", "version": "1.45.6-7.el8_10", "kind": "binary", "source": { "id": "", "name": "e2fsprogs", "version": "1.45.6-7.el8_10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "xvIYCTeML23osZxD1kFItQ==": { "id": "xvIYCTeML23osZxD1kFItQ==", "name": "lua", "version": "5.3.4-12.el8", "kind": "binary", "source": { "id": "", "name": "lua", "version": "5.3.4-12.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "ypZwlmuME3Db6H+D0SaJbg==": { "id": "ypZwlmuME3Db6H+D0SaJbg==", "name": "ubi8/openjdk-17-runtime", "version": "1.23-5", "kind": "ancestry", "source": { "id": "p7tNYPUXLVhWy6vBQfT6hA==", "name": "openjdk-17-runtime-ubi8-container", "version": "1.23-5", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1.23.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "normalized_version": "unmatchable:1.23.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null }, "zAReYdYoHUkp8wr8i3SW2g==": { "id": "zAReYdYoHUkp8wr8i3SW2g==", "name": "libffi", "version": "3.1-24.el8", "kind": "binary", "source": { "id": "", "name": "libffi", "version": "3.1-24.el8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "zdqdBY2jg/Zs374g8Ylc6g==": { "id": "zdqdBY2jg/Zs374g8Ylc6g==", "name": "libcap", "version": "2.48-6.el8_10.1", "kind": "binary", "source": { "id": "", "name": "libcap", "version": "2.48-6.el8_10.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "x86_64", "cpe": "", "detector": null }, "zq37oCfqwm2d5LV97XrO8Q==": { "id": "zq37oCfqwm2d5LV97XrO8Q==", "name": "ubi8/openjdk-17-runtime", "version": "1786598906", "kind": "source", "source": { "id": "", "name": "", "version": "", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "rhctag:1786598906.0.0.0.0.0.0.0.0.0", "arch": "x86_64", "cpe": "", "detector": null } }, "distributions": { "9da6b00b-ee35-4122-be55-6c0f99a0806a": { "id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "did": "rhel", "name": "Red Hat Enterprise Linux Server", "version": "8", "version_code_name": "", "version_id": "8", "arch": "", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "pretty_name": "Red Hat Enterprise Linux Server 8" } }, "repository": { "09aa29d7-325e-4b81-a4f8-e8e47d6a37ec": { "id": "09aa29d7-325e-4b81-a4f8-e8e47d6a37ec", "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-8-for-x86_64-appstream-rpms", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "0c66dc9d-ff42-4fe3-bd08-266e790525d7": { "id": "0c66dc9d-ff42-4fe3-bd08-266e790525d7", "name": "maven", "uri": "https://repo1.maven.apache.org/maven2", "cpe": "" }, "2b384fa1-0900-4f4a-becd-83e01a868e11": { "id": "2b384fa1-0900-4f4a-becd-83e01a868e11", "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-8-for-x86_64-baseos-rpms", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d": { "id": "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d", "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-8-for-x86_64-baseos-rpms", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "50c55364-502c-438e-8b26-3c235ff2c57f": { "id": "50c55364-502c-438e-8b26-3c235ff2c57f", "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhcc-container-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "5b349d99-51fd-490d-be61-6476cfeafcc3": { "id": "5b349d99-51fd-490d-be61-6476cfeafcc3", "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhel-cpe-repository", "uri": "repoid=rhel-8-for-x86_64-appstream-rpms", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "71a51f20-1a3a-43d8-b4e7-9bbedea1ae7b": { "id": "71a51f20-1a3a-43d8-b4e7-9bbedea1ae7b", "name": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*", "key": "rhcc-container-repository", "cpe": "cpe:2.3:a:redhat:enterprise_linux:8:*:appstream:*:*:*:*:*" }, "eed176a2-41f7-4a42-8121-28d1294b721c": { "id": "eed176a2-41f7-4a42-8121-28d1294b721c", "name": "Red Hat Container Catalog", "key": "rhcc-container-repository", "uri": "https://catalog.redhat.com/software/containers/explore", "cpe": "" } }, "environments": { "+XM+s3niWaEk1U5jnR5DpA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "+Xr7HyTxXf0c8jLaUyo3xA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "+hvIC0Et/RtHi7EAFCmfEw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "+qrxjVH7Im8eBfrz4h4P/w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "1gormAsAjMuks2JveQRd0Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "2gKctomQ2vBMxlyAOjcc7g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "3+d+oaGDGj9g2+1RFZjY5A==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "3jI2apoRMNGhHa141Q5dlQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "3uSX4NgBxQvC8LEk48QoOQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "4+CwJaQ8b1eMPAoQX4kL+A==": [ { "package_db": "root/buildinfo/Dockerfile-ubi8-openjdk-17-runtime-1.23-5", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": [ "eed176a2-41f7-4a42-8121-28d1294b721c", "eed176a2-41f7-4a42-8121-28d1294b721c" ] } ], "45rvgYmy022Tx6fVWfking==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "4sG4bBloak5Sz907ZDRs6Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "5Md0+J4/AY7tfKpid0Vbew==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "5U8sNbKx0xZsaHcVt4MmxA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "6TosRb2Tsu+lux2SVlDfZw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "7/rWOzofNr4yV+C5oOgcRQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "7ImMeyXZ75qIGtloaQtHNw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "7WjsyjO4dyAYyLB4UAj3bQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "9uhqFNTCJ7/bpzSlc7qCaQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "ACY3djwkey7ZIXbd0V+Giw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "AiPN0MTxzb2TnXiQF7zMVg==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:5a6cb5489cbf1e89c9aca33a2494173af4ef456782e7e6caa8517b19f4d88669", "distribution_id": "", "repository_ids": [ "50c55364-502c-438e-8b26-3c235ff2c57f" ] } ], "AuC6XQzcU/5tB4luIfjLFg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "AzR13YeWt5QuEhdGyJ1bsQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "AziZ1oGI+oDXVPzldKNj+w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "BC2SLYOMYLcx8DhgPt8T+w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "BbZqfCvuyJyaO67Dr03HHg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "BmK1zIjr5KsuOODCYwxRCw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "CP6fmHsRon29d9dGmAC8yQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "CUMXU+cfm9pjhlqh7KtdUQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "CbqHQON08ZsUvPS9XDaTFA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "Cklbj7Y2kf3vqxqc0m1GHQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "D/ASdBsgxLNlG5Q8U7UPsQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "D9iJYSwBt2n6JCuuNo2fKg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "DMo4b1Un6YxynFkb5aEmow==": [ { "package_db": "maven:deployments/hacbs-test.jar", "introduced_in": "sha256:5a6cb5489cbf1e89c9aca33a2494173af4ef456782e7e6caa8517b19f4d88669", "distribution_id": "", "repository_ids": [ "0c66dc9d-ff42-4fe3-bd08-266e790525d7" ] } ], "DV119Dw0W4RdsbJkdoHU9w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "DgyhtZBcSIlVmY6xC8s1mA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "Dmgfuk4/ZGW2Pjrf3pzOwg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "DrRsA7ihemgW3wIHNdisag==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "EiNiLT8ulizCzEWcybhizQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "EoUwdHBtRhmxCfWNwlaMOg==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": [ "71a51f20-1a3a-43d8-b4e7-9bbedea1ae7b" ] } ], "F7AOP7tK5AfUXV1g9iTzFA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "FS5/DAbDsXWURU9onlACPA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "Fvsb4f5LSINVZCKXD4/zpA==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": [ "71a51f20-1a3a-43d8-b4e7-9bbedea1ae7b" ] } ], "GLKhGblbPbPbtDKwfpCv5A==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "Gg1Q6hponuT1eSJHwaJ83w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "HMIoZ/TKrKhxI1rD26qmpw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "HkK1gu6fZUcneyvc1Nl+Ig==": [ { "package_db": "maven:deployments/hacbs-test.jar", "introduced_in": "sha256:5a6cb5489cbf1e89c9aca33a2494173af4ef456782e7e6caa8517b19f4d88669", "distribution_id": "", "repository_ids": [ "0c66dc9d-ff42-4fe3-bd08-266e790525d7" ] } ], "IzLcxZDtcvtJR5Gwdq9HDg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "J34PJ2GThOWZuKVgFIoieA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "JNDNKhJbFTSevs7EALfE9A==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "K6Euqji9wJy/jvFfJGKBDw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "KYSXsdsObSOPb3/iOOdbDw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "LXiVkIlXLq/usMYIwCTH8Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "LbxcyGOx/WnGZlMK7you6A==": [ { "package_db": "maven:deployments/hacbs-test.jar", "introduced_in": "sha256:5a6cb5489cbf1e89c9aca33a2494173af4ef456782e7e6caa8517b19f4d88669", "distribution_id": "", "repository_ids": [ "0c66dc9d-ff42-4fe3-bd08-266e790525d7" ] } ], "N1RbIRo2SyHosQefv+skDw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "N3ZaMrNJKoumMpaY0smlMQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "N5EuVcX6TPHBo7OPtax5uA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "NJbhst8VIOwst++ZzRP6tA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "NguWV8S6YQYvQsGQDJm2Rg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "NsvPyDc//39XTuXcn3j2uQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "ORsDK2A5479NPB0r01PoXQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "P5Se4zJpr8ZUwZNUojfuzA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "P5UTXxqhA6R98OWY7h85rQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "PYGQE1Mr52aqIP4tEB4VSw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "PcSVlceQ6PCKCKw9Y7o89w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "Q0uPb/t/3IQ8GEwlv/J3Cw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "QC6e3OaV78mjs678tGU2KQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "QXEDMSZisv5SUXtJo7Fs5g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "RRWuvyUdhwGbBo2a/Ra1hw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "RtlxSleee0sHxodv8Zav/g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "RtrzwDgrQgu9S5B72s2sww==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "TARQvmsLVC/S1fQD1jO4Xw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "TpA/hV9k8pWHhLODuSJ+Zg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "USWNn71p+k059dbiu5HDEA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "UUZyda9G/ffvF6rJ5W1UnQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "Uy0rTKzcfvmCCFLkfEu6Rw==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": [ "71a51f20-1a3a-43d8-b4e7-9bbedea1ae7b" ] } ], "VT/lJKaSpr1RIIPMBOKV+A==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "VrCmPwuY69qW5jl9ctxOZg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "W66WOQ3v6r7mSn6+o7gaew==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "YdkMQeor/R4f5UlWcv1fVA==": [ { "package_db": "maven:deployments/hacbs-test.jar", "introduced_in": "sha256:5a6cb5489cbf1e89c9aca33a2494173af4ef456782e7e6caa8517b19f4d88669", "distribution_id": "", "repository_ids": [ "0c66dc9d-ff42-4fe3-bd08-266e790525d7" ] } ], "YjDcGmvP0/z8VqRiUvkhOQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "ZALhBg0G9taJfH1fvOjqNg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "Za0y7YiKRidyIBZNIzq/Ng==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "ar0do80Wlk1FaVvtx66g6Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "auI8KtI6OozP7EAIr9UlQQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "bWUdPEYmtshwdmuX5VapfQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "bmxL3lydQy0yU8g1iBgovg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "cXCMP7NdkMDf1+Rb1IEktQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "dOBT1Qffq44NOVuk9chDyg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "dOwQwVL1NxmF6ouACZklrQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "dSjxsaDISLUiFwRTCSO8Tg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "dtGaxafuhIU1Ppty914fJw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "eQIyD5D8mIGfekk4SP2BeQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "eZ7CwFvwDCQu4vzKyuIZgA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "f/Al/eNlUhjEgKSV0J2z7w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "f1lteJj1IxLDbDb+BI8yjg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "g146nKetkX1f4hfH1b5RWA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "gMqsUnRclTj6iuxHCslNRA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "gOaN4treTmKK7tU+N6AZ1w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "gtbMsmX05ZWh+bkM1Wprlw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "h53SWWmMQUh4cLyBmYeNvw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "hSTTMcRX1DBcXc+8jKeg3Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "hcJqCsCpWm+XI9JT6ImS5g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "isKqi8Xwt9MjwRVhU+6KzQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "isPl2YxnCTfcLmUYH6Q0sA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "jJ8GFze+u3yX6EECKEDlVA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "jmNxyfDM4IV/F4mrfNTfyg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "jtdCxL/eH5JTPcKstKunJg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "k4gCNgIfg7MM/e42ThRx2w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "kwc9NYOQig+qWs5qmBRL/w==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "lEFbOzBTlWwCqC/ZbjJfgQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "lU0MYRg2dg5wynl2dMGsgA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "mAmp7BtGrfzV0HnAKw9sTw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "mLwCNKs2wEtLWAiibtR4BQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "mkpeQMTn6iNiF+ShBe+oZg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "mlTBgPgv44eBdmn7f2Thag==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "mtrWxjnWyzrIFOuHVeUG6g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "nDtLoMnkuhspYDn7NZEcjw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "o4v1nyEgxKUJdf78CSzLEg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "oPxhGBL0xk+N4XwwxvflAQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "p7tNYPUXLVhWy6vBQfT6hA==": [ { "package_db": "root/buildinfo/Dockerfile-ubi8-openjdk-17-runtime-1.23-5", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": [ "eed176a2-41f7-4a42-8121-28d1294b721c", "eed176a2-41f7-4a42-8121-28d1294b721c" ] } ], "p9tXHgTBVU/b3sTnwfubzg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "pY2NT/GP1UxyOuAl2rKgCw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "peUaHHW4E9Y6Nd8+gJR5cQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "r23nOnTJvuvXzj0P21ldlw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "rFsA2fU/SFo3JGOkxRURTQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "s5qs8lj0/L/p9c08upXwSg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "sMrsZHOrW8FfprPHZo6Jww==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "sUhkiUesE2DHTU1IF7t+tw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "teyVOt1iJyAfEH0z7JVBTQ==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:5a6cb5489cbf1e89c9aca33a2494173af4ef456782e7e6caa8517b19f4d88669", "distribution_id": "", "repository_ids": [ "50c55364-502c-438e-8b26-3c235ff2c57f" ] } ], "trIX86+UkjuJsaeYfHvnYw==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "u25cfo+Wn6RpzVY/kgcoGQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "uCw7c1p0VzVV36rFL2/j4Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "v/KoDsdxOHqLHd7du8yyWQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "wJ4dAQ6SE4hHS42wVhzrWg==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "wQToP4WURQ4/A8LQU1k5kA==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "09aa29d7-325e-4b81-a4f8-e8e47d6a37ec" ] } ], "wpJmhjYJz5TYuh0mbRPs4Q==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "xDLbw0lNdZ2pSj9R8k9t6A==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "xTF9l16G3x26txeCsO9Bug==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "xY/gcEds28iVWCynxOCw9g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "xvIYCTeML23osZxD1kFItQ==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "5b349d99-51fd-490d-be61-6476cfeafcc3", "45dfb24f-ee0c-4b5e-9ddd-053d60e9c51d" ] } ], "ypZwlmuME3Db6H+D0SaJbg==": [ { "package_db": "root/buildinfo/Dockerfile-ubi8-openjdk-17-runtime-1.23-5", "introduced_in": "sha256:0dad12e22f7f18881533e45f2b9a03f8c91afada4557fa5e139c74f13b7a1621", "distribution_id": "", "repository_ids": [ "eed176a2-41f7-4a42-8121-28d1294b721c", "eed176a2-41f7-4a42-8121-28d1294b721c" ] } ], "zAReYdYoHUkp8wr8i3SW2g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "zdqdBY2jg/Zs374g8Ylc6g==": [ { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "", "repository_ids": null }, { "package_db": "bdb:var/lib/rpm", "introduced_in": "sha256:2e28c41ddfec9331bb4b80fdf560d6dc3fe93d51491fb8d3aff3a66d84883051", "distribution_id": "9da6b00b-ee35-4122-be55-6c0f99a0806a", "repository_ids": [ "2b384fa1-0900-4f4a-becd-83e01a868e11" ] } ], "zq37oCfqwm2d5LV97XrO8Q==": [ { "package_db": "root/buildinfo/labels.json", "introduced_in": "sha256:5a6cb5489cbf1e89c9aca33a2494173af4ef456782e7e6caa8517b19f4d88669", "distribution_id": "", "repository_ids": [ "50c55364-502c-438e-8b26-3c235ff2c57f" ] } ] }, "vulnerabilities": { "+et2nlLBpUOdsIiOQHCCVQ==": { "id": "+et2nlLBpUOdsIiOQHCCVQ==", "updater": "rhel-vex", "name": "CVE-2019-8906", "description": "A vulnerability has been identified in the File Project, specifically in the do_core_note function within readelf.c of libmagic.a where, an out-of-bounds read, can be exploited by a local attacker using a specially crafted file which could result in a denial of service or leakage of sensitive information.", "issued": "2019-01-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-8906 https://bugzilla.redhat.com/show_bug.cgi?id=1679175 https://www.cve.org/CVERecord?id=CVE-2019-8906 https://nvd.nist.gov/vuln/detail/CVE-2019-8906 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-8906.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "file", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+nHq7dak7Hkjcru/xpwzhQ==": { "id": "+nHq7dak7Hkjcru/xpwzhQ==", "updater": "rhel-vex", "name": "CVE-2020-12413", "description": "A flaw was found in Mozilla nss. A raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman(DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The highest threat from this vulnerability is to data confidentiality.", "issued": "2020-09-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-12413 https://bugzilla.redhat.com/show_bug.cgi?id=1877557 https://www.cve.org/CVERecord?id=CVE-2020-12413 https://nvd.nist.gov/vuln/detail/CVE-2020-12413 https://raccoon-attack.com/RacoonAttack.pdf https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-12413.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nss", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/1CYFiexnJcM7p4YrI/FVg==": { "id": "/1CYFiexnJcM7p4YrI/FVg==", "updater": "rhel-vex", "name": "CVE-2023-4504", "description": "A vulnerability was found in CUPS and libppd, where a failure to validate the length provided in an attacker-crafted PPD PostScript document can lead to a heap-based buffer overflow, causing a denial of service or, in some cases, execute arbitrary code, depending on how the application processes untrusted PPD files.", "issued": "2023-09-20T12:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4504 https://bugzilla.redhat.com/show_bug.cgi?id=2238509 https://www.cve.org/CVERecord?id=CVE-2023-4504 https://nvd.nist.gov/vuln/detail/CVE-2023-4504 https://takeonme.org/cves/CVE-2023-4504.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4504.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "cups", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/hG2eFl/EZ15/sR5oOZbCA==": { "id": "/hG2eFl/EZ15/sR5oOZbCA==", "updater": "rhel-vex", "name": "CVE-2026-7383", "description": "A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-7383 https://bugzilla.redhat.com/show_bug.cgi?id=2481879 https://www.cve.org/CVERecord?id=CVE-2026-7383 https://nvd.nist.gov/vuln/detail/CVE-2026-7383 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7383.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/jsmptxiHRXbuYhopHC+AQ==": { "id": "/jsmptxiHRXbuYhopHC+AQ==", "updater": "rhel-vex", "name": "CVE-2025-13462", "description": "A flaw was found in the `tarfile` module of cpython. This vulnerability allows a remote attacker to craft a malicious tar archive that, when processed, could be misinterpreted by the `tarfile` module. This misinterpretation occurs because the module incorrectly applies normalization of `AREGTYPE` blocks to `DIRTYPE` during the processing of multi-block members, such as `GNUTYPE_LONGNAME` or `GNUTYPE_LONGLINK`. The consequence is that the `tarfile` module may process the archive differently than intended, potentially leading to unexpected file system changes or data integrity issues.", "issued": "2026-03-12T17:59:26Z", "links": "https://access.redhat.com/security/cve/CVE-2025-13462 https://bugzilla.redhat.com/show_bug.cgi?id=2447082 https://www.cve.org/CVERecord?id=CVE-2025-13462 https://nvd.nist.gov/vuln/detail/CVE-2025-13462 https://github.com/python/cpython/issues/141707 https://github.com/python/cpython/pull/143934 https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13462.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0IkIJ5q/xNX41U2yF71Pyw==": { "id": "0IkIJ5q/xNX41U2yF71Pyw==", "updater": "rhel-vex", "name": "CVE-2026-13595", "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.", "issued": "2026-05-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13595 https://bugzilla.redhat.com/show_bug.cgi?id=2494101 https://www.cve.org/CVERecord?id=CVE-2026-13595 https://nvd.nist.gov/vuln/detail/CVE-2026-13595 https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13595.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0QzoXQSqkKieJ7Oc+px0JA==": { "id": "0QzoXQSqkKieJ7Oc+px0JA==", "updater": "rhel-vex", "name": "CVE-2025-13837", "description": "A flaw was found in the plistlib module in the Python standard library. The amount of data to read from a Plist file is specified in the file itself. This issue allows a specially crafted Plist file to cause an application to allocate a large amount of memory, potentially resulting in allocations errors, swapping, out-of-memory conditions or even system freezes.", "issued": "2025-12-01T18:13:32Z", "links": "https://access.redhat.com/security/cve/CVE-2025-13837 https://bugzilla.redhat.com/show_bug.cgi?id=2418084 https://www.cve.org/CVERecord?id=CVE-2025-13837 https://nvd.nist.gov/vuln/detail/CVE-2025-13837 https://github.com/python/cpython/issues/119342 https://github.com/python/cpython/pull/119343 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13837.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0fCtWwB6iclgRvIA+IqiJQ==": { "id": "0fCtWwB6iclgRvIA+IqiJQ==", "updater": "rhel-vex", "name": "CVE-2026-1484", "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1484 https://bugzilla.redhat.com/show_bug.cgi?id=2433259 https://www.cve.org/CVERecord?id=CVE-2026-1484 https://nvd.nist.gov/vuln/detail/CVE-2026-1484 https://gitlab.gnome.org/GNOME/glib/-/issues/3870 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1484.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0fRIluxuaC1n6wm+qP9Pjw==": { "id": "0fRIluxuaC1n6wm+qP9Pjw==", "updater": "rhel-vex", "name": "CVE-2026-59848", "description": "A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.", "issued": "2026-07-21T13:18:03Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59848 https://bugzilla.redhat.com/show_bug.cgi?id=2498181 https://www.cve.org/CVERecord?id=CVE-2026-59848 https://nvd.nist.gov/vuln/detail/CVE-2026-59848 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59848.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0nQ3GJDLY22M176Z5ESg6A==": { "id": "0nQ3GJDLY22M176Z5ESg6A==", "updater": "rhel-vex", "name": "CVE-2025-68972", "description": "A flaw was found in GnuPG. An adversary can exploit this vulnerability by crafting a signed message that includes a form feed character (\\f) at the end of a plaintext line. This allows the adversary to append additional, unsigned text to the message while the signature verification still reports success. This issue leads to an integrity bypass, potentially enabling the spoofing of signed communications.", "issued": "2025-12-27T22:52:30Z", "links": "https://access.redhat.com/security/cve/CVE-2025-68972 https://bugzilla.redhat.com/show_bug.cgi?id=2425646 https://www.cve.org/CVERecord?id=CVE-2025-68972 https://nvd.nist.gov/vuln/detail/CVE-2025-68972 https://gpg.fail/formfeed https://news.ycombinator.com/item?id=46404339 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68972.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0v/g0Z/XEXV13r48i52JgA==": { "id": "0v/g0Z/XEXV13r48i52JgA==", "updater": "rhel-vex", "name": "CVE-2026-6276", "description": "A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intended for the first host to the second host, resulting in a cookie leak. This issue is categorized as an Origin Validation Error (CWE-346). Exploitation typically requires specific debugging configurations.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6276 https://bugzilla.redhat.com/show_bug.cgi?id=2461203 https://www.cve.org/CVERecord?id=CVE-2026-6276 https://nvd.nist.gov/vuln/detail/CVE-2026-6276 https://curl.se/docs/CVE-2026-6276.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6276.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1lUHOMB3ANHGWpqCBv9Ynw==": { "id": "1lUHOMB3ANHGWpqCBv9Ynw==", "updater": "rhel-vex", "name": "CVE-2026-4105", "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.", "issued": "2026-03-13T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4105 https://bugzilla.redhat.com/show_bug.cgi?id=2447262 https://www.cve.org/CVERecord?id=CVE-2026-4105 https://nvd.nist.gov/vuln/detail/CVE-2026-4105 https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4105.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1vG4ZYIu07BTj9XJ+a+P9Q==": { "id": "1vG4ZYIu07BTj9XJ+a+P9Q==", "updater": "rhel-vex", "name": "CVE-2026-27171", "description": "A flaw was found in zlib. An attacker providing specially crafted input to the `crc32_combine64` or `crc32_combine_gen64` functions could trigger an infinite loop within the `x2nmodp` function. This leads to excessive CPU consumption, which can result in a Denial of Service (DoS) for the affected system.", "issued": "2026-02-18T02:36:19Z", "links": "https://access.redhat.com/security/cve/CVE-2026-27171 https://bugzilla.redhat.com/show_bug.cgi?id=2440530 https://www.cve.org/CVERecord?id=CVE-2026-27171 https://nvd.nist.gov/vuln/detail/CVE-2026-27171 https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/ https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf https://github.com/madler/zlib/issues/904 https://github.com/madler/zlib/releases/tag/v1.3.2 https://ostif.org/zlib-audit-complete/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27171.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "java-17-openjdk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "29qrZyz+fmdn9Nzjpl2/Pg==": { "id": "29qrZyz+fmdn9Nzjpl2/Pg==", "updater": "rhel-vex", "name": "CVE-2026-22693", "description": "A null pointer dereference vector has been discovered in the harfbuzz package. A null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh:1672-1673. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault.", "issued": "2026-01-10T05:53:21Z", "links": "https://access.redhat.com/security/cve/CVE-2026-22693 https://bugzilla.redhat.com/show_bug.cgi?id=2428439 https://www.cve.org/CVERecord?id=CVE-2026-22693 https://nvd.nist.gov/vuln/detail/CVE-2026-22693 https://github.com/harfbuzz/harfbuzz/commit/1265ff8d990284f04d8768f35b0e20ae5f60daae https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-xvjr-f2r9-c7ww https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22693.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "java-17-openjdk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2DLcncUUd6/1/JtsPnknxw==": { "id": "2DLcncUUd6/1/JtsPnknxw==", "updater": "rhel-vex", "name": "CVE-2018-20839", "description": "The issue arises from the way systemd handles user passwords during the boot process. Specifically, passwords entered on the console during the system boot (e.g., for unlocking encrypted disks or logging in) could be logged in plaintext if certain conditions are met.", "issued": "2019-05-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-20839 https://bugzilla.redhat.com/show_bug.cgi?id=1716955 https://www.cve.org/CVERecord?id=CVE-2018-20839 https://nvd.nist.gov/vuln/detail/CVE-2018-20839 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-20839.json", "severity": "CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2GyYg2XSUSR6EJven3MV7w==": { "id": "2GyYg2XSUSR6EJven3MV7w==", "updater": "rhel-vex", "name": "CVE-2026-56132", "description": "A flaw was found in libexpat, a library used for parsing XML data. An attacker could exploit a heap-based buffer overflow, a type of memory error, by providing specially crafted XML input. This vulnerability occurs when the library mishandles memory reallocation while processing XML, particularly when multiple parsers share data. Successful exploitation could allow the attacker to execute arbitrary code, access sensitive information, or cause the application to crash, leading to a denial of service.", "issued": "2026-06-19T03:00:42Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56132 https://bugzilla.redhat.com/show_bug.cgi?id=2490669 https://www.cve.org/CVERecord?id=CVE-2026-56132 https://nvd.nist.gov/vuln/detail/CVE-2026-56132 https://github.com/libexpat/libexpat/pull/1272 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56132.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2U6d1qsPVwS8vUnflv9AcQ==": { "id": "2U6d1qsPVwS8vUnflv9AcQ==", "updater": "rhel-vex", "name": "CVE-2026-4873", "description": "A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass the TLS requirement, leading to the transmission of sensitive information in cleartext. This vulnerability, categorized as Cleartext Transmission of Sensitive Information (CWE-319), results in information disclosure.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4873 https://bugzilla.redhat.com/show_bug.cgi?id=2461200 https://www.cve.org/CVERecord?id=CVE-2026-4873 https://nvd.nist.gov/vuln/detail/CVE-2026-4873 https://curl.se/docs/CVE-2026-4873.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4873.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2U8ppg+02PjFDuM5YqFstQ==": { "id": "2U8ppg+02PjFDuM5YqFstQ==", "updater": "rhel-vex", "name": "CVE-2025-15282", "description": "Missing newline filtering has been discovered in Python. User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.", "issued": "2026-01-20T21:35:13Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15282 https://bugzilla.redhat.com/show_bug.cgi?id=2431366 https://www.cve.org/CVERecord?id=CVE-2025-15282 https://nvd.nist.gov/vuln/detail/CVE-2025-15282 https://github.com/python/cpython/issues/143925 https://github.com/python/cpython/pull/143926 https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15282.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3IgZDz5UYkhu/U1/4kSWKg==": { "id": "3IgZDz5UYkhu/U1/4kSWKg==", "updater": "rhel-vex", "name": "CVE-2021-25317", "description": "It was found that some Linux vendors may assign the ownership of the /var/log/cups directory to the `lp` user. This could allow an attacker with such privileges to create empty files in arbitrary locations, or to force arbitrary files to be opened and closed, using a symlink attack. This has a low impact on the integrity of the system.", "issued": "2021-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-25317 https://bugzilla.redhat.com/show_bug.cgi?id=1949119 https://www.cve.org/CVERecord?id=CVE-2021-25317 https://nvd.nist.gov/vuln/detail/CVE-2021-25317 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-25317.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "cups", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3O4IzHXnRQMZXCe1gYATvw==": { "id": "3O4IzHXnRQMZXCe1gYATvw==", "updater": "rhel-vex", "name": "CVE-2026-22185", "description": "A flaw was found in OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load. When processing malformed input, a local attacker can exploit a heap buffer underflow vulnerability in the readline() function. This can lead to an out-of-bounds read, potentially causing a denial of service (DoS) and limited disclosure of heap memory contents.", "issued": "2026-01-07T20:26:30Z", "links": "https://access.redhat.com/security/cve/CVE-2026-22185 https://bugzilla.redhat.com/show_bug.cgi?id=2427679 https://www.cve.org/CVERecord?id=CVE-2026-22185 https://nvd.nist.gov/vuln/detail/CVE-2026-22185 https://seclists.org/fulldisclosure/2026/Jan/5 https://seclists.org/fulldisclosure/2026/Jan/8 https://www.openldap.org/ https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22185.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "openldap", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4JszZEguo/SAFbgp6PdKMQ==": { "id": "4JszZEguo/SAFbgp6PdKMQ==", "updater": "rhel-vex", "name": "CVE-2026-5773", "description": "A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5773 https://bugzilla.redhat.com/show_bug.cgi?id=2461201 https://www.cve.org/CVERecord?id=CVE-2026-5773 https://nvd.nist.gov/vuln/detail/CVE-2026-5773 https://curl.se/docs/CVE-2026-5773.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5773.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4jAWcNPbUa6mXzywmxFG1g==": { "id": "4jAWcNPbUa6mXzywmxFG1g==", "updater": "rhel-vex", "name": "CVE-2026-58011", "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.", "issued": "2026-03-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58011 https://bugzilla.redhat.com/show_bug.cgi?id=2492245 https://www.cve.org/CVERecord?id=CVE-2026-58011 https://nvd.nist.gov/vuln/detail/CVE-2026-58011 https://gitlab.gnome.org/GNOME/glib/-/issues/3917 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58011.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "54QMeb97RdTZwYWYELMfPw==": { "id": "54QMeb97RdTZwYWYELMfPw==", "updater": "rhel-vex", "name": "CVE-2018-1000654", "description": "A vulnerability was found in GNU Libtasn1, where a resource management issue can lead to a denial of service, here an attacker could exploit this flaw by persuading a victim to parse a specially crafted file, exhausting all available CPU resources.", "issued": "2018-08-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-1000654 https://bugzilla.redhat.com/show_bug.cgi?id=1621972 https://www.cve.org/CVERecord?id=CVE-2018-1000654 https://nvd.nist.gov/vuln/detail/CVE-2018-1000654 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-1000654.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libtasn1", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5B1tQ2BK8z/YjRkYcvwqag==": { "id": "5B1tQ2BK8z/YjRkYcvwqag==", "updater": "rhel-vex", "name": "CVE-2019-19244", "description": "A flaw was found in the way SQLite handled certain types of SQL queries using DISTINCT, OVER and ORDER BY clauses. A remote attacker could exploit this flaw by providing a malicious SQL query that, when processed by an application linked to SQLite, would crash the application causing a denial of service.", "issued": "2019-11-22T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-19244 https://bugzilla.redhat.com/show_bug.cgi?id=1777945 https://www.cve.org/CVERecord?id=CVE-2019-19244 https://nvd.nist.gov/vuln/detail/CVE-2019-19244 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-19244.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5N/X0o1/JN9fqvD4aiuURA==": { "id": "5N/X0o1/JN9fqvD4aiuURA==", "updater": "rhel-vex", "name": "CVE-2026-42250", "description": "A flaw was found in bzip2. The bzip2recover utility contains an off-by-one error that allows a local attacker to cause an out-of-bounds write to a global buffer by processing a specially crafted file. This memory corruption can lead to a crash, resulting in a Denial of Service (DoS).", "issued": "2026-05-28T13:15:19Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42250 https://bugzilla.redhat.com/show_bug.cgi?id=2482704 https://www.cve.org/CVERecord?id=CVE-2026-42250 https://nvd.nist.gov/vuln/detail/CVE-2026-42250 https://cert.pl/en/posts/2026/05/CVE-2026-42250/ https://sourceware.org/bzip2/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42250.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "bzip2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5ZHvcDYhgzWjwNpRgF2u1w==": { "id": "5ZHvcDYhgzWjwNpRgF2u1w==", "updater": "rhel-vex", "name": "CVE-2025-1795", "description": "A flaw was found in Python. When a separating comma ends up on a folded line during an address list folding of email headers, the comma is unintentionally unicode encoded. The expected behavior is that the separating comma remains unencoded. This can result in the address header being misinterpreted by some mail servers.", "issued": "2025-02-28T18:59:31Z", "links": "https://access.redhat.com/security/cve/CVE-2025-1795 https://bugzilla.redhat.com/show_bug.cgi?id=2349061 https://www.cve.org/CVERecord?id=CVE-2025-1795 https://nvd.nist.gov/vuln/detail/CVE-2025-1795 https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48 https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593 https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74 https://github.com/python/cpython/issues/100884 https://github.com/python/cpython/pull/100885 https://github.com/python/cpython/pull/119099 https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1795.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5e3gC+KDeb36jTLxBYtijg==": { "id": "5e3gC+KDeb36jTLxBYtijg==", "updater": "rhel-vex", "name": "CVE-2026-41990", "description": "A flaw was found in Libgcrypt. During Dilithium signing operations, the library fails to perform a bounds check when writing to a static array. While the data involved is not directly controlled by an attacker, this vulnerability could lead to memory corruption, potentially resulting in a denial of service (DoS) or affecting data integrity.", "issued": "2026-04-23T04:39:04Z", "links": "https://access.redhat.com/security/cve/CVE-2026-41990 https://bugzilla.redhat.com/show_bug.cgi?id=2461068 https://www.cve.org/CVERecord?id=CVE-2026-41990 https://nvd.nist.gov/vuln/detail/CVE-2026-41990 https://dev.gnupg.org/T8208 https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html https://www.openwall.com/lists/oss-security/2026/04/21/1 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41990.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "619DQiII/+IW12e6tmtrxw==": { "id": "619DQiII/+IW12e6tmtrxw==", "updater": "rhel-vex", "name": "CVE-2026-6732", "description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.", "issued": "2026-04-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6732 https://bugzilla.redhat.com/show_bug.cgi?id=2461300 https://www.cve.org/CVERecord?id=CVE-2026-6732 https://nvd.nist.gov/vuln/detail/CVE-2026-6732 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097 https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6732.json", "severity": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "673FKazcUiydbfN5c6amaw==": { "id": "673FKazcUiydbfN5c6amaw==", "updater": "rhel-vex", "name": "CVE-2020-19190", "description": "A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19190 https://bugzilla.redhat.com/show_bug.cgi?id=2234923 https://www.cve.org/CVERecord?id=CVE-2020-19190 https://nvd.nist.gov/vuln/detail/CVE-2020-19190 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19190.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6Cqvzp5JbuVfHsuYnIJNFw==": { "id": "6Cqvzp5JbuVfHsuYnIJNFw==", "updater": "rhel-vex", "name": "CVE-2026-4438", "description": "A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.", "issued": "2026-03-20T19:59:06Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4438 https://bugzilla.redhat.com/show_bug.cgi?id=2449783 https://www.cve.org/CVERecord?id=CVE-2026-4438 https://nvd.nist.gov/vuln/detail/CVE-2026-4438 https://sourceware.org/bugzilla/show_bug.cgi?id=34015 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4438.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6FQUI3OxX4C5skWXKgq80Q==": { "id": "6FQUI3OxX4C5skWXKgq80Q==", "updater": "rhel-vex", "name": "CVE-2023-0464", "description": "A security vulnerability has been identified in all supported OpenSSL versions related to verifying X.509 certificate chains that include policy constraints. This flaw allows attackers to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial of service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the -policy' argument to the command line utilities or calling the X509_VERIFY_PARAM_set1_policies()' function.", "issued": "2023-03-22T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-0464 https://bugzilla.redhat.com/show_bug.cgi?id=2181082 https://www.cve.org/CVERecord?id=CVE-2023-0464 https://nvd.nist.gov/vuln/detail/CVE-2023-0464 https://www.openssl.org/news/secadv/20230322.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0464.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6UnjveNMgk4ukDQJdTGvOQ==": { "id": "6UnjveNMgk4ukDQJdTGvOQ==", "updater": "rhel-vex", "name": "CVE-2026-18739", "description": "A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.", "issued": "2026-08-03T18:46:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-18739 https://bugzilla.redhat.com/show_bug.cgi?id=2510737 https://www.cve.org/CVERecord?id=CVE-2026-18739 https://nvd.nist.gov/vuln/detail/CVE-2026-18739 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18739.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "popt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6Xr5PbPGSy+aHLDQ9q4L9w==": { "id": "6Xr5PbPGSy+aHLDQ9q4L9w==", "updater": "rhel-vex", "name": "CVE-2026-1502", "description": "A flaw was found in Python. This vulnerability allows for the injection of extra information into HTTP communication. Specifically, the system does not properly prevent special characters (carriage return and line feed) from being included in HTTP client proxy tunnel headers or host fields.", "issued": "2026-04-10T17:54:44Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1502 https://bugzilla.redhat.com/show_bug.cgi?id=2457409 https://www.cve.org/CVERecord?id=CVE-2026-1502 https://nvd.nist.gov/vuln/detail/CVE-2026-1502 https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69 https://github.com/python/cpython/issues/146211 https://github.com/python/cpython/pull/146212 https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1502.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6pD/2IKN8cR6N6PBQHwPrQ==": { "id": "6pD/2IKN8cR6N6PBQHwPrQ==", "updater": "rhel-vex", "name": "CVE-2026-42766", "description": "A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42766 https://bugzilla.redhat.com/show_bug.cgi?id=2481890 https://www.cve.org/CVERecord?id=CVE-2026-42766 https://nvd.nist.gov/vuln/detail/CVE-2026-42766 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42766.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7Fk3wVCUvtHC5JGu/YwCEw==": { "id": "7Fk3wVCUvtHC5JGu/YwCEw==", "updater": "rhel-vex", "name": "CVE-2026-54371", "description": "A flaw was found in the `attr` package. This vulnerability allows a local attacker to perform a symlink traversal attack by replacing a pathname component with a symbolic link - either during directory hierarchy traversal by `getfattr` or during backup restoration by `setfattr`, which reads and resolves full pathnames from backup files. In both cases, when these utilities are executed by a privileged process over a path controlled by the attacker, this can lead to local privilege escalation.", "issued": "2026-06-29T13:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-54371 https://bugzilla.redhat.com/show_bug.cgi?id=2490283 https://www.cve.org/CVERecord?id=CVE-2026-54371 https://nvd.nist.gov/vuln/detail/CVE-2026-54371 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "attr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7Puka2o1jq4jSr2Hekrfhg==": { "id": "7Puka2o1jq4jSr2Hekrfhg==", "updater": "rhel-vex", "name": "CVE-2026-1757", "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.", "issued": "2026-02-02T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1757 https://bugzilla.redhat.com/show_bug.cgi?id=2435940 https://www.cve.org/CVERecord?id=CVE-2026-1757 https://nvd.nist.gov/vuln/detail/CVE-2026-1757 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1757.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7lnphmrb/VojuhlikpNO5w==": { "id": "7lnphmrb/VojuhlikpNO5w==", "updater": "rhel-vex", "name": "CVE-2026-24401", "description": "A flaw was found in Avahi, a system that enables devices to discover services on a local network. A remote attacker can exploit this vulnerability by sending a specially crafted mDNS (multicast Domain Name System) response containing a recursive CNAME (Canonical Name) record. This triggers an uncontrolled recursion within the avahi-daemon process, leading to stack exhaustion and causing the service to crash. This results in a denial of service (DoS) for affected systems.", "issued": "2026-01-24T01:25:02Z", "links": "https://access.redhat.com/security/cve/CVE-2026-24401 https://bugzilla.redhat.com/show_bug.cgi?id=2432534 https://www.cve.org/CVERecord?id=CVE-2026-24401 https://nvd.nist.gov/vuln/detail/CVE-2026-24401 https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524 https://github.com/avahi/avahi/issues/501 https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24401.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "avahi", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "86unVXyTxdffdcXWZTYw5g==": { "id": "86unVXyTxdffdcXWZTYw5g==", "updater": "rhel-vex", "name": "CVE-2023-0465", "description": "A flaw was found in OpenSSL. Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. OpenSSL and other certificate policy checks silently ignore invalid certificate policies in leaf certificates that are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.", "issued": "2023-03-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-0465 https://bugzilla.redhat.com/show_bug.cgi?id=2182561 https://www.cve.org/CVERecord?id=CVE-2023-0465 https://nvd.nist.gov/vuln/detail/CVE-2023-0465 https://www.openssl.org/news/secadv/20230328.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0465.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8D3i4K1ylUr5dGk9imV9zA==": { "id": "8D3i4K1ylUr5dGk9imV9zA==", "updater": "rhel-vex", "name": "CVE-2025-69420", "description": "A flaw was found in OpenSSL. A type confusion vulnerability exists in the TimeStamp Response verification code, where an ASN1_TYPE union member is accessed without proper type validation. A remote attacker can exploit this by providing a malformed TimeStamp Response to an application that verifies timestamp responses. This can lead to an invalid or NULL pointer dereference, resulting in a Denial of Service (DoS) due to an application crash.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-69420 https://bugzilla.redhat.com/show_bug.cgi?id=2430388 https://www.cve.org/CVERecord?id=CVE-2025-69420 https://nvd.nist.gov/vuln/detail/CVE-2025-69420 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69420.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8I2jFG8JRR+6+eqqYlXhAg==": { "id": "8I2jFG8JRR+6+eqqYlXhAg==", "updater": "rhel-vex", "name": "CVE-2018-20225", "description": "A vulnerability was found in python-pip due to a flaw in the --extra-index-url option, where it installs the version with the highest version number, even if the user intended to obtain a private package from a private index. Exploitation requires that the package does not already exist in the public index, allowing an attacker to place the package there with an arbitrary version number.", "issued": "2020-04-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-20225 https://bugzilla.redhat.com/show_bug.cgi?id=1835736 https://www.cve.org/CVERecord?id=CVE-2018-20225 https://nvd.nist.gov/vuln/detail/CVE-2018-20225 https://cowlicks.website/posts/arbitrary-code-execution-from-pips-extra-index-url.html https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-20225.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "python-pip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8KJb4x3mXgChaQULEsid2A==": { "id": "8KJb4x3mXgChaQULEsid2A==", "updater": "rhel-vex", "name": "CVE-2025-15224", "description": "A flaw was found in libcurl. When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15224 https://bugzilla.redhat.com/show_bug.cgi?id=2426410 https://www.cve.org/CVERecord?id=CVE-2025-15224 https://nvd.nist.gov/vuln/detail/CVE-2025-15224 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15224.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8Sec+JvKiQWGqYCOBdZhjg==": { "id": "8Sec+JvKiQWGqYCOBdZhjg==", "updater": "rhel-vex", "name": "CVE-2025-5918", "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5918 https://bugzilla.redhat.com/show_bug.cgi?id=2370877 https://www.cve.org/CVERecord?id=CVE-2025-5918 https://nvd.nist.gov/vuln/detail/CVE-2025-5918 https://github.com/libarchive/libarchive/pull/2584 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5918.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8TgjbHNGzIFm7/fF9DBU7Q==": { "id": "8TgjbHNGzIFm7/fF9DBU7Q==", "updater": "rhel-vex", "name": "CVE-2026-34757", "description": "A flaw was found in libpng, a library used for handling PNG (Portable Network Graphics) image files. This vulnerability arises when an application reuses a pointer, previously obtained from functions like png_get_PLTE, by passing it back to a corresponding setter function within the same image structure. This action causes the setter to access memory that has already been deallocated, leading to a use-after-free condition. A local attacker could potentially exploit this flaw to corrupt image metadata or disclose sensitive information from the application's memory.", "issued": "2026-04-09T14:41:18Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34757 https://bugzilla.redhat.com/show_bug.cgi?id=2456918 https://www.cve.org/CVERecord?id=CVE-2026-34757 https://nvd.nist.gov/vuln/detail/CVE-2026-34757 https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc https://github.com/pnggroup/libpng/issues/836 https://github.com/pnggroup/libpng/issues/837 https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34757.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "java-17-openjdk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8WDcymWmuQ3Sn9ymHvtn4Q==": { "id": "8WDcymWmuQ3Sn9ymHvtn4Q==", "updater": "rhel-vex", "name": "CVE-2026-13757", "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.", "issued": "2026-06-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13757 https://bugzilla.redhat.com/show_bug.cgi?id=2494556 https://www.cve.org/CVERecord?id=CVE-2026-13757 https://nvd.nist.gov/vuln/detail/CVE-2026-13757 https://github.com/advisories/GHSA-p2wm-69qx-x25w https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13757.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "p11-kit", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8ZxbhBIT+9Mj99/XbMpLSQ==": { "id": "8ZxbhBIT+9Mj99/XbMpLSQ==", "updater": "rhel-vex", "name": "CVE-2024-0232", "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.", "issued": "2023-10-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-0232 https://bugzilla.redhat.com/show_bug.cgi?id=2243754 https://www.cve.org/CVERecord?id=CVE-2024-0232 https://nvd.nist.gov/vuln/detail/CVE-2024-0232 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0232.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8qOJVWAut1+UqTXPOWH12g==": { "id": "8qOJVWAut1+UqTXPOWH12g==", "updater": "rhel-vex", "name": "CVE-2025-8291", "description": "A zip file handling flaw has been discovered in the python standard library `zipfile` module. The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations.", "issued": "2025-10-07T18:10:05Z", "links": "https://access.redhat.com/security/cve/CVE-2025-8291 https://bugzilla.redhat.com/show_bug.cgi?id=2402342 https://www.cve.org/CVERecord?id=CVE-2025-8291 https://nvd.nist.gov/vuln/detail/CVE-2025-8291 https://github.com/python/cpython/commit/162997bb70e067668c039700141770687bc8f267 https://github.com/python/cpython/commit/333d4a6f4967d3ace91492a39ededbcf3faa76a6 https://github.com/python/cpython/issues/139700 https://github.com/python/cpython/pull/139702 https://mail.python.org/archives/list/security-announce@python.org/thread/QECOPWMTH4VPPJAXAH2BGTA4XADOP62G/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-8291.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8rDgIikh0LbAtcEOjHed4Q==": { "id": "8rDgIikh0LbAtcEOjHed4Q==", "updater": "rhel-vex", "name": "CVE-2026-6368", "description": "A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS).", "issued": "2026-08-10T18:40:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6368 https://bugzilla.redhat.com/show_bug.cgi?id=2513608 https://www.cve.org/CVERecord?id=CVE-2026-6368 https://nvd.nist.gov/vuln/detail/CVE-2026-6368 https://sourceware.org/bugzilla/show_bug.cgi?id=34090 https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6368.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8rvqTFlh9aOz4UvxQN0SBQ==": { "id": "8rvqTFlh9aOz4UvxQN0SBQ==", "updater": "rhel-vex", "name": "CVE-2026-3479", "description": "A flaw was found in Python's `pkgutil.get_data()` function, which is used to retrieve data from packages. This function did not properly validate the `resource` argument, allowing a local attacker to perform path traversal attacks. Path traversal enables an attacker to access files and directories stored outside the intended root directory, potentially leading to information disclosure or unintended file access.", "issued": "2026-03-18T18:13:42Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3479 https://bugzilla.redhat.com/show_bug.cgi?id=2448746 https://www.cve.org/CVERecord?id=CVE-2026-3479 https://nvd.nist.gov/vuln/detail/CVE-2026-3479 https://github.com/python/cpython/issues/146121 https://github.com/python/cpython/pull/146122 https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3479.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8rxYDEPu2XxazQ3cBUhX0Q==": { "id": "8rxYDEPu2XxazQ3cBUhX0Q==", "updater": "rhel-vex", "name": "CVE-2019-9923", "description": "pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.", "issued": "2019-01-02T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-9923 https://bugzilla.redhat.com/show_bug.cgi?id=1691764 https://www.cve.org/CVERecord?id=CVE-2019-9923 https://nvd.nist.gov/vuln/detail/CVE-2019-9923 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-9923.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "97PwDrD8knMveLXwKCvQjA==": { "id": "97PwDrD8knMveLXwKCvQjA==", "updater": "rhel-vex", "name": "CVE-2026-22795", "description": "A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a Denial of Service (DoS) by tricking a user or application into processing a maliciously crafted PKCS#12 (Personal Information Exchange Syntax Standard) file. The vulnerability leads to an invalid or NULL pointer dereference, resulting in an application crash.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-22795 https://bugzilla.redhat.com/show_bug.cgi?id=2430389 https://www.cve.org/CVERecord?id=CVE-2026-22795 https://nvd.nist.gov/vuln/detail/CVE-2026-22795 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22795.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9ZCmRufeuC0TKSSi9pcU6g==": { "id": "9ZCmRufeuC0TKSSi9pcU6g==", "updater": "rhel-vex", "name": "CVE-2026-41079", "description": "A flaw was found in CUPS. A network-adjacent attacker can send a specially crafted Simple Network Management Protocol (SNMP) response to the CUPS SNMP backend, leading to an out-of-bounds read. This vulnerability allows for the disclosure of up to 176 bytes of sensitive memory, which is then converted and stored as printer supply description strings. Authenticated users can subsequently view this leaked information through IPP Get-Printer-Attributes responses and the CUPS web interface.", "issued": "2026-04-24T16:54:38Z", "links": "https://access.redhat.com/security/cve/CVE-2026-41079 https://bugzilla.redhat.com/show_bug.cgi?id=2461611 https://www.cve.org/CVERecord?id=CVE-2026-41079 https://nvd.nist.gov/vuln/detail/CVE-2026-41079 https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080 https://github.com/OpenPrinting/cups/commit/d7fe0f521ff3b24676511e747b058362b9a20737 https://github.com/OpenPrinting/cups/security/advisories/GHSA-6wpw-g8g6-wvrv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41079.json", "severity": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "cups", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9jHXNtwzqlOir/Op7pd9+w==": { "id": "9jHXNtwzqlOir/Op7pd9+w==", "updater": "rhel-vex", "name": "CVE-2025-68276", "description": "A flaw was found in Avahi, a system that facilitates service discovery on a local network. An unprivileged local user can exploit this vulnerability by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can lead to a Denial of Service (DoS) by crashing the avahi-daemon, making the service unavailable.", "issued": "2026-01-12T17:31:49Z", "links": "https://access.redhat.com/security/cve/CVE-2025-68276 https://bugzilla.redhat.com/show_bug.cgi?id=2428713 https://www.cve.org/CVERecord?id=CVE-2025-68276 https://nvd.nist.gov/vuln/detail/CVE-2025-68276 https://github.com/avahi/avahi/commit/ede7048475c5d47d53890e3bc1350dda8e0b3688 https://github.com/avahi/avahi/pull/806 https://github.com/avahi/avahi/security/advisories/GHSA-mhf3-865v-g5rc https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68276.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "avahi", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9oBjtBiHtz7+Hwc4swPaAw==": { "id": "9oBjtBiHtz7+Hwc4swPaAw==", "updater": "rhel-vex", "name": "CVE-2026-34979", "description": "A flaw was found in OpenPrinting CUPS. A remote attacker could exploit a heap-based buffer overflow by sending specially crafted job attributes when building filter option strings. This could lead to a denial of service, making the printing system unavailable.", "issued": "2026-04-03T21:16:38Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34979 https://bugzilla.redhat.com/show_bug.cgi?id=2454946 https://www.cve.org/CVERecord?id=CVE-2026-34979 https://nvd.nist.gov/vuln/detail/CVE-2026-34979 https://github.com/OpenPrinting/cups/security/advisories/GHSA-6qxf-7jx6-86fh https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34979.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "cups", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9uK7ZDYgFtqP786n0QunAg==": { "id": "9uK7ZDYgFtqP786n0QunAg==", "updater": "rhel-vex", "name": "CVE-2023-39804", "description": "A flaw was found in tar. This issue occurs when extended attributes are processed in PAX archives, and could allow an attacker to cause an application crash, resulting in a denial of service.", "issued": "2023-12-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-39804 https://bugzilla.redhat.com/show_bug.cgi?id=2254067 https://www.cve.org/CVERecord?id=CVE-2023-39804 https://nvd.nist.gov/vuln/detail/CVE-2023-39804 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-39804.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A0ZMrO+gsPP+1kjH7JYgNw==": { "id": "A0ZMrO+gsPP+1kjH7JYgNw==", "updater": "rhel-vex", "name": "CVE-2024-11053", "description": "A flaw was found in curl. A logic error when processing credentials from the .netrc file while performing redirects allows the transfer of credentials from the original host to the followed-to host under certain circumstances, leaking the credentials to the followed-to host.", "issued": "2024-12-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-11053 https://bugzilla.redhat.com/show_bug.cgi?id=2331191 https://www.cve.org/CVERecord?id=CVE-2024-11053 https://nvd.nist.gov/vuln/detail/CVE-2024-11053 https://curl.se/docs/CVE-2024-11053.html https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-11053.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A1UDSDMkPKOSx7ma/geQyg==": { "id": "A1UDSDMkPKOSx7ma/geQyg==", "updater": "rhel-vex", "name": "CVE-2025-68468", "description": "A flaw was found in Avahi. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted unsolicited announcements containing CNAME resource records. These records, when pointing to other resource records with short Time-To-Live (TTL) values, can lead to the `avahi-daemon` crashing once they expire. This vulnerability impacts the availability of services relying on Avahi's service discovery.", "issued": "2026-01-12T17:38:10Z", "links": "https://access.redhat.com/security/cve/CVE-2025-68468 https://bugzilla.redhat.com/show_bug.cgi?id=2428714 https://www.cve.org/CVERecord?id=CVE-2025-68468 https://nvd.nist.gov/vuln/detail/CVE-2025-68468 https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a https://github.com/avahi/avahi/issues/683 https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68468.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "avahi", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AE8Cp1u8I9t52OYW7oGU4w==": { "id": "AE8Cp1u8I9t52OYW7oGU4w==", "updater": "rhel-vex", "name": "CVE-2024-57970", "description": "A flaw was found in the libarchive library. A specially-crafted tar file may trigger a head-based buffer over-read condition due to incorrect handling of truncation in the middle of a long GNU linkname. This issue can cause an application crash leading to a denial of service.", "issued": "2025-02-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-57970 https://bugzilla.redhat.com/show_bug.cgi?id=2345954 https://www.cve.org/CVERecord?id=CVE-2024-57970 https://nvd.nist.gov/vuln/detail/CVE-2024-57970 https://github.com/libarchive/libarchive/issues/2415 https://github.com/libarchive/libarchive/pull/2422 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-57970.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AFfQXLrpt1jw7bczIIvo6Q==": { "id": "AFfQXLrpt1jw7bczIIvo6Q==", "updater": "rhel-vex", "name": "CVE-2018-1000879", "description": "A vulnerability was found in libarchive, where a NULL pointer dereference in the archive_acl_from_text_l function in libarchive/archive_acl.c can lead to a denial of service, a remote attacker could exploit this flaw by persuading a victim to open a specially crafted file, causing the application to crash.", "issued": "2018-11-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-1000879 https://bugzilla.redhat.com/show_bug.cgi?id=1663890 https://www.cve.org/CVERecord?id=CVE-2018-1000879 https://nvd.nist.gov/vuln/detail/CVE-2018-1000879 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-1000879.json", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AIctk9Oe2AgHDAC8E7gw8Q==": { "id": "AIctk9Oe2AgHDAC8E7gw8Q==", "updater": "rhel-vex", "name": "CVE-2026-53655", "description": "A flaw was found in node-tar. This vulnerability arises because node-tar incorrectly applies PAX extended header size records to subsequent intermediary metadata headers, leading to a desynchronization of the tar stream cursor compared to other standard tar implementations. A remote attacker could exploit this by crafting a malicious archive, causing different interpretations of archive contents between node-tar and other tools. This could allow an attacker to hide malicious files or sensitive information from security scanners that rely on different tar parsing libraries, potentially leading to information disclosure or bypassing security controls.", "issued": "2026-06-22T14:55:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-53655 https://bugzilla.redhat.com/show_bug.cgi?id=2491423 https://www.cve.org/CVERecord?id=CVE-2026-53655 https://nvd.nist.gov/vuln/detail/CVE-2026-53655 https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53655.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AZQ9MHTiNLYiRU7sYZlVGw==": { "id": "AZQ9MHTiNLYiRU7sYZlVGw==", "updater": "rhel-vex", "name": "CVE-2022-4899", "description": "A vulnerability was found in zstd. This flaw allows an attacker to supply an empty string as an argument to the command line tool to cause a buffer overrun.", "issued": "2022-07-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-4899 https://bugzilla.redhat.com/show_bug.cgi?id=2179864 https://www.cve.org/CVERecord?id=CVE-2022-4899 https://nvd.nist.gov/vuln/detail/CVE-2022-4899 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-4899.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "zstd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AsUlQvbhYUzI8ZRGAIAAkw==": { "id": "AsUlQvbhYUzI8ZRGAIAAkw==", "updater": "rhel-vex", "name": "CVE-2026-8932", "description": "A flaw was found in curl. The libcurl library, used for transferring data with URLs, could improperly reuse existing network connections. This occurred even when changes to mutual Transport Layer Security (mTLS) settings, particularly those for client certificates, should have prevented such reuse. This issue could lead to a security feature bypass, where a client might use a connection with an unintended or weaker security configuration, potentially compromising the integrity or confidentiality of data.", "issued": "2026-07-03T06:16:30Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8932 https://bugzilla.redhat.com/show_bug.cgi?id=2496759 https://www.cve.org/CVERecord?id=CVE-2026-8932 https://nvd.nist.gov/vuln/detail/CVE-2026-8932 https://curl.se/docs/CVE-2026-8932.html https://curl.se/docs/CVE-2026-8932.json https://hackerone.com/reports/3733910 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8932.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BV++s35Ur4bQRS6HK0QCIA==": { "id": "BV++s35Ur4bQRS6HK0QCIA==", "updater": "rhel-vex", "name": "CVE-2026-31789", "description": "A flaw was found in OpenSSL. This vulnerability, a heap buffer overflow, affects 32-bit systems when processing an unusually large X.509 certificate. If an application or service attempts to print or log such a specially crafted certificate, it could lead to a system crash or potentially allow an attacker to execute arbitrary code. This issue is considered low severity due to the specific conditions required for exploitation, including the need for an extremely large certificate and a 32-bit operating environment.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-31789 https://bugzilla.redhat.com/show_bug.cgi?id=2451095 https://www.cve.org/CVERecord?id=CVE-2026-31789 https://nvd.nist.gov/vuln/detail/CVE-2026-31789 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31789.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BWyeN3+8e4QAjW/V4C/Ktg==": { "id": "BWyeN3+8e4QAjW/V4C/Ktg==", "updater": "rhel-vex", "name": "CVE-2026-56131", "description": "A use-after-free vulnerability in libexpat occurs because handler call depth isn't properly tracked when XML_ResumeParser is invoked during policy violations. This flaw can lead to information disclosure, data corruption, or denial of service.", "issued": "2026-06-19T02:56:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56131 https://bugzilla.redhat.com/show_bug.cgi?id=2490668 https://www.cve.org/CVERecord?id=CVE-2026-56131 https://nvd.nist.gov/vuln/detail/CVE-2026-56131 https://github.com/libexpat/libexpat/pull/1267 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56131.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Bgew407C4GMDdNe8dNeN7w==": { "id": "Bgew407C4GMDdNe8dNeN7w==", "updater": "rhel-vex", "name": "CVE-2024-52615", "description": "A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.", "issued": "2024-11-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-52615 https://bugzilla.redhat.com/show_bug.cgi?id=2326418 https://www.cve.org/CVERecord?id=CVE-2024-52615 https://nvd.nist.gov/vuln/detail/CVE-2024-52615 https://github.com/avahi/avahi/pull/577 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-52615.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "avahi", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BooDzA4nzaDI1l3E5zAHgg==": { "id": "BooDzA4nzaDI1l3E5zAHgg==", "updater": "rhel-vex", "name": "CVE-2021-3997", "description": "A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.", "issued": "2022-01-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-3997 https://bugzilla.redhat.com/show_bug.cgi?id=2024639 https://www.cve.org/CVERecord?id=CVE-2021-3997 https://nvd.nist.gov/vuln/detail/CVE-2021-3997 https://www.openwall.com/lists/oss-security/2022/01/10/2 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-3997.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CPZo3oXfySRcVVjDJkrS3g==": { "id": "CPZo3oXfySRcVVjDJkrS3g==", "updater": "rhel-vex", "name": "CVE-2019-9937", "description": "A vulnerability was found in SQLite due to a NULL pointer dereference in the fts5ChunkIterate function within sqlite3.c, where an attacker could exploit this flaw by creating a specially crafted table, causing the application to crash and resulting in a denial of service condition.", "issued": "2019-03-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-9937 https://bugzilla.redhat.com/show_bug.cgi?id=1692357 https://www.cve.org/CVERecord?id=CVE-2019-9937 https://nvd.nist.gov/vuln/detail/CVE-2019-9937 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-9937.json", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CmGl35oJyKxCfItoqDiYoQ==": { "id": "CmGl35oJyKxCfItoqDiYoQ==", "updater": "rhel-vex", "name": "CVE-2026-15588", "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.", "issued": "2026-07-12T10:10:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-15588 https://bugzilla.redhat.com/show_bug.cgi?id=2499675 https://www.cve.org/CVERecord?id=CVE-2026-15588 https://nvd.nist.gov/vuln/detail/CVE-2026-15588 https://gitlab.gnome.org/GNOME/glib/-/issues/3985 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15588.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CwmELSAfO/DM/HghGDWwow==": { "id": "CwmELSAfO/DM/HghGDWwow==", "updater": "rhel-vex", "name": "CVE-2026-6653", "description": "A flaw was found in libxml2. A remote attacker can exploit a use-after-free vulnerability in the `xmlParseInternalSubset` function by providing maliciously crafted XML input. This improper handling of entity resolution can lead to a denial-of-service (DoS), making the affected system or application unavailable.", "issued": "2026-06-22T12:40:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6653 https://bugzilla.redhat.com/show_bug.cgi?id=2491354 https://www.cve.org/CVERecord?id=CVE-2026-6653 https://nvd.nist.gov/vuln/detail/CVE-2026-6653 https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260 https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6653.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DDWmqlxBSfXi2KJJ5mwTNg==": { "id": "DDWmqlxBSfXi2KJJ5mwTNg==", "updater": "rhel-vex", "name": "CVE-2025-60753", "description": "A vulnerability in apply_substitution() function in libarchive's bsdtar allows crafted -s substitution rules to repeatedly match a zero-length substring and append replacements without advancing the input pointer. When the rule uses the global /g flag (or an explicitly empty pattern), this leads to unbounded output allocation and eventual process OOM (Denial of Service). Upgrade to libarchive 3.8.1 or apply a patch that prevents zero-length match loops or rejects empty patterns.", "issued": "2025-11-05T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-60753 https://bugzilla.redhat.com/show_bug.cgi?id=2412648 https://www.cve.org/CVERecord?id=CVE-2025-60753 https://nvd.nist.gov/vuln/detail/CVE-2025-60753 https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753 https://github.com/libarchive/libarchive/issues/2725 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-60753.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DdbtHYUAFK3EvhnE38LOBw==": { "id": "DdbtHYUAFK3EvhnE38LOBw==", "updater": "rhel-vex", "name": "CVE-2026-57062", "description": "A flaw in GnuPG's gpgsm component improperly handles the Cryptographic Message Syntax (CMS) format for AES-GCM. By accepting an authentication tag length of 4 bytes instead of the required 12 bytes, this vulnerability allows for a low-impact data integrity issue where the cryptographic validity of messages could be compromised.", "issued": "2026-06-23T17:26:25Z", "links": "https://access.redhat.com/security/cve/CVE-2026-57062 https://bugzilla.redhat.com/show_bug.cgi?id=2491859 https://www.cve.org/CVERecord?id=CVE-2026-57062 https://nvd.nist.gov/vuln/detail/CVE-2026-57062 https://blog.calif.io/p/how-to-format-a-ciphertext https://www.gnupg.org/download/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57062.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DkHpdzAuAlElCotBlgVgPA==": { "id": "DkHpdzAuAlElCotBlgVgPA==", "updater": "rhel-vex", "name": "CVE-2026-18839", "description": "An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.", "issued": "2026-08-05T18:56:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-18839 https://bugzilla.redhat.com/show_bug.cgi?id=2511010 https://www.cve.org/CVERecord?id=CVE-2026-18839 https://nvd.nist.gov/vuln/detail/CVE-2026-18839 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18839.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "popt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DoTF+GSVr6bH3qr9kb98Iw==": { "id": "DoTF+GSVr6bH3qr9kb98Iw==", "updater": "rhel-vex", "name": "CVE-2025-3360", "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.", "issued": "2025-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-3360 https://bugzilla.redhat.com/show_bug.cgi?id=2357754 https://www.cve.org/CVERecord?id=CVE-2025-3360 https://nvd.nist.gov/vuln/detail/CVE-2025-3360 https://gitlab.gnome.org/GNOME/glib/-/issues/3647 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-3360.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EKs36DFwHVCzU/cF0Be9pQ==": { "id": "EKs36DFwHVCzU/cF0Be9pQ==", "updater": "rhel-vex", "name": "CVE-2023-29499", "description": "A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.", "issued": "2022-12-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-29499 https://bugzilla.redhat.com/show_bug.cgi?id=2211828 https://www.cve.org/CVERecord?id=CVE-2023-29499 https://nvd.nist.gov/vuln/detail/CVE-2023-29499 https://gitlab.gnome.org/GNOME/glib/-/issues/2794 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-29499.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EiJx6rOT8KoLX+Wu7/N6HQ==": { "id": "EiJx6rOT8KoLX+Wu7/N6HQ==", "updater": "rhel-vex", "name": "CVE-2025-27113", "description": "A flaw was found in libxml2. This vulnerability allows a NULL pointer dereference, leading to a potential crash or denial of service via a crafted XML pattern.", "issued": "2025-02-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-27113 https://bugzilla.redhat.com/show_bug.cgi?id=2346410 https://www.cve.org/CVERecord?id=CVE-2025-27113 https://nvd.nist.gov/vuln/detail/CVE-2025-27113 https://gitlab.gnome.org/GNOME/libxml2/-/issues/861 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-27113.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EiL50P2QSOoRA18XAAH6Pg==": { "id": "EiL50P2QSOoRA18XAAH6Pg==", "updater": "rhel-vex", "name": "CVE-2023-32665", "description": "A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.", "issued": "2022-12-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-32665 https://bugzilla.redhat.com/show_bug.cgi?id=2211827 https://www.cve.org/CVERecord?id=CVE-2023-32665 https://nvd.nist.gov/vuln/detail/CVE-2023-32665 https://gitlab.gnome.org/GNOME/glib/-/issues/2121 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-32665.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ElIjMFAz33tt/XVMysRkdA==": { "id": "ElIjMFAz33tt/XVMysRkdA==", "updater": "rhel-vex", "name": "CVE-2026-0988", "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0988 https://bugzilla.redhat.com/show_bug.cgi?id=2429886 https://www.cve.org/CVERecord?id=CVE-2026-0988 https://nvd.nist.gov/vuln/detail/CVE-2026-0988 https://gitlab.gnome.org/GNOME/glib/-/issues/3851 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0988.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EpK5bQtJedMNlT+XQ842nA==": { "id": "EpK5bQtJedMNlT+XQ842nA==", "updater": "rhel-vex", "name": "CVE-2026-56404", "description": "A flaw was found in libexpat. This vulnerability, an integer overflow in the `addBinding` function, could allow a local attacker to execute arbitrary code. By exploiting this, an attacker could gain control over the affected system, compromising its confidentiality and integrity.", "issued": "2026-06-21T15:45:55Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56404 https://bugzilla.redhat.com/show_bug.cgi?id=2491185 https://www.cve.org/CVERecord?id=CVE-2026-56404 https://nvd.nist.gov/vuln/detail/CVE-2026-56404 https://github.com/libexpat/libexpat/pull/1249 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56404.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "F0n/1XXyzTob8lElmXmB6g==": { "id": "F0n/1XXyzTob8lElmXmB6g==", "updater": "rhel-vex", "name": "CVE-2026-16517", "description": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.", "issued": "2026-07-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-16517 https://bugzilla.redhat.com/show_bug.cgi?id=2505492 https://www.cve.org/CVERecord?id=CVE-2026-16517 https://nvd.nist.gov/vuln/detail/CVE-2026-16517 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16517.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "F2aHNsZ7wIxMKRFoRhLULQ==": { "id": "F2aHNsZ7wIxMKRFoRhLULQ==", "updater": "rhel-vex", "name": "CVE-2026-9076", "description": "A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9076 https://bugzilla.redhat.com/show_bug.cgi?id=2481880 https://www.cve.org/CVERecord?id=CVE-2026-9076 https://nvd.nist.gov/vuln/detail/CVE-2026-9076 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9076.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Fd2ov7jSJY3Im+378GMgdA==": { "id": "Fd2ov7jSJY3Im+378GMgdA==", "updater": "rhel-vex", "name": "CVE-2026-7210", "description": "A flaw was found in the `python` and `expat` components. Insufficient entropy in the hash-flooding protection mechanism of `xml.parsers.expat` and `xml.etree.ElementTree` allows a remote attacker to craft a malicious XML document. This crafted document can trigger a hash flooding attack, leading to a denial of service (DoS) condition.", "issued": "2026-05-11T17:19:09Z", "links": "https://access.redhat.com/security/cve/CVE-2026-7210 https://bugzilla.redhat.com/show_bug.cgi?id=2469216 https://www.cve.org/CVERecord?id=CVE-2026-7210 https://nvd.nist.gov/vuln/detail/CVE-2026-7210 https://github.com/python/cpython/issues/149018 https://github.com/python/cpython/pull/149023 https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7210.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FkRDB0vpJYeh2ipqLS0/Iw==": { "id": "FkRDB0vpJYeh2ipqLS0/Iw==", "updater": "rhel-vex", "name": "CVE-2025-28164", "description": "A flaw was found in libpng. This buffer overflow vulnerability allows a local attacker to cause a denial of service (DoS) by exploiting the `png_create_read_struct()` function. This can lead to the affected system becoming unresponsive or crashing.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-28164 https://bugzilla.redhat.com/show_bug.cgi?id=2433398 https://www.cve.org/CVERecord?id=CVE-2025-28164 https://nvd.nist.gov/vuln/detail/CVE-2025-28164 https://gist.github.com/kittener/506516f8c22178005b4379c8b2a7de20 https://github.com/pnggroup/libpng/issues/655 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-28164.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "java-17-openjdk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Fp999hDC/lucBsNHwOlp/A==": { "id": "Fp999hDC/lucBsNHwOlp/A==", "updater": "rhel-vex", "name": "CVE-2024-13176", "description": "A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected.", "issued": "2025-01-20T13:29:57Z", "links": "https://access.redhat.com/security/cve/CVE-2024-13176 https://bugzilla.redhat.com/show_bug.cgi?id=2338999 https://www.cve.org/CVERecord?id=CVE-2024-13176 https://nvd.nist.gov/vuln/detail/CVE-2024-13176 https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-13176.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "G2Djh6mj4eOKfpIiPPuLew==": { "id": "G2Djh6mj4eOKfpIiPPuLew==", "updater": "rhel-vex", "name": "CVE-2026-15028", "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.", "issued": "2026-07-08T10:10:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-15028 https://bugzilla.redhat.com/show_bug.cgi?id=2497970 https://www.cve.org/CVERecord?id=CVE-2026-15028 https://nvd.nist.gov/vuln/detail/CVE-2026-15028 https://github.com/libarchive/libarchive/issues/3251 https://github.com/libarchive/libarchive/pull/3253 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15028.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "G7IyfoPhe9f8QzIGbOfn7Q==": { "id": "G7IyfoPhe9f8QzIGbOfn7Q==", "updater": "rhel-vex", "name": "CVE-2023-45322", "description": "A flaw was found in libxml2. In an out-of-memory condition or when limiting the memory allocation, processing a XML document using the HTML parser may result in a use-after-free vulnerability.", "issued": "2023-08-23T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-45322 https://bugzilla.redhat.com/show_bug.cgi?id=2242945 https://www.cve.org/CVERecord?id=CVE-2023-45322 https://nvd.nist.gov/vuln/detail/CVE-2023-45322 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-45322.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GWg5WOvOqfRt4sWhRhSM+A==": { "id": "GWg5WOvOqfRt4sWhRhSM+A==", "updater": "rhel-vex", "name": "CVE-2026-58014", "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58014 https://bugzilla.redhat.com/show_bug.cgi?id=2492255 https://www.cve.org/CVERecord?id=CVE-2026-58014 https://nvd.nist.gov/vuln/detail/CVE-2026-58014 https://gitlab.gnome.org/GNOME/glib/-/issues/3930 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58014.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GY12kVf6J5Mt34JLrWLJkw==": { "id": "GY12kVf6J5Mt34JLrWLJkw==", "updater": "rhel-vex", "name": "CVE-2026-50219", "description": "A flaw was found in libexpat. This vulnerability occurs because the library, in versions before 2.8.2, does not properly track handler call depth when certain XML parsing functions are invoked from within handlers during a policy violation. This oversight can lead to a use-after-free condition, which may result in information disclosure, integrity loss, or denial of service.", "issued": "2026-06-04T04:20:32Z", "links": "https://access.redhat.com/security/cve/CVE-2026-50219 https://bugzilla.redhat.com/show_bug.cgi?id=2484620 https://www.cve.org/CVERecord?id=CVE-2026-50219 https://nvd.nist.gov/vuln/detail/CVE-2026-50219 https://github.com/libexpat/libexpat/pull/1246 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50219.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "H9Ud41wofJc/QlL6Rm7WkA==": { "id": "H9Ud41wofJc/QlL6Rm7WkA==", "updater": "rhel-vex", "name": "CVE-2026-0968", "description": "A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.", "issued": "2026-02-10T18:46:58Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0968 https://bugzilla.redhat.com/show_bug.cgi?id=2436982 https://www.cve.org/CVERecord?id=CVE-2026-0968 https://nvd.nist.gov/vuln/detail/CVE-2026-0968 https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0968.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HB9r/GLycEmk6aXttwtBlw==": { "id": "HB9r/GLycEmk6aXttwtBlw==", "updater": "rhel-vex", "name": "CVE-2025-11468", "description": "Missing character filtering has been discovered in Python. When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.", "issued": "2026-01-20T21:09:11Z", "links": "https://access.redhat.com/security/cve/CVE-2025-11468 https://bugzilla.redhat.com/show_bug.cgi?id=2431375 https://www.cve.org/CVERecord?id=CVE-2025-11468 https://nvd.nist.gov/vuln/detail/CVE-2025-11468 https://github.com/python/cpython/issues/143935 https://github.com/python/cpython/pull/143936 https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11468.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HDr4rB3dwHneK78KvohfHQ==": { "id": "HDr4rB3dwHneK78KvohfHQ==", "updater": "rhel-vex", "name": "CVE-2026-34180", "description": "A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34180 https://bugzilla.redhat.com/show_bug.cgi?id=2481881 https://www.cve.org/CVERecord?id=CVE-2026-34180 https://nvd.nist.gov/vuln/detail/CVE-2026-34180 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34180.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HKrLnQyTw1292mNt3MQ0aQ==": { "id": "HKrLnQyTw1292mNt3MQ0aQ==", "updater": "rhel-vex", "name": "CVE-2024-7592", "description": "A flaw was found in the `http.cookies` module in the Python package. When parsing cookies that contain backslashes, under certain circumstances, the module uses an algorithm with quadratic complexity, leading to excessive CPU consumption.", "issued": "2024-08-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-7592 https://bugzilla.redhat.com/show_bug.cgi?id=2305879 https://www.cve.org/CVERecord?id=CVE-2024-7592 https://nvd.nist.gov/vuln/detail/CVE-2024-7592 https://github.com/python/cpython/issues/123067 https://github.com/python/cpython/pull/123075 https://mail.python.org/archives/list/security-announce@python.org/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-7592.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HNpGGr9eP5twQKC3yCh1mA==": { "id": "HNpGGr9eP5twQKC3yCh1mA==", "updater": "rhel-vex", "name": "CVE-2025-5915", "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5915 https://bugzilla.redhat.com/show_bug.cgi?id=2370865 https://www.cve.org/CVERecord?id=CVE-2025-5915 https://nvd.nist.gov/vuln/detail/CVE-2025-5915 https://github.com/libarchive/libarchive/pull/2599 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5915.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HTk+AAyRWNCrZTtBLx34Aw==": { "id": "HTk+AAyRWNCrZTtBLx34Aw==", "updater": "rhel-vex", "name": "CVE-2024-25260", "description": "A NULL pointer dereference vulnerability in the elfutils library has been discovered. This vulnerability occurs within the handle_verdef() function in the readelf.c source file. A NULL pointer dereference typically happens when a program attempts to access memory using a pointer that is not pointing anywhere (i.e., it's NULL), leading to a crash or potentially exploitable behavior.", "issued": "2024-02-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-25260 https://bugzilla.redhat.com/show_bug.cgi?id=2265194 https://www.cve.org/CVERecord?id=CVE-2024-25260 https://nvd.nist.gov/vuln/detail/CVE-2024-25260 https://github.com/schsiung/fuzzer_issues/issues/1 https://sourceware.org/bugzilla/show_bug.cgi?id=31058 https://sourceware.org/elfutils/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-25260.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "elfutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HdAyLUATPStr/HXiy9fgQw==": { "id": "HdAyLUATPStr/HXiy9fgQw==", "updater": "rhel-vex", "name": "CVE-2026-0990", "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0990 https://bugzilla.redhat.com/show_bug.cgi?id=2429959 https://www.cve.org/CVERecord?id=CVE-2026-0990 https://nvd.nist.gov/vuln/detail/CVE-2026-0990 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0990.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HuLJLN6ajygY/CpLyzV5lw==": { "id": "HuLJLN6ajygY/CpLyzV5lw==", "updater": "rhel-vex", "name": "CVE-2023-45803", "description": "A flaw was found in urllib3, an HTTP client library for Python. urllib3 doesn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303, after changing the method in a request from one that could accept a request body such as `POST` to `GET`, as is required by HTTP RFCs. This issue requires a previously trusted service to become compromised in order to have an impact on confidentiality, therefore, the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies; if this is the case, this vulnerability isn't exploitable.", "issued": "2023-10-13T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-45803 https://bugzilla.redhat.com/show_bug.cgi?id=2246840 https://www.cve.org/CVERecord?id=CVE-2023-45803 https://nvd.nist.gov/vuln/detail/CVE-2023-45803 https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9 https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4 https://www.rfc-editor.org/rfc/rfc9110.html#name-get https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-45803.json", "severity": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python-pip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HuOxI+pWjgGV0XsBvltzlg==": { "id": "HuOxI+pWjgGV0XsBvltzlg==", "updater": "rhel-vex", "name": "CVE-2020-19187", "description": "A flaw was found in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash, leading to a denial of service.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19187 https://bugzilla.redhat.com/show_bug.cgi?id=2234911 https://www.cve.org/CVERecord?id=CVE-2020-19187 https://nvd.nist.gov/vuln/detail/CVE-2020-19187 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19187.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IItHEdPWz5fl9O7ZhzjDAA==": { "id": "IItHEdPWz5fl9O7ZhzjDAA==", "updater": "rhel-vex", "name": "CVE-2026-0672", "description": "An injection flaw has been discovered in Python. When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.", "issued": "2026-01-20T21:52:33Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0672 https://bugzilla.redhat.com/show_bug.cgi?id=2431374 https://www.cve.org/CVERecord?id=CVE-2026-0672 https://nvd.nist.gov/vuln/detail/CVE-2026-0672 https://github.com/python/cpython/issues/143919 https://github.com/python/cpython/pull/143920 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0672.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ig/iNncFD4P4EYoOu9TAeQ==": { "id": "Ig/iNncFD4P4EYoOu9TAeQ==", "updater": "rhel-vex", "name": "CVE-2026-59843", "description": "A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.", "issued": "2026-07-21T11:07:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59843 https://bugzilla.redhat.com/show_bug.cgi?id=2498176 https://www.cve.org/CVERecord?id=CVE-2026-59843 https://nvd.nist.gov/vuln/detail/CVE-2026-59843 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59843.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "J0YQQx6sv/Elt2kRDVPlXg==": { "id": "J0YQQx6sv/Elt2kRDVPlXg==", "updater": "rhel-vex", "name": "CVE-2026-8458", "description": "A flaw was found in libcurl. A logical error in the connection pooling mechanism may cause libcurl to reuse an authenticated connection for an unintended service. This could allow an application to wrongfully reuse an existing connection to the same server that was authenticated for a different service, potentially leading to unauthorized access or information disclosure.", "issued": "2026-07-03T06:14:42Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8458 https://bugzilla.redhat.com/show_bug.cgi?id=2496764 https://www.cve.org/CVERecord?id=CVE-2026-8458 https://nvd.nist.gov/vuln/detail/CVE-2026-8458 https://curl.se/docs/CVE-2026-8458.html https://curl.se/docs/CVE-2026-8458.json https://hackerone.com/reports/3721183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8458.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "K3eafQ/8P8PEZ3BPWZfCgg==": { "id": "K3eafQ/8P8PEZ3BPWZfCgg==", "updater": "rhel-vex", "name": "CVE-2026-27447", "description": "A flaw was found in OpenPrinting CUPS. This authorization bypass vulnerability allows an unprivileged user to gain unauthorized access to restricted operations. This can be exploited by using a username that differs only in case from an authorized user during authorization checks.", "issued": "2026-04-03T21:11:59Z", "links": "https://access.redhat.com/security/cve/CVE-2026-27447 https://bugzilla.redhat.com/show_bug.cgi?id=2454949 https://www.cve.org/CVERecord?id=CVE-2026-27447 https://nvd.nist.gov/vuln/detail/CVE-2026-27447 https://github.com/OpenPrinting/cups/commit/88516bf6d9e34cef7a64a704b856b837f70cd220 https://github.com/OpenPrinting/cups/security/advisories/GHSA-v987-m8hp-phj9 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27447.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "cups", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KCgCqCavM9U0xL+GHJqzSg==": { "id": "KCgCqCavM9U0xL+GHJqzSg==", "updater": "rhel-vex", "name": "CVE-2026-0964", "description": "A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\n\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111.", "issued": "2026-02-10T18:44:42Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0964 https://bugzilla.redhat.com/show_bug.cgi?id=2436979 https://www.cve.org/CVERecord?id=CVE-2026-0964 https://nvd.nist.gov/vuln/detail/CVE-2026-0964 https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0964.json", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KExChYIaW0MvXNLWbjS/Hw==": { "id": "KExChYIaW0MvXNLWbjS/Hw==", "updater": "rhel-vex", "name": "CVE-2026-41080", "description": "A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing a specially crafted XML document that leverages insufficient entropy in the hash function. This can lead to hash flooding, a type of Denial of Service (DoS) attack, where the system becomes unresponsive or crashes due to excessive resource consumption.", "issued": "2026-04-16T16:52:01Z", "links": "https://access.redhat.com/security/cve/CVE-2026-41080 https://bugzilla.redhat.com/show_bug.cgi?id=2458967 https://www.cve.org/CVERecord?id=CVE-2026-41080 https://nvd.nist.gov/vuln/detail/CVE-2026-41080 https://github.com/libexpat/libexpat/issues/47 https://github.com/libexpat/libexpat/pull/1183 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41080.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KaROgE0QmtiOixMG9Wi1RA==": { "id": "KaROgE0QmtiOixMG9Wi1RA==", "updater": "rhel-vex", "name": "CVE-2023-32636", "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.", "issued": "2022-12-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-32636 https://bugzilla.redhat.com/show_bug.cgi?id=2211833 https://www.cve.org/CVERecord?id=CVE-2023-32636 https://nvd.nist.gov/vuln/detail/CVE-2023-32636 https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835 https://gitlab.gnome.org/GNOME/glib/-/issues/2841 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-32636.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "L3k0cIIlkMGQFiWnZm8Mlg==": { "id": "L3k0cIIlkMGQFiWnZm8Mlg==", "updater": "rhel-vex", "name": "CVE-2025-12781", "description": "A flaw was found in the base64 module in the Python standard library. The b64decode, standard_b64decode and urlsafe_b64decode functions will always accept the '+' and '/' characters even when an alternative base64 alphabet is specified via the altchars parameter that excludes them. This input validation bypass allows malformed or unexpected data to pass through decoding filters, potentially causing logical errors or data integrity issues in applications relying on strict character sets.", "issued": "2026-01-21T19:34:47Z", "links": "https://access.redhat.com/security/cve/CVE-2025-12781 https://bugzilla.redhat.com/show_bug.cgi?id=2431736 https://www.cve.org/CVERecord?id=CVE-2025-12781 https://nvd.nist.gov/vuln/detail/CVE-2025-12781 https://github.com/python/cpython/issues/125346 https://github.com/python/cpython/pull/141128 https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-12781.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "L7QbkTbsy8v3tMfOqNsVKQ==": { "id": "L7QbkTbsy8v3tMfOqNsVKQ==", "updater": "rhel-vex", "name": "CVE-2024-7531", "description": "The Mozilla Foundation Security Advisory describes this flaw as:\n\nCalling PK11_Encrypt() in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on Intel Sandy Bridge and later processors. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change.", "issued": "2024-08-06T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-7531 https://bugzilla.redhat.com/show_bug.cgi?id=2303148 https://www.cve.org/CVERecord?id=CVE-2024-7531 https://nvd.nist.gov/vuln/detail/CVE-2024-7531 https://www.mozilla.org/en-US/security/advisories/mfsa2024-34/#CVE-2024-7531 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-7531.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "nss", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LTmcTrhW8bJGvJXJVPjm/g==": { "id": "LTmcTrhW8bJGvJXJVPjm/g==", "updater": "rhel-vex", "name": "CVE-2026-24515", "description": "A null pointer dereference flaw has been discovered in libexpat. The function `XML_ExternalEntityParserCreate` failed to copy the encoding handler data passed to XML_SetUnknownEncodingHandler from the parent to the new subparser. This can cause a NULL dereference from external entities that declare use of an unknown encoding. The expected impact is denial of service. It takes use of both functions `XML_ExternalEntityParserCreate` and `XML_SetUnknownEncodingHandler` for an application to be vulnerable.", "issued": "2026-01-23T07:46:36Z", "links": "https://access.redhat.com/security/cve/CVE-2026-24515 https://bugzilla.redhat.com/show_bug.cgi?id=2432312 https://www.cve.org/CVERecord?id=CVE-2026-24515 https://nvd.nist.gov/vuln/detail/CVE-2026-24515 https://github.com/libexpat/libexpat/pull/1131 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24515.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LWLSX4FCLbzYWK97i5Or+A==": { "id": "LWLSX4FCLbzYWK97i5Or+A==", "updater": "rhel-vex", "name": "CVE-2026-28389", "description": "A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-28389 https://bugzilla.redhat.com/show_bug.cgi?id=2451096 https://www.cve.org/CVERecord?id=CVE-2026-28389 https://nvd.nist.gov/vuln/detail/CVE-2026-28389 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28389.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Lt2Hg7sVYgz0GD7ldFmjjA==": { "id": "Lt2Hg7sVYgz0GD7ldFmjjA==", "updater": "rhel-vex", "name": "CVE-2026-32777", "description": "A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted Document Type Definition (DTD) content. This could lead to an infinite loop during parsing, resulting in a Denial of Service (DoS) for the application using libexpat.", "issued": "2026-03-16T06:58:06Z", "links": "https://access.redhat.com/security/cve/CVE-2026-32777 https://bugzilla.redhat.com/show_bug.cgi?id=2447890 https://www.cve.org/CVERecord?id=CVE-2026-32777 https://nvd.nist.gov/vuln/detail/CVE-2026-32777 https://github.com/libexpat/libexpat/issues/1161 https://github.com/libexpat/libexpat/pull/1159 https://github.com/libexpat/libexpat/pull/1162 https://issues.oss-fuzz.com/issues/486993411 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32777.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "M59UwDbs3+/LtSu1P1x+Rg==": { "id": "M59UwDbs3+/LtSu1P1x+Rg==", "updater": "rhel-vex", "name": "CVE-2026-9149", "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).", "issued": "2026-05-20T22:19:32Z", "links": "https://access.redhat.com/security/cve/CVE-2026-9149 https://bugzilla.redhat.com/show_bug.cgi?id=2460380 https://www.cve.org/CVERecord?id=CVE-2026-9149 https://nvd.nist.gov/vuln/detail/CVE-2026-9149 https://github.com/openSUSE/libsolv/pull/617 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9149.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libsolv", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MW3KGjkk7BWuR5JCc6cywg==": { "id": "MW3KGjkk7BWuR5JCc6cywg==", "updater": "rhel-vex", "name": "CVE-2024-52616", "description": "A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.", "issued": "2024-11-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-52616 https://bugzilla.redhat.com/show_bug.cgi?id=2326429 https://www.cve.org/CVERecord?id=CVE-2024-52616 https://nvd.nist.gov/vuln/detail/CVE-2024-52616 https://github.com/avahi/avahi/pull/577 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-52616.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "avahi", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NZdLkPGdPGyb8ltD0LX9SQ==": { "id": "NZdLkPGdPGyb8ltD0LX9SQ==", "updater": "rhel-vex", "name": "CVE-2017-6519", "description": "A vulnerability was found in Avahi, where the avahi-daemon improperly handles responses to IPv6 unicast queries, a remote attacker could exploit this flaw by sending specially crafted port-5353 UDP packets, potentially causing a denial of service (traffic amplification) or leaking sensitive information.", "issued": "2015-03-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2017-6519 https://bugzilla.redhat.com/show_bug.cgi?id=1426712 https://www.cve.org/CVERecord?id=CVE-2017-6519 https://nvd.nist.gov/vuln/detail/CVE-2017-6519 https://www.kb.cert.org/vuls/id/550620 https://security.access.redhat.com/data/csaf/v2/vex/2017/cve-2017-6519.json", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "avahi", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O0WA+v5udE7etzYMGY4hKQ==": { "id": "O0WA+v5udE7etzYMGY4hKQ==", "updater": "rhel-vex", "name": "CVE-2025-45582", "description": "A flaw was found in GNU Tar. An attacker could exploit this vulnerability by providing two specially crafted TAR archives, if those archives were extracted in the same directory. The first archive contains a symbolic link that points to a critical directory. The second archive, when extracted, uses this symbolic link to overwrite sensitive files on the system, bypassing existing directory traversal protections. This could lead to unauthorized file modification or, in some cases, privilege escalation.", "issued": "2025-07-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-45582 https://bugzilla.redhat.com/show_bug.cgi?id=2379592 https://www.cve.org/CVERecord?id=CVE-2025-45582 https://nvd.nist.gov/vuln/detail/CVE-2025-45582 https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md https://www.gnu.org/software/tar/ https://www.gnu.org/software/tar/manual/html_node/Integrity.html#Integrity https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-45582.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O8fIVXqcGshIonMWsEH9gA==": { "id": "O8fIVXqcGshIonMWsEH9gA==", "updater": "rhel-vex", "name": "CVE-2025-5916", "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5916 https://bugzilla.redhat.com/show_bug.cgi?id=2370872 https://www.cve.org/CVERecord?id=CVE-2025-5916 https://nvd.nist.gov/vuln/detail/CVE-2025-5916 https://github.com/libarchive/libarchive/pull/2568 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5916.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OFdQC3/0S5rItoyqpACTFw==": { "id": "OFdQC3/0S5rItoyqpACTFw==", "updater": "rhel-vex", "name": "CVE-2026-4224", "description": "A stack overflow flaw has been discovered in the python pyexpat module. When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. This will result in a program crash.", "issued": "2026-03-16T17:52:26Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4224 https://bugzilla.redhat.com/show_bug.cgi?id=2448181 https://www.cve.org/CVERecord?id=CVE-2026-4224 https://nvd.nist.gov/vuln/detail/CVE-2026-4224 https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3 https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768 https://github.com/python/cpython/issues/145986 https://github.com/python/cpython/pull/145987 https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4224.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OLKvdPVgT9/lPcflJTxE3Q==": { "id": "OLKvdPVgT9/lPcflJTxE3Q==", "updater": "rhel-vex", "name": "CVE-2025-68160", "description": "A flaw was found in OpenSSL. This vulnerability involves an out-of-bounds write in the line-buffering BIO filter, which can lead to memory corruption. While exploitation is unlikely to be under direct attacker control, a successful attack could cause an application to crash, resulting in a Denial of Service (DoS).", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-68160 https://bugzilla.redhat.com/show_bug.cgi?id=2430380 https://www.cve.org/CVERecord?id=CVE-2025-68160 https://nvd.nist.gov/vuln/detail/CVE-2025-68160 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68160.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OPNDKUsVLJt2v1gO1zvkBA==": { "id": "OPNDKUsVLJt2v1gO1zvkBA==", "updater": "rhel-vex", "name": "CVE-2025-1632", "description": "A flaw was found in the bsdunzip utility of libarchive. In affected versions, a specially crafted file may trigger a null pointer dereference. This issue can lead to an application crash or other unexpected behavior. This bug does not compromise the integrity or availability of the base system.", "issued": "2025-02-24T13:31:08Z", "links": "https://access.redhat.com/security/cve/CVE-2025-1632 https://bugzilla.redhat.com/show_bug.cgi?id=2347309 https://www.cve.org/CVERecord?id=CVE-2025-1632 https://nvd.nist.gov/vuln/detail/CVE-2025-1632 https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc https://vuldb.com/?ctiid.296619 https://vuldb.com/?id.296619 https://vuldb.com/?submit.496460 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1632.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OgFGrvrnAoXXvapnatTrxQ==": { "id": "OgFGrvrnAoXXvapnatTrxQ==", "updater": "rhel-vex", "name": "CVE-2026-0965", "description": "A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.", "issued": "2026-02-10T18:47:22Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0965 https://bugzilla.redhat.com/show_bug.cgi?id=2436980 https://www.cve.org/CVERecord?id=CVE-2026-0965 https://nvd.nist.gov/vuln/detail/CVE-2026-0965 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0965.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OpUahpCA4oBceG962KxTMA==": { "id": "OpUahpCA4oBceG962KxTMA==", "updater": "rhel-vex", "name": "CVE-2026-22796", "description": "A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a denial of service (DoS) by providing specially crafted PKCS#7 data to an application that performs signature verification. The vulnerability occurs because the application accesses an ASN1_TYPE union member without proper type validation, leading to an invalid or NULL pointer dereference and a crash.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-22796 https://bugzilla.redhat.com/show_bug.cgi?id=2430390 https://www.cve.org/CVERecord?id=CVE-2026-22796 https://nvd.nist.gov/vuln/detail/CVE-2026-22796 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22796.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PRkbEOx7V6ePRT/WUyklHg==": { "id": "PRkbEOx7V6ePRT/WUyklHg==", "updater": "rhel-vex", "name": "CVE-2026-8927", "description": "A flaw was found in libcurl. When reusing a libcurl handle for sequential transfers with environment-variable proxy configuration, the library does not properly clear the proxy authentication state. This oversight can lead to the unintended disclosure of `Proxy-Authorization` headers to an incorrect proxy, potentially exposing sensitive authentication information to an unauthorized entity. This is an information disclosure vulnerability.", "issued": "2026-07-03T06:16:06Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8927 https://bugzilla.redhat.com/show_bug.cgi?id=2496769 https://www.cve.org/CVERecord?id=CVE-2026-8927 https://nvd.nist.gov/vuln/detail/CVE-2026-8927 https://curl.se/docs/CVE-2026-8927.html https://curl.se/docs/CVE-2026-8927.json https://hackerone.com/reports/3744543 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8927.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "High", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PcNbuWOo0ahqjfbOQhXvvQ==": { "id": "PcNbuWOo0ahqjfbOQhXvvQ==", "updater": "rhel-vex", "name": "CVE-2024-41996", "description": "A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations.", "issued": "2024-08-26T06:15:04Z", "links": "https://access.redhat.com/security/cve/CVE-2024-41996 https://bugzilla.redhat.com/show_bug.cgi?id=2307826 https://www.cve.org/CVERecord?id=CVE-2024-41996 https://nvd.nist.gov/vuln/detail/CVE-2024-41996 https://dheatattack.gitlab.io/details/ https://dheatattack.gitlab.io/faq/ https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1 https://github.com/openssl/openssl/issues/17374 https://openssl-library.org/post/2022-10-21-tls-groups-configuration/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-41996.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Pe4IHqZpuBtuSkrgd2HMEg==": { "id": "Pe4IHqZpuBtuSkrgd2HMEg==", "updater": "rhel-vex", "name": "CVE-2025-13034", "description": "A flaw was found in curl. When configured to use public key pinning with QUIC connections and GnuTLS, and with standard certificate verification explicitly disabled, curl could bypass the intended public key check. This oversight allows a malicious server to impersonate a legitimate one, potentially leading to unauthorized access or information disclosure due to a failure in verifying the server's identity.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-13034 https://bugzilla.redhat.com/show_bug.cgi?id=2426406 https://www.cve.org/CVERecord?id=CVE-2025-13034 https://nvd.nist.gov/vuln/detail/CVE-2025-13034 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13034.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Q5xJp4zJ1MCYcYbDi9qrdQ==": { "id": "Q5xJp4zJ1MCYcYbDi9qrdQ==", "updater": "rhel-vex", "name": "CVE-2026-25068", "description": "alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.", "issued": "2026-01-29T19:08:03Z", "links": "https://access.redhat.com/security/cve/CVE-2026-25068 https://bugzilla.redhat.com/show_bug.cgi?id=2435372 https://www.cve.org/CVERecord?id=CVE-2026-25068 https://nvd.nist.gov/vuln/detail/CVE-2026-25068 https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40 https://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25068.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "alsa-lib", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QSNBg/XspHcBwSxBTMU4rg==": { "id": "QSNBg/XspHcBwSxBTMU4rg==", "updater": "rhel-vex", "name": "CVE-2025-50181", "description": "A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration to manipulate request flows and disrupt service. This bypass occurs through improper handling of retry parameters during PoolManager instantiation. This issue can reult in a denial of service or unintended data exposure due to altered request destinations.", "issued": "2025-06-19T01:08:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-50181 https://bugzilla.redhat.com/show_bug.cgi?id=2373799 https://www.cve.org/CVERecord?id=CVE-2025-50181 https://nvd.nist.gov/vuln/detail/CVE-2025-50181 https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857 https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-50181.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python-pip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QUtTYJuHdkAOgtveagWUfA==": { "id": "QUtTYJuHdkAOgtveagWUfA==", "updater": "rhel-vex", "name": "CVE-2023-0466", "description": "A flaw was found in OpenSSL. The X509_VERIFY_PARAM_add0_policy() function is documented to enable the certificate policy check when doing certificate verification implicitly. However, implementing the function does not enable the check, allowing certificates with invalid or incorrect policies to pass the certificate verification. Suddenly enabling the policy check could break existing deployments, so it was decided to keep the existing behavior of the X509_VERIFY_PARAM_add0_policy() function. The applications that require OpenSSL to perform certificate policy check need to use X509_VERIFY_PARAM_set1_policies() or explicitly enable the policy check by calling X509_VERIFY_PARAM_set_flags() with the X509_V_FLAG_POLICY_CHECK flag argument. Certificate policy checks are disabled by default in OpenSSL and are not commonly used by applications.", "issued": "2023-03-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-0466 https://bugzilla.redhat.com/show_bug.cgi?id=2182565 https://www.cve.org/CVERecord?id=CVE-2023-0466 https://nvd.nist.gov/vuln/detail/CVE-2023-0466 https://www.openssl.org/news/secadv/20230328.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0466.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QwBnC+2unbl7BaURui6Tng==": { "id": "QwBnC+2unbl7BaURui6Tng==", "updater": "rhel-vex", "name": "CVE-2026-3832", "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.", "issued": "2026-04-30T17:29:25Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3832 https://bugzilla.redhat.com/show_bug.cgi?id=2445762 https://www.cve.org/CVERecord?id=CVE-2026-3832 https://nvd.nist.gov/vuln/detail/CVE-2026-3832 https://gitlab.com/gnutls/gnutls/-/issues/1801 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3832.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "gnutls", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R0kLLh/19P/mLd+t6ufaFg==": { "id": "R0kLLh/19P/mLd+t6ufaFg==", "updater": "rhel-vex", "name": "CVE-2026-40553", "description": "A flaw was found in gawk. A buffer overflow vulnerability exists in the `ftype()` routine, located in the `extension/readdir.c` program file. This vulnerability could allow an attacker to crash the program, resulting in a denial of service. It may also potentially lead to arbitrary code execution, though this has not been definitively confirmed.", "issued": "2026-07-13T12:07:56Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40553 https://bugzilla.redhat.com/show_bug.cgi?id=2499657 https://www.cve.org/CVERecord?id=CVE-2026-40553 https://nvd.nist.gov/vuln/detail/CVE-2026-40553 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40553.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R90VfdEewbj2ZB0bKqbhNA==": { "id": "R90VfdEewbj2ZB0bKqbhNA==", "updater": "rhel-vex", "name": "CVE-2026-0966", "description": "A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.", "issued": "2026-02-10T18:47:15Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0966 https://bugzilla.redhat.com/show_bug.cgi?id=2433121 https://www.cve.org/CVERecord?id=CVE-2026-0966 https://nvd.nist.gov/vuln/detail/CVE-2026-0966 https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0966.json", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RVCidRUm4D1IKoPhoUi2AA==": { "id": "RVCidRUm4D1IKoPhoUi2AA==", "updater": "rhel-vex", "name": "CVE-2019-9674", "description": "A ZIP bomb attack was found in the Python zipfile module. A remote attacker could abuse this flaw by providing a specially crafted ZIP file that, when decompressed by zipfile, would exhaust system resources resulting in a denial of service.", "issued": "2019-03-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-9674 https://bugzilla.redhat.com/show_bug.cgi?id=1800749 https://www.cve.org/CVERecord?id=CVE-2019-9674 https://nvd.nist.gov/vuln/detail/CVE-2019-9674 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-9674.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RXjd5U95osIGXnqCa34Jkg==": { "id": "RXjd5U95osIGXnqCa34Jkg==", "updater": "rhel-vex", "name": "CVE-2026-0989", "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested \u003cinclude\u003e directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0989 https://bugzilla.redhat.com/show_bug.cgi?id=2429933 https://www.cve.org/CVERecord?id=CVE-2026-0989 https://nvd.nist.gov/vuln/detail/CVE-2026-0989 https://gitlab.gnome.org/GNOME/libxml2/-/issues/998 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0989.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RYqFgDYIttLgJc8B82sK/w==": { "id": "RYqFgDYIttLgJc8B82sK/w==", "updater": "rhel-vex", "name": "CVE-2025-66382", "description": "A flaw was found in libexpat. This vulnerability allows a denial of service (DoS) by processing a crafted file with an approximate size of 2 MiB, leading to dozens of seconds of processing time.", "issued": "2025-11-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-66382 https://bugzilla.redhat.com/show_bug.cgi?id=2417661 https://www.cve.org/CVERecord?id=CVE-2025-66382 https://nvd.nist.gov/vuln/detail/CVE-2025-66382 https://github.com/libexpat/libexpat/issues/1076 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66382.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RdjNn4dAdZKcn6VS95a/SQ==": { "id": "RdjNn4dAdZKcn6VS95a/SQ==", "updater": "rhel-vex", "name": "CVE-2026-39314", "description": "A flaw was found in CUPS, an open-source printing system. An unprivileged local user can exploit an integer underflow vulnerability by providing a negative job-password-supported Internet Printing Protocol (IPP) attribute. This manipulation causes the cupsd root process to crash, which can be repeatedly triggered to achieve a sustained Denial of Service (DoS) on the system.", "issued": "2026-04-07T16:59:23Z", "links": "https://access.redhat.com/security/cve/CVE-2026-39314 https://bugzilla.redhat.com/show_bug.cgi?id=2456107 https://www.cve.org/CVERecord?id=CVE-2026-39314 https://nvd.nist.gov/vuln/detail/CVE-2026-39314 https://github.com/OpenPrinting/cups/security/advisories/GHSA-pp8w-2g52-7vj7 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39314.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "cups", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Rfm1tD+QxSP/TVjKFDNabg==": { "id": "Rfm1tD+QxSP/TVjKFDNabg==", "updater": "rhel-vex", "name": "CVE-2026-0967", "description": "A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.", "issued": "2026-02-10T18:47:09Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0967 https://bugzilla.redhat.com/show_bug.cgi?id=2436981 https://www.cve.org/CVERecord?id=CVE-2026-0967 https://nvd.nist.gov/vuln/detail/CVE-2026-0967 https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0967.json", "severity": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Rw8DyDlyRHRJOeZaAbGMRA==": { "id": "Rw8DyDlyRHRJOeZaAbGMRA==", "updater": "rhel-vex", "name": "CVE-2025-59529", "description": "A flaw was found in avahi. The simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local Denial of Service.", "issued": "2025-12-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-59529 https://bugzilla.redhat.com/show_bug.cgi?id=2405338 https://www.cve.org/CVERecord?id=CVE-2025-59529 https://nvd.nist.gov/vuln/detail/CVE-2025-59529 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59529.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "avahi", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SHxE0qXbBmDEp/LL1ieJeA==": { "id": "SHxE0qXbBmDEp/LL1ieJeA==", "updater": "rhel-vex", "name": "CVE-2020-19189", "description": "A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19189 https://bugzilla.redhat.com/show_bug.cgi?id=2234926 https://www.cve.org/CVERecord?id=CVE-2020-19189 https://nvd.nist.gov/vuln/detail/CVE-2020-19189 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19189.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Te9j1HGn7feNCE/Fduu0+A==": { "id": "Te9j1HGn7feNCE/Fduu0+A==", "updater": "rhel-vex", "name": "CVE-2025-64505", "description": "A heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access.", "issued": "2025-11-24T23:38:40Z", "links": "https://access.redhat.com/security/cve/CVE-2025-64505 https://bugzilla.redhat.com/show_bug.cgi?id=2416905 https://www.cve.org/CVERecord?id=CVE-2025-64505 https://nvd.nist.gov/vuln/detail/CVE-2025-64505 https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37 https://github.com/pnggroup/libpng/pull/748 https://github.com/pnggroup/libpng/security/advisories/GHSA-4952-h5wq-4m42 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-64505.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "java-17-openjdk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Tld/B+HymU17Pebpq5Rixg==": { "id": "Tld/B+HymU17Pebpq5Rixg==", "updater": "rhel-vex", "name": "CVE-2026-56405", "description": "A flaw was found in libexpat. An integer overflow vulnerability exists within the `getAttributeId` function. This flaw could allow an attacker to potentially disclose sensitive information or execute arbitrary code, leading to a compromise of the system's integrity and confidentiality.", "issued": "2026-06-21T15:47:13Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56405 https://bugzilla.redhat.com/show_bug.cgi?id=2491188 https://www.cve.org/CVERecord?id=CVE-2026-56405 https://nvd.nist.gov/vuln/detail/CVE-2026-56405 https://github.com/libexpat/libexpat/pull/1251 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56405.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TuBnhFrkwMqIcYtYYgNGNQ==": { "id": "TuBnhFrkwMqIcYtYYgNGNQ==", "updater": "rhel-vex", "name": "CVE-2026-3784", "description": "A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user.", "issued": "2026-03-11T10:09:21Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3784 https://bugzilla.redhat.com/show_bug.cgi?id=2446449 https://www.cve.org/CVERecord?id=CVE-2026-3784 https://nvd.nist.gov/vuln/detail/CVE-2026-3784 http://www.openwall.com/lists/oss-security/2026/03/11/3 https://curl.se/docs/CVE-2026-3784.html https://curl.se/docs/CVE-2026-3784.json https://hackerone.com/reports/3584903 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3784.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "U8up9/ZYW+CTO5UcJB1hZQ==": { "id": "U8up9/ZYW+CTO5UcJB1hZQ==", "updater": "rhel-vex", "name": "CVE-2025-5278", "description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.", "issued": "2025-05-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5278 https://bugzilla.redhat.com/show_bug.cgi?id=2368764 https://www.cve.org/CVERecord?id=CVE-2025-5278 https://nvd.nist.gov/vuln/detail/CVE-2025-5278 https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633 https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5278.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UMD4nV1Ky5C5eKUMgtnKzw==": { "id": "UMD4nV1Ky5C5eKUMgtnKzw==", "updater": "rhel-vex", "name": "CVE-2021-20193", "description": "A flaw was found in the src/list.c of tar. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.", "issued": "2021-01-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-20193 https://bugzilla.redhat.com/show_bug.cgi?id=1917565 https://www.cve.org/CVERecord?id=CVE-2021-20193 https://nvd.nist.gov/vuln/detail/CVE-2021-20193 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-20193.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UPzTyNn8ZLXlb+bwRFPPTA==": { "id": "UPzTyNn8ZLXlb+bwRFPPTA==", "updater": "rhel-vex", "name": "CVE-2023-2650", "description": "A flaw was found in OpenSSL resulting in a possible denial of service while translating ASN.1 object identifiers. Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience long delays when processing messages, which may lead to a denial of service.", "issued": "2023-05-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-2650 https://bugzilla.redhat.com/show_bug.cgi?id=2207947 https://www.cve.org/CVERecord?id=CVE-2023-2650 https://nvd.nist.gov/vuln/detail/CVE-2023-2650 https://www.openssl.org/news/secadv/20230530.txt https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-2650.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UUIKm7f4jyfDWGKvptUQ8Q==": { "id": "UUIKm7f4jyfDWGKvptUQ8Q==", "updater": "rhel-vex", "name": "CVE-2025-8277", "description": "A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability.", "issued": "2025-09-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-8277 https://bugzilla.redhat.com/show_bug.cgi?id=2383888 https://www.cve.org/CVERecord?id=CVE-2025-8277 https://nvd.nist.gov/vuln/detail/CVE-2025-8277 https://www.libssh.org/security/advisories/CVE-2025-8277.txt https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-8277.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UbmdE2pHXRFccv8l1e02Jw==": { "id": "UbmdE2pHXRFccv8l1e02Jw==", "updater": "rhel-vex", "name": "CVE-2023-4156", "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.", "issued": "2023-06-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-4156 https://bugzilla.redhat.com/show_bug.cgi?id=2215930 https://www.cve.org/CVERecord?id=CVE-2023-4156 https://nvd.nist.gov/vuln/detail/CVE-2023-4156 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4156.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UyCjBcpeB0nhkRTVhUcAJQ==": { "id": "UyCjBcpeB0nhkRTVhUcAJQ==", "updater": "rhel-vex", "name": "CVE-2026-39316", "description": "A flaw was found in CUPS, an open-source printing system. This vulnerability, known as a use-after-free, occurs in the CUPS scheduler when temporary printers are automatically removed. The system fails to properly manage memory, leaving a pointer to a freed memory location. An attacker could exploit this to cause the CUPS daemon to crash, leading to a denial of service. In more severe scenarios, this could potentially allow an attacker to execute arbitrary code.", "issued": "2026-04-07T17:00:26Z", "links": "https://access.redhat.com/security/cve/CVE-2026-39316 https://bugzilla.redhat.com/show_bug.cgi?id=2456120 https://www.cve.org/CVERecord?id=CVE-2026-39316 https://nvd.nist.gov/vuln/detail/CVE-2026-39316 https://github.com/OpenPrinting/cups/security/advisories/GHSA-pjv5-prqp-46rg https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39316.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "cups", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VLzwKVDYC7fQrtcpCzjXjA==": { "id": "VLzwKVDYC7fQrtcpCzjXjA==", "updater": "rhel-vex", "name": "CVE-2025-69418", "description": "A flaw was found in OpenSSL. When applications directly call the low-level CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions with non-block-aligned lengths in a single call on hardware-accelerated builds, the trailing 1-15 bytes of a message may be exposed in cleartext. These exposed bytes are not covered by the authentication tag, allowing an attacker to read or tamper with them without detection.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-69418 https://bugzilla.redhat.com/show_bug.cgi?id=2430381 https://www.cve.org/CVERecord?id=CVE-2025-69418 https://nvd.nist.gov/vuln/detail/CVE-2025-69418 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69418.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VsocCwaFpF6PzdX5PxR+sQ==": { "id": "VsocCwaFpF6PzdX5PxR+sQ==", "updater": "rhel-vex", "name": "CVE-2020-19185", "description": "A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash, causing denial of service.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19185 https://bugzilla.redhat.com/show_bug.cgi?id=2234924 https://www.cve.org/CVERecord?id=CVE-2020-19185 https://nvd.nist.gov/vuln/detail/CVE-2020-19185 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19185.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W/DMqBRMDYVkVH3D67luGg==": { "id": "W/DMqBRMDYVkVH3D67luGg==", "updater": "rhel-vex", "name": "CVE-2025-64118", "description": "A flaw was found in node-tar, a Tar utility for Node.js. This vulnerability allows a local attacker to potentially disclose sensitive information. When the .t (or .list) function is used with { sync: true } to read tar entry contents, and the tar file is concurrently modified on disk to a smaller size, the function may return uninitialized memory contents. This could lead to the exposure of arbitrary data.", "issued": "2025-10-30T17:50:20Z", "links": "https://access.redhat.com/security/cve/CVE-2025-64118 https://bugzilla.redhat.com/show_bug.cgi?id=2407440 https://www.cve.org/CVERecord?id=CVE-2025-64118 https://nvd.nist.gov/vuln/detail/CVE-2025-64118 https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d https://github.com/isaacs/node-tar/issues/445 https://github.com/isaacs/node-tar/pull/446 https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-64118.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W/d4trZ7jb2yxjrq4cNOWA==": { "id": "W/d4trZ7jb2yxjrq4cNOWA==", "updater": "rhel-vex", "name": "CVE-2022-3219", "description": "A vulnerability was found in GnuPG. GnuPG can spin on a relatively small input by crafting a public key with thousands of signatures attached and compressed down to a few kilobytes. This issue can potentially cause a denial of service.", "issued": "2022-09-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-3219 https://bugzilla.redhat.com/show_bug.cgi?id=2127010 https://www.cve.org/CVERecord?id=CVE-2022-3219 https://nvd.nist.gov/vuln/detail/CVE-2022-3219 https://dev.gnupg.org/D556 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-3219.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W0l4QAgarxrOkTlGvtp0uA==": { "id": "W0l4QAgarxrOkTlGvtp0uA==", "updater": "rhel-vex", "name": "CVE-2026-59846", "description": "A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.", "issued": "2026-07-21T12:46:04Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59846 https://bugzilla.redhat.com/show_bug.cgi?id=2498179 https://www.cve.org/CVERecord?id=CVE-2026-59846 https://nvd.nist.gov/vuln/detail/CVE-2026-59846 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59846.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WGOq+rhe3/NaL51WCyZSeA==": { "id": "WGOq+rhe3/NaL51WCyZSeA==", "updater": "rhel-vex", "name": "CVE-2026-5419", "description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5419 https://bugzilla.redhat.com/show_bug.cgi?id=2467686 https://www.cve.org/CVERecord?id=CVE-2026-5419 https://nvd.nist.gov/vuln/detail/CVE-2026-5419 https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5419.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "gnutls", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WGvgNwrW2u5APZcidQ6v1Q==": { "id": "WGvgNwrW2u5APZcidQ6v1Q==", "updater": "rhel-vex", "name": "CVE-2026-27456", "description": "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.", "issued": "2026-04-03T21:23:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-27456 https://bugzilla.redhat.com/show_bug.cgi?id=2454956 https://www.cve.org/CVERecord?id=CVE-2026-27456 https://nvd.nist.gov/vuln/detail/CVE-2026-27456 https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4 https://github.com/util-linux/util-linux/releases/tag/v2.41.4 https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27456.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WcChSpNAL6V9Xfxc9AqW7g==": { "id": "WcChSpNAL6V9Xfxc9AqW7g==", "updater": "rhel-vex", "name": "CVE-2025-15469", "description": "A flaw was found in openssl. When a user signs or verifies files larger than 16MB using the `openssl dgst` command with one-shot algorithms, the tool silently truncates the input to 16MB. This creates an integrity gap, allowing trailing data beyond the initial 16MB to be modified without detection because it remains unauthenticated. This vulnerability primarily impacts workflows that both sign and verify files using the affected `openssl dgst` command.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15469 https://bugzilla.redhat.com/show_bug.cgi?id=2430378 https://www.cve.org/CVERecord?id=CVE-2025-15469 https://nvd.nist.gov/vuln/detail/CVE-2025-15469 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15469.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WnU62DA2fwlfQLbeba0AYA==": { "id": "WnU62DA2fwlfQLbeba0AYA==", "updater": "rhel-vex", "name": "CVE-2026-56391", "description": "A flaw was found in GNU coreutils uniq. When processing specially crafted multibyte input with the --check-chars option, an attacker can trigger an out-of-bounds read. This vulnerability can lead to a denial of service (DoS) due to an application crash and potentially expose sensitive information from adjacent memory.", "issued": "2026-07-24T07:44:45Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56391 https://bugzilla.redhat.com/show_bug.cgi?id=2506691 https://www.cve.org/CVERecord?id=CVE-2026-56391 https://nvd.nist.gov/vuln/detail/CVE-2026-56391 https://cert.pl/en/posts/2026/07/CVE-2026-56391 https://git.savannah.gnu.org/cgit/coreutils.git/ https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56391.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Wp4+QBQm4nhI8rQxVklEXw==": { "id": "Wp4+QBQm4nhI8rQxVklEXw==", "updater": "rhel-vex", "name": "CVE-2025-4878", "description": "A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.", "issued": "2025-06-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-4878 https://bugzilla.redhat.com/show_bug.cgi?id=2376184 https://www.cve.org/CVERecord?id=CVE-2025-4878 https://nvd.nist.gov/vuln/detail/CVE-2025-4878 https://git.libssh.org/projects/libssh.git/commit/?id=697650caa97eaf7623924c75f9fcfec6dd423cd1 https://git.libssh.org/projects/libssh.git/commit/?id=b35ee876adc92a208d47194772e99f9c71e0bedb https://www.libssh.org/security/advisories/CVE-2025-4878.txt https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4878.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XBiy/XVR6SoThCkYUmkD1g==": { "id": "XBiy/XVR6SoThCkYUmkD1g==", "updater": "rhel-vex", "name": "CVE-2026-33056", "description": "A flaw was found in tar-rs, a Rust library for reading and writing tar archives. When unpacking a crafted tar archive, an attacker can exploit a symbolic link vulnerability. By including a symlink followed by a directory with the same name, the library incorrectly applies file permissions to the symlink's target. This allows an attacker to modify the permissions of arbitrary directories outside the intended extraction location.", "issued": "2026-03-20T07:11:10Z", "links": "https://access.redhat.com/security/cve/CVE-2026-33056 https://bugzilla.redhat.com/show_bug.cgi?id=2449490 https://www.cve.org/CVERecord?id=CVE-2026-33056 https://nvd.nist.gov/vuln/detail/CVE-2026-33056 https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446 https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33056.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XXiaw1EwhFkuilI94EKiqQ==": { "id": "XXiaw1EwhFkuilI94EKiqQ==", "updater": "rhel-vex", "name": "CVE-2026-5713", "description": "A flaw was found in Python. A malicious Python process could exploit the \"profiling.sampling\" module and \"asyncio introspection capabilities\" to read and write memory addresses within a privileged process. This vulnerability occurs when the privileged process connects to the malicious process via its remote debugging feature, potentially leading to information disclosure and arbitrary code execution. Successful exploitation requires repeated connections, which may cause instability in the connecting process.", "issued": "2026-04-14T15:11:51Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5713 https://bugzilla.redhat.com/show_bug.cgi?id=2458239 https://www.cve.org/CVERecord?id=CVE-2026-5713 https://nvd.nist.gov/vuln/detail/CVE-2026-5713 https://github.com/python/cpython/issues/148178 https://github.com/python/cpython/pull/148187 https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5713.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XbpXfbeApuDuIKvY0/qWiA==": { "id": "XbpXfbeApuDuIKvY0/qWiA==", "updater": "rhel-vex", "name": "CVE-2026-3731", "description": "A flaw was found in libssh. A remote attacker could trigger an out-of-bounds read vulnerability in the SFTP Extension Name Handler by manipulating the `idx` argument in the `sftp_extensions_get_name` or `sftp_extensions_get_data` functions. This could lead to a Denial of Service (DoS), making the affected system unresponsive.", "issued": "2026-03-08T10:32:19Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3731 https://bugzilla.redhat.com/show_bug.cgi?id=2445579 https://www.cve.org/CVERecord?id=CVE-2026-3731 https://nvd.nist.gov/vuln/detail/CVE-2026-3731 https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60 https://vuldb.com/?ctiid.349709 https://vuldb.com/?id.349709 https://vuldb.com/?submit.767120 https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3731.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XygysGe2kdlyCRQHM1fu3w==": { "id": "XygysGe2kdlyCRQHM1fu3w==", "updater": "rhel-vex", "name": "CVE-2025-5917", "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.", "issued": "2025-05-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5917 https://bugzilla.redhat.com/show_bug.cgi?id=2370874 https://www.cve.org/CVERecord?id=CVE-2025-5917 https://nvd.nist.gov/vuln/detail/CVE-2025-5917 https://github.com/libarchive/libarchive/pull/2588 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5917.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YNodYYe4cB6HofVRKHeLCw==": { "id": "YNodYYe4cB6HofVRKHeLCw==", "updater": "rhel-vex", "name": "CVE-2026-56406", "description": "A flaw was found in libexpat. An integer overflow vulnerability exists in the `XML_ParseBuffer` function due to a missing check. This flaw could allow an attacker to cause memory corruption, potentially leading to arbitrary code execution, information disclosure, or a denial of service.", "issued": "2026-06-21T15:48:21Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56406 https://bugzilla.redhat.com/show_bug.cgi?id=2491187 https://www.cve.org/CVERecord?id=CVE-2026-56406 https://nvd.nist.gov/vuln/detail/CVE-2026-56406 https://github.com/libexpat/libexpat/pull/1255 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56406.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YOjk++xRTh9VXO273YBySg==": { "id": "YOjk++xRTh9VXO273YBySg==", "updater": "rhel-vex", "name": "CVE-2026-59845", "description": "A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.", "issued": "2026-07-21T11:23:44Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59845 https://bugzilla.redhat.com/show_bug.cgi?id=2498178 https://www.cve.org/CVERecord?id=CVE-2026-59845 https://nvd.nist.gov/vuln/detail/CVE-2026-59845 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59845.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YbAnIQEqWeedb46YJk3cBg==": { "id": "YbAnIQEqWeedb46YJk3cBg==", "updater": "rhel-vex", "name": "CVE-2026-58012", "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.", "issued": "2026-03-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58012 https://bugzilla.redhat.com/show_bug.cgi?id=2492247 https://www.cve.org/CVERecord?id=CVE-2026-58012 https://nvd.nist.gov/vuln/detail/CVE-2026-58012 https://gitlab.gnome.org/GNOME/glib/-/issues/3918 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58012.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YiJlkUTKf0/7+ORZMmQ2cw==": { "id": "YiJlkUTKf0/7+ORZMmQ2cw==", "updater": "rhel-vex", "name": "CVE-2025-25724", "description": "A flaw was found in the libarchive package. Affected versions of libarchive do not check a strftime return value, which can lead to a denial of service or unspecified other impacts via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.", "issued": "2025-03-02T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-25724 https://bugzilla.redhat.com/show_bug.cgi?id=2349221 https://www.cve.org/CVERecord?id=CVE-2025-25724 https://nvd.nist.gov/vuln/detail/CVE-2025-25724 https://gist.github.com/Ekkosun/a83870ce7f3b7813b9b462a395e8ad92 https://github.com/Ekkosun/pocs/blob/main/bsdtarbug https://github.com/libarchive/libarchive/blob/b439d586f53911c84be5e380445a8a259e19114c/tar/util.c#L751-L752 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-25724.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YoCxZvEp16Bt9LDv+Ficeg==": { "id": "YoCxZvEp16Bt9LDv+Ficeg==", "updater": "rhel-vex", "name": "CVE-2025-64506", "description": "A buffer over read flaw has been discovered in libpng. A heap buffer over-read vulnerability exists in libpng's png_write_image_8bit function when processing 8-bit images through the simplified write API with convert_to_8bit enabled. The vulnerability affects 8-bit grayscale+alpha, RGB/RGBA, and images with incomplete row data. A conditional guard incorrectly allows 8-bit input to enter code expecting 16-bit input, causing reads up to 2 bytes beyond allocated buffer boundaries.", "issued": "2025-11-24T23:41:09Z", "links": "https://access.redhat.com/security/cve/CVE-2025-64506 https://bugzilla.redhat.com/show_bug.cgi?id=2416906 https://www.cve.org/CVERecord?id=CVE-2025-64506 https://nvd.nist.gov/vuln/detail/CVE-2025-64506 https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821 https://github.com/pnggroup/libpng/pull/749 https://github.com/pnggroup/libpng/security/advisories/GHSA-qpr4-xm66-hww6 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-64506.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "java-17-openjdk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Yruwfu4Vkg/KNSmhqw2VEg==": { "id": "Yruwfu4Vkg/KNSmhqw2VEg==", "updater": "rhel-vex", "name": "CVE-2026-58015", "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.", "issued": "2026-04-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58015 https://bugzilla.redhat.com/show_bug.cgi?id=2492256 https://www.cve.org/CVERecord?id=CVE-2026-58015 https://nvd.nist.gov/vuln/detail/CVE-2026-58015 https://gitlab.gnome.org/GNOME/glib/-/issues/3931 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58015.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z98lUsU1mVOsrmb49hActA==": { "id": "Z98lUsU1mVOsrmb49hActA==", "updater": "rhel-vex", "name": "CVE-2026-42308", "description": "A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceeding large amount, an integer overflow can occur when Pillow tracks the current position. This could lead to a denial of service (DoS) condition, making the application unavailable.", "issued": "2026-05-09T04:09:01Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42308 https://bugzilla.redhat.com/show_bug.cgi?id=2468457 https://www.cve.org/CVERecord?id=CVE-2026-42308 https://nvd.nist.gov/vuln/detail/CVE-2026-42308 https://github.com/python-pillow/Pillow/releases/tag/12.2.0 https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42308.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZTGiJlkqcqrCLJSY/Sq8lA==": { "id": "ZTGiJlkqcqrCLJSY/Sq8lA==", "updater": "rhel-vex", "name": "CVE-2020-19186", "description": "A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a buffer over-read, resulting in an application crash.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19186 https://bugzilla.redhat.com/show_bug.cgi?id=2234908 https://www.cve.org/CVERecord?id=CVE-2020-19186 https://nvd.nist.gov/vuln/detail/CVE-2020-19186 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19186.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZkEez7f24VNVhTaTCDhuEg==": { "id": "ZkEez7f24VNVhTaTCDhuEg==", "updater": "rhel-vex", "name": "CVE-2025-15468", "description": "A flaw was found in openssl. A remote attacker could trigger a NULL pointer dereference by sending an unknown or unsupported cipher ID during the client hello callback in applications using the QUIC (Quick UDP Internet Connections) protocol. This vulnerability, occurring when the SSL_CIPHER_find() function is called in this specific context, leads to an abnormal termination of the running process, causing a Denial of Service (DoS).", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15468 https://bugzilla.redhat.com/show_bug.cgi?id=2430377 https://www.cve.org/CVERecord?id=CVE-2025-15468 https://nvd.nist.gov/vuln/detail/CVE-2025-15468 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15468.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZlxfTVb/4bi6yWQ+JLaOnw==": { "id": "ZlxfTVb/4bi6yWQ+JLaOnw==", "updater": "rhel-vex", "name": "CVE-2026-2297", "description": "A flaw was found in CPython. This vulnerability allows a local user with low privileges to bypass security auditing mechanisms. The issue occurs because the SourcelessFileLoader component, responsible for handling older Python compiled files (.pyc), does not properly trigger system audit events. This oversight could enable malicious activities to go undetected, compromising the integrity of the system.", "issued": "2026-03-04T22:10:43Z", "links": "https://access.redhat.com/security/cve/CVE-2026-2297 https://bugzilla.redhat.com/show_bug.cgi?id=2444691 https://www.cve.org/CVERecord?id=CVE-2026-2297 https://nvd.nist.gov/vuln/detail/CVE-2026-2297 https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86 https://github.com/python/cpython/issues/145506 https://github.com/python/cpython/pull/145507 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2297.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Znm2hdK/FULQhTTGTVX59Q==": { "id": "Znm2hdK/FULQhTTGTVX59Q==", "updater": "rhel-vex", "name": "CVE-2026-3783", "description": "A flaw was found in curl. When an OAuth2 bearer token is used for an HTTP(S) transfer that redirects to a second URL, curl could unintentionally leak the token. This occurs if the second hostname has entries in the `.netrc` file, allowing the bearer token intended for the first host to be sent to the redirected host. This information disclosure could allow an attacker to gain unauthorized access.", "issued": "2026-03-11T10:09:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3783 https://bugzilla.redhat.com/show_bug.cgi?id=2446450 https://www.cve.org/CVERecord?id=CVE-2026-3783 https://nvd.nist.gov/vuln/detail/CVE-2026-3783 http://www.openwall.com/lists/oss-security/2026/03/11/2 https://curl.se/docs/CVE-2026-3783.html https://curl.se/docs/CVE-2026-3783.json https://hackerone.com/reports/3583983 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3783.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Zp5q2R9PHTn/pmrn158k9A==": { "id": "Zp5q2R9PHTn/pmrn158k9A==", "updater": "rhel-vex", "name": "CVE-2026-41989", "description": "A flaw was found in Libgcrypt. A remote attacker could exploit this vulnerability by sending crafted Elliptic Curve Diffie-Hellman (ECDH) ciphertext to the `gcry_pk_decrypt` function. This can lead to a heap-based buffer overflow, potentially causing a denial of service (DoS) condition.", "issued": "2026-04-23T04:30:26Z", "links": "https://access.redhat.com/security/cve/CVE-2026-41989 https://bugzilla.redhat.com/show_bug.cgi?id=2461063 https://www.cve.org/CVERecord?id=CVE-2026-41989 https://nvd.nist.gov/vuln/detail/CVE-2026-41989 https://dev.gnupg.org/T8211 https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html https://www.openwall.com/lists/oss-security/2026/04/21/1 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41989.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Zp9+pixFuNBueE2yO610gQ==": { "id": "Zp9+pixFuNBueE2yO610gQ==", "updater": "rhel-vex", "name": "CVE-2024-56433", "description": "A flaw was found in shadow-utils. Affected versions of shadow-utils establish a default /etc/subuid behavior, for example, uid 100000 through 165535 for the first user account, that can conflict with the uids of users defined on locally administered networks. This issue potentially leads to account takeover by leveraging newuidmap for access to an NFS home directory or same-host resources for remote logins by these local network users.", "issued": "2024-12-26T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-56433 https://bugzilla.redhat.com/show_bug.cgi?id=2334165 https://www.cve.org/CVERecord?id=CVE-2024-56433 https://nvd.nist.gov/vuln/detail/CVE-2024-56433 https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241 https://github.com/shadow-maint/shadow/issues/1157 https://github.com/shadow-maint/shadow/releases/tag/4.4 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-56433.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "shadow-utils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZvX4VR3jvMBd1Wq+RxNTgg==": { "id": "ZvX4VR3jvMBd1Wq+RxNTgg==", "updater": "rhel-vex", "name": "CVE-2020-35512", "description": "A use-after-free flaw was found in D-Bus when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors.", "issued": "2020-06-30T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-35512 https://bugzilla.redhat.com/show_bug.cgi?id=1909101 https://www.cve.org/CVERecord?id=CVE-2020-35512 https://nvd.nist.gov/vuln/detail/CVE-2020-35512 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-35512.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "dbus", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "a067YUjLHWzR99JNl/RtGQ==": { "id": "a067YUjLHWzR99JNl/RtGQ==", "updater": "rhel-vex", "name": "CVE-2025-4598", "description": "A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.", "issued": "2025-05-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-4598 https://bugzilla.redhat.com/show_bug.cgi?id=2369242 https://www.cve.org/CVERecord?id=CVE-2025-4598 https://nvd.nist.gov/vuln/detail/CVE-2025-4598 https://www.openwall.com/lists/oss-security/2025/05/29/3 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4598.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "a9FCHpokzVfpw+gdnrzSXg==": { "id": "a9FCHpokzVfpw+gdnrzSXg==", "updater": "rhel-vex", "name": "CVE-2026-59850", "description": "A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.", "issued": "2026-07-21T14:08:16Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59850 https://bugzilla.redhat.com/show_bug.cgi?id=2498183 https://www.cve.org/CVERecord?id=CVE-2026-59850 https://nvd.nist.gov/vuln/detail/CVE-2026-59850 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59850.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "assnsOgZ19ItYfuh/iKLMA==": { "id": "assnsOgZ19ItYfuh/iKLMA==", "updater": "rhel-vex", "name": "CVE-2026-59844", "description": "A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.", "issued": "2026-07-21T11:17:49Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59844 https://bugzilla.redhat.com/show_bug.cgi?id=2498177 https://www.cve.org/CVERecord?id=CVE-2026-59844 https://nvd.nist.gov/vuln/detail/CVE-2026-59844 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59844.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cCowLuOsLfTMmPFOoqUVww==": { "id": "cCowLuOsLfTMmPFOoqUVww==", "updater": "rhel-vex", "name": "CVE-2024-0397", "description": "A vulnerability was found in Python. A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time that certificates are loaded into the SSLContext, such as during the TLS handshake with a configured certificate directory.", "issued": "2024-06-17T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-0397 https://bugzilla.redhat.com/show_bug.cgi?id=2301891 https://www.cve.org/CVERecord?id=CVE-2024-0397 https://nvd.nist.gov/vuln/detail/CVE-2024-0397 https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/ https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0397.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cERFf1oFvXQnx4BPCz9RhA==": { "id": "cERFf1oFvXQnx4BPCz9RhA==", "updater": "rhel-vex", "name": "CVE-2026-42768", "description": "A flaw was found in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim's private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application's error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42768 https://bugzilla.redhat.com/show_bug.cgi?id=2481892 https://www.cve.org/CVERecord?id=CVE-2026-42768 https://nvd.nist.gov/vuln/detail/CVE-2026-42768 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42768.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cqYWiTibDLM7aibErMKang==": { "id": "cqYWiTibDLM7aibErMKang==", "updater": "rhel-vex", "name": "CVE-2026-4437", "description": "A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.", "issued": "2026-03-20T19:59:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4437 https://bugzilla.redhat.com/show_bug.cgi?id=2449777 https://www.cve.org/CVERecord?id=CVE-2026-4437 https://nvd.nist.gov/vuln/detail/CVE-2026-4437 https://sourceware.org/bugzilla/show_bug.cgi?id=34014 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4437.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "crmilTSJ/pTSPBKY9EJmZg==": { "id": "crmilTSJ/pTSPBKY9EJmZg==", "updater": "rhel-vex", "name": "CVE-2025-14524", "description": "A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14524 https://bugzilla.redhat.com/show_bug.cgi?id=2426407 https://www.cve.org/CVERecord?id=CVE-2025-14524 https://nvd.nist.gov/vuln/detail/CVE-2025-14524 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14524.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dGtImtgXxemdBTM1vCCLUg==": { "id": "dGtImtgXxemdBTM1vCCLUg==", "updater": "rhel-vex", "name": "CVE-2019-8905", "description": "A vulnerability was found in the \"File\" project where a stack-based buffer over-read exists in the do_core_note function within readelf.c of libmagic.a, by using a specially crafted file the attacker could access sensitive information or cause a denial of service.", "issued": "2019-02-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-8905 https://bugzilla.redhat.com/show_bug.cgi?id=1679181 https://www.cve.org/CVERecord?id=CVE-2019-8905 https://nvd.nist.gov/vuln/detail/CVE-2019-8905 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-8905.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "file", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dLBwvrbHvvMzC4tdzDzNMw==": { "id": "dLBwvrbHvvMzC4tdzDzNMw==", "updater": "rhel-vex", "name": "CVE-2026-11850", "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len \u003c 2, triggering the underflow when the KDC or kadmind reads principal data.", "issued": "2026-06-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11850 https://bugzilla.redhat.com/show_bug.cgi?id=2459970 https://www.cve.org/CVERecord?id=CVE-2026-11850 https://nvd.nist.gov/vuln/detail/CVE-2026-11850 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11850.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "krb5", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dYucp/SettSQd/Hpukj6pA==": { "id": "dYucp/SettSQd/Hpukj6pA==", "updater": "rhel-vex", "name": "CVE-2026-5545", "description": "A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5545 https://bugzilla.redhat.com/show_bug.cgi?id=2461204 https://www.cve.org/CVERecord?id=CVE-2026-5545 https://nvd.nist.gov/vuln/detail/CVE-2026-5545 https://curl.se/docs/CVE-2026-5545.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5545.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eCNdMtt9JN2Rrb8I23NIsA==": { "id": "eCNdMtt9JN2Rrb8I23NIsA==", "updater": "rhel-vex", "name": "CVE-2026-34990", "description": "A flaw was found in OpenPrinting CUPS. A local unprivileged user can exploit this vulnerability by coercing the `cupsd` service to authenticate to an attacker-controlled Internet Printing Protocol (IPP) service. This allows the user to create a persistent printer queue that can overwrite arbitrary files with root privileges. Successful exploitation can lead to privilege escalation and arbitrary root command execution.", "issued": "2026-04-03T21:14:09Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34990 https://bugzilla.redhat.com/show_bug.cgi?id=2454947 https://www.cve.org/CVERecord?id=CVE-2026-34990 https://nvd.nist.gov/vuln/detail/CVE-2026-34990 https://github.com/OpenPrinting/cups/security/advisories/GHSA-c54j-2vqw-wpwp https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34990.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "cups", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eFkHRGAjSFu9sbgr+RArOA==": { "id": "eFkHRGAjSFu9sbgr+RArOA==", "updater": "rhel-vex", "name": "CVE-2026-56392", "description": "A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a heap-based buffer overflow, occurs due to an integer overflow when `unexpand` processes unusually large tab stop values provided by a local attacker. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries. Successful exploitation can cause the `unexpand` utility to crash, potentially resulting in a denial of service or enabling further memory manipulation.", "issued": "2026-07-24T07:44:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56392 https://bugzilla.redhat.com/show_bug.cgi?id=2506694 https://www.cve.org/CVERecord?id=CVE-2026-56392 https://nvd.nist.gov/vuln/detail/CVE-2026-56392 https://cert.pl/en/posts/2026/07/CVE-2026-56391 https://git.savannah.gnu.org/cgit/coreutils.git/ https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56392.json https://access.redhat.com/errata/RHBA-2026:47115", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "coreutils-single", "version": "", "kind": "binary", "normalized_version": "", "arch": "aarch64|ppc64le|s390x|amd64|x86_64", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*" }, "fixed_in_version": "0:8.30-20.el8_10", "arch_op": "pattern match", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eO2vvxX2WuQSx4VuCGHAwQ==": { "id": "eO2vvxX2WuQSx4VuCGHAwQ==", "updater": "rhel-vex", "name": "CVE-2026-11972", "description": "A flaw was found in the Python `tarfile` module. When processing a specially crafted tar archive opened in 'streaming mode' (mode='r|'), the module does not properly handle the end-of-file (EOF) condition. This can cause the `tarfile` module to enter an infinite loop, leading to a Denial of Service (DoS) for applications processing such archives.", "issued": "2026-06-23T22:02:45Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11972 https://bugzilla.redhat.com/show_bug.cgi?id=2492050 https://www.cve.org/CVERecord?id=CVE-2026-11972 https://nvd.nist.gov/vuln/detail/CVE-2026-11972 https://github.com/python/cpython/issues/151981 https://github.com/python/cpython/pull/151982 https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11972.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fT6cIVRM+743nfHJKo4yuQ==": { "id": "fT6cIVRM+743nfHJKo4yuQ==", "updater": "rhel-vex", "name": "CVE-2026-6429", "description": "A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6429 https://bugzilla.redhat.com/show_bug.cgi?id=2461205 https://www.cve.org/CVERecord?id=CVE-2026-6429 https://nvd.nist.gov/vuln/detail/CVE-2026-6429 https://curl.se/docs/CVE-2026-6429.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6429.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fXpWtuXNPi3tb2edhk37bw==": { "id": "fXpWtuXNPi3tb2edhk37bw==", "updater": "rhel-vex", "name": "CVE-2024-2236", "description": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.", "issued": "2024-03-06T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2236 https://bugzilla.redhat.com/show_bug.cgi?id=2245218 https://www.cve.org/CVERecord?id=CVE-2024-2236 https://nvd.nist.gov/vuln/detail/CVE-2024-2236 https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2236.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fayrPya6DVXP9weWvA6obQ==": { "id": "fayrPya6DVXP9weWvA6obQ==", "updater": "rhel-vex", "name": "CVE-2024-7264", "description": "A flaw was found in libcurl, where libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the length of the *time fraction*, leading to a `strlen()` performed on a pointer to a heap buffer area that is not purposely NULL terminated.", "issued": "2024-07-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-7264 https://bugzilla.redhat.com/show_bug.cgi?id=2301888 https://www.cve.org/CVERecord?id=CVE-2024-7264 https://nvd.nist.gov/vuln/detail/CVE-2024-7264 https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-7264.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fg5E5MKinCbJn9w+SABeOA==": { "id": "fg5E5MKinCbJn9w+SABeOA==", "updater": "rhel-vex", "name": "CVE-2026-11940", "description": "A flaw was found in the `tarfile.extractall()` function within Python. A remote attacker could exploit this vulnerability by providing a specially crafted archive. This archive could bypass security filters by using a hardlink that references a symlink, allowing the symlink to be recreated outside the intended destination directory. This could lead to out-of-destination file reads or writes, potentially resulting in information disclosure or arbitrary file modification.", "issued": "2026-06-23T16:04:17Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11940 https://bugzilla.redhat.com/show_bug.cgi?id=2491848 https://www.cve.org/CVERecord?id=CVE-2026-11940 https://nvd.nist.gov/vuln/detail/CVE-2026-11940 https://github.com/python/cpython/issues/151558 https://github.com/python/cpython/pull/151559 https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11940.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fvGjL9hw9hDQockMTb7lrA==": { "id": "fvGjL9hw9hDQockMTb7lrA==", "updater": "rhel-vex", "name": "CVE-2021-4209", "description": "A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.", "issued": "2021-12-22T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-4209 https://bugzilla.redhat.com/show_bug.cgi?id=2044156 https://www.cve.org/CVERecord?id=CVE-2021-4209 https://nvd.nist.gov/vuln/detail/CVE-2021-4209 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-4209.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gnutls", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gaFOKxy9D9KR/Iyd+kDZoA==": { "id": "gaFOKxy9D9KR/Iyd+kDZoA==", "updater": "rhel-vex", "name": "CVE-2025-50182", "description": "A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can enable a remote attacker to control the redirect destination, leading to arbitrary URL redirection. Consequently, an attacker can redirect users to malicious websites. This \nvulnerability stems from a failure to constrain the redirect target.", "issued": "2025-06-19T01:42:44Z", "links": "https://access.redhat.com/security/cve/CVE-2025-50182 https://bugzilla.redhat.com/show_bug.cgi?id=2373800 https://www.cve.org/CVERecord?id=CVE-2025-50182 https://nvd.nist.gov/vuln/detail/CVE-2025-50182 https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-50182.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python-pip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gagftKXuSuh9pi4dRu9yPQ==": { "id": "gagftKXuSuh9pi4dRu9yPQ==", "updater": "rhel-vex", "name": "CVE-2024-2511", "description": "A flaw was found in OpenSSL. A malicious client can trigger an uncontrolled memory consumption, resulting in a Denial of Service. This issue occurs due to OpenSSL's TLSv1.3 session cache going into an incorrect state, leading to it failing to flush properly as it fills. OpenSSL must be configured with the non-default SSL_OP_NO_TICKET option enabled to be vulnerable. This issue only affects TLSv1.3 servers, while TLS clients are not affected.", "issued": "2024-04-08T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-2511 https://bugzilla.redhat.com/show_bug.cgi?id=2274020 https://www.cve.org/CVERecord?id=CVE-2024-2511 https://nvd.nist.gov/vuln/detail/CVE-2024-2511 https://www.openssl.org/news/vulnerabilities.html https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-2511.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gt35pyOzR5Ohdk7qjUsg2w==": { "id": "gt35pyOzR5Ohdk7qjUsg2w==", "updater": "rhel-vex", "name": "CVE-2026-56412", "description": "A flaw was found in libexpat. This vulnerability, present in versions before 2.8.2, stems from improper handling of XML CDATA sections, where the library fails to adequately track the depth of handler calls. This can result in a 'use-after-free' error, a type of memory corruption that could allow an attacker to crash the application or potentially gain unauthorized control.", "issued": "2026-06-21T15:58:59Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56412 https://bugzilla.redhat.com/show_bug.cgi?id=2491203 https://www.cve.org/CVERecord?id=CVE-2026-56412 https://nvd.nist.gov/vuln/detail/CVE-2026-56412 https://github.com/libexpat/libexpat/pull/1278 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56412.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "h6rS2s3xilGaG0a+pIjl8A==": { "id": "h6rS2s3xilGaG0a+pIjl8A==", "updater": "rhel-vex", "name": "CVE-2026-3644", "description": "A control character validation flaw has been discovered in the Python http.cookie module. The Morsel.update(), |= operator, and unpickling paths were not patched to resolve CVE-2026-0672, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().", "issued": "2026-03-16T17:37:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3644 https://bugzilla.redhat.com/show_bug.cgi?id=2448168 https://www.cve.org/CVERecord?id=CVE-2026-3644 https://nvd.nist.gov/vuln/detail/CVE-2026-3644 https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4 https://github.com/python/cpython/issues/145599 https://github.com/python/cpython/pull/145600 https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3644.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hfBpyVezkUAf98QWnlvzIA==": { "id": "hfBpyVezkUAf98QWnlvzIA==", "updater": "rhel-vex", "name": "CVE-2026-34743", "description": "A flaw was found in XZ Utils. When the `lzma_index_decoder()` function processes an empty index, and a subsequent `lzma_index_append()` operation is performed, insufficient memory is allocated. This can lead to a buffer overflow, potentially causing a denial of service (DoS) for affected systems.", "issued": "2026-04-02T18:36:37Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34743 https://bugzilla.redhat.com/show_bug.cgi?id=2454589 https://www.cve.org/CVERecord?id=CVE-2026-34743 https://nvd.nist.gov/vuln/detail/CVE-2026-34743 https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87 https://github.com/tukaani-project/xz/releases/tag/v5.8.3 https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34743.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "xz", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iEGZHZXt8HWPSM5eJesddQ==": { "id": "iEGZHZXt8HWPSM5eJesddQ==", "updater": "rhel-vex", "name": "CVE-2025-7039", "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.", "issued": "2025-07-02T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-7039 https://bugzilla.redhat.com/show_bug.cgi?id=2392423 https://www.cve.org/CVERecord?id=CVE-2025-7039 https://nvd.nist.gov/vuln/detail/CVE-2025-7039 https://gitlab.gnome.org/GNOME/glib/-/issues/3716 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-7039.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iFhWPnp6w/VV9hJa/b0oig==": { "id": "iFhWPnp6w/VV9hJa/b0oig==", "updater": "rhel-vex", "name": "CVE-2026-42770", "description": "A flaw was found in OpenSSL. A malicious peer can exploit this vulnerability by presenting a specially crafted DHX (X9.42) peer key. Due to improper validation of the peer key's subgroup membership, an attacker can recover the victim's private key after a small number of key exchange attempts. This information disclosure can lead to unauthorized access or further compromise of affected systems.", "issued": "2026-06-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42770 https://bugzilla.redhat.com/show_bug.cgi?id=2481894 https://www.cve.org/CVERecord?id=CVE-2026-42770 https://nvd.nist.gov/vuln/detail/CVE-2026-42770 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42770.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iP8YLvnxQemAwp/nhhOW0w==": { "id": "iP8YLvnxQemAwp/nhhOW0w==", "updater": "rhel-vex", "name": "CVE-2026-3276", "description": "A flaw was found in the `unicodedata.normalize()` function in Python. This vulnerability allows a remote attacker to cause excessive CPU consumption by providing specially crafted Unicode input. Successful exploitation can lead to a Denial of Service (DoS) on the affected system.", "issued": "2026-06-03T14:29:39Z", "links": "https://access.redhat.com/security/cve/CVE-2026-3276 https://bugzilla.redhat.com/show_bug.cgi?id=2484424 https://www.cve.org/CVERecord?id=CVE-2026-3276 https://nvd.nist.gov/vuln/detail/CVE-2026-3276 https://github.com/python/cpython/issues/149079 https://github.com/python/cpython/pull/149080 https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3276.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "icj6a8bc4dYK/DJNvkU0+A==": { "id": "icj6a8bc4dYK/DJNvkU0+A==", "updater": "rhel-vex", "name": "CVE-2022-41409", "description": "A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack.", "issued": "2023-07-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-41409 https://bugzilla.redhat.com/show_bug.cgi?id=2260814 https://www.cve.org/CVERecord?id=CVE-2022-41409 https://nvd.nist.gov/vuln/detail/CVE-2022-41409 https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35 https://github.com/PCRE2Project/pcre2/issues/141 https://github.com/advisories/GHSA-4qfx-v7wh-3q4j https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-41409.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "pcre2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ieASPdYzGxWke8nZZhE02Q==": { "id": "ieASPdYzGxWke8nZZhE02Q==", "updater": "rhel-vex", "name": "CVE-2018-20657", "description": "A vulnerability was found in the demangle_template function in GNU libiberty, as distributed in GNU Binutils, where a memory leak could occur, a specially crafted file could cause the application to consume excessive memory, potentially leading to a crash.", "issued": "2018-12-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-20657 https://bugzilla.redhat.com/show_bug.cgi?id=1664708 https://www.cve.org/CVERecord?id=CVE-2018-20657 https://nvd.nist.gov/vuln/detail/CVE-2018-20657 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-20657.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gcc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jKke6Txz52GXq3xidnEMgg==": { "id": "jKke6Txz52GXq3xidnEMgg==", "updater": "rhel-vex", "name": "CVE-2026-8924", "description": "A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity.", "issued": "2026-07-03T06:15:04Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8924 https://bugzilla.redhat.com/show_bug.cgi?id=2496765 https://www.cve.org/CVERecord?id=CVE-2026-8924 https://nvd.nist.gov/vuln/detail/CVE-2026-8924 https://curl.se/docs/CVE-2026-8924.html https://curl.se/docs/CVE-2026-8924.json https://hackerone.com/reports/3733905 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8924.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jO9fUvpFi0R9/mJ1YH7KXA==": { "id": "jO9fUvpFi0R9/mJ1YH7KXA==", "updater": "rhel-vex", "name": "CVE-2026-59847", "description": "A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.", "issued": "2026-07-21T13:02:11Z", "links": "https://access.redhat.com/security/cve/CVE-2026-59847 https://bugzilla.redhat.com/show_bug.cgi?id=2498180 https://www.cve.org/CVERecord?id=CVE-2026-59847 https://nvd.nist.gov/vuln/detail/CVE-2026-59847 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59847.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jw1ZiDut5Ot+DyVFjCrixg==": { "id": "jw1ZiDut5Ot+DyVFjCrixg==", "updater": "rhel-vex", "name": "CVE-2020-19188", "description": "A flaw was found in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a stack-based buffer overflow, resulting in an application crash, leading to a denial of service.", "issued": "2019-05-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2020-19188 https://bugzilla.redhat.com/show_bug.cgi?id=2234913 https://www.cve.org/CVERecord?id=CVE-2020-19188 https://nvd.nist.gov/vuln/detail/CVE-2020-19188 https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-19188.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "k3o+5yuHivArIfBtIXx02Q==": { "id": "k3o+5yuHivArIfBtIXx02Q==", "updater": "rhel-vex", "name": "CVE-2026-5958", "description": "A Time-of-Check Time-of-Use (TOCTOU) race condition was found in GNU sed. When the -i (in-place) and --follow-symlinks options are used together, sed resolves the symlink but reopens the path for writing. An attacker with write access to the directory containing the symlink can swap it between the check and the open operations. If a privileged user executes sed in this manner on a path influenced by the attacker, it can lead to arbitrary file overwrites and potential privilege escalation.", "issued": "2026-04-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5958 https://bugzilla.redhat.com/show_bug.cgi?id=2458960 https://www.cve.org/CVERecord?id=CVE-2026-5958 https://nvd.nist.gov/vuln/detail/CVE-2026-5958 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5958.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "sed", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kCsMurCi7F77HxJoLqd9jA==": { "id": "kCsMurCi7F77HxJoLqd9jA==", "updater": "rhel-vex", "name": "CVE-2026-34978", "description": "A flaw was found in OpenPrinting CUPS. A remote attacker can exploit a path traversal vulnerability in the RSS notifier by manipulating the `notify-recipient-uri`. This allows writing arbitrary RSS XML data to sensitive files outside the intended directory. This can lead to a denial of service (DoS) by corrupting critical system files, such as the job cache, causing the scheduler to fail and previously queued jobs to disappear.", "issued": "2026-04-03T21:15:15Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34978 https://bugzilla.redhat.com/show_bug.cgi?id=2454957 https://www.cve.org/CVERecord?id=CVE-2026-34978 https://nvd.nist.gov/vuln/detail/CVE-2026-34978 https://github.com/OpenPrinting/cups/security/advisories/GHSA-f53q-7mxp-9gcr https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34978.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "cups", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "klCkJxhhNVG564GOUQMh+Q==": { "id": "klCkJxhhNVG564GOUQMh+Q==", "updater": "rhel-vex", "name": "CVE-2026-5745", "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5745 https://bugzilla.redhat.com/show_bug.cgi?id=2455921 https://www.cve.org/CVERecord?id=CVE-2026-5745 https://nvd.nist.gov/vuln/detail/CVE-2026-5745 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5745.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mQtrNhzMQ9mAh/coURV/3g==": { "id": "mQtrNhzMQ9mAh/coURV/3g==", "updater": "rhel-vex", "name": "CVE-2026-40467", "description": "A flaw was found in gawk. A Use After Free vulnerability exists in the do_getline_redir() routine within the io.c program file. This vulnerability can be triggered by an attacker, potentially leading to a system crash and causing a Denial of Service (DoS).", "issued": "2026-07-13T12:07:52Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40467 https://bugzilla.redhat.com/show_bug.cgi?id=2499658 https://www.cve.org/CVERecord?id=CVE-2026-40467 https://nvd.nist.gov/vuln/detail/CVE-2026-40467 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40467.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mRazAXjBcgFrTolNDZHDsA==": { "id": "mRazAXjBcgFrTolNDZHDsA==", "updater": "rhel-vex", "name": "CVE-2025-6069", "description": "A denial-of-service (DoS) vulnerability has been discovered in Python's html.parser.HTMLParser class. When processing specially malformed HTML input, the parsing runtime can become quadratic with respect to the input size. This significantly increased processing time can lead to excessive resource consumption, ultimately causing a denial-of-service condition in applications that rely on this parser.", "issued": "2025-06-17T13:39:46Z", "links": "https://access.redhat.com/security/cve/CVE-2025-6069 https://bugzilla.redhat.com/show_bug.cgi?id=2373234 https://www.cve.org/CVERecord?id=CVE-2025-6069 https://nvd.nist.gov/vuln/detail/CVE-2025-6069 https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949 https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41 https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b https://github.com/python/cpython/issues/135462 https://github.com/python/cpython/pull/135464 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6069.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mS0YOFVdBeDRbPVhCEovGQ==": { "id": "mS0YOFVdBeDRbPVhCEovGQ==", "updater": "rhel-vex", "name": "CVE-2026-51298", "description": "A flaw was found in SQLite. A remote attacker could exploit a use-after-free vulnerability in the JSON extraction function. This occurs when the program attempts to access memory after it has been freed, specifically within the `JsonParse` object. Successful exploitation of this vulnerability can lead to a service crash and a denial of service (DoS) for affected systems.", "issued": "2026-07-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-51298 https://bugzilla.redhat.com/show_bug.cgi?id=2507556 https://www.cve.org/CVERecord?id=CVE-2026-51298 https://nvd.nist.gov/vuln/detail/CVE-2026-51298 https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51298 https://github.com/sqlite/sqlite/blob/master/src/json.c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-51298.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "High", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mVZw6HfBeWMeBMbQ3QI3eQ==": { "id": "mVZw6HfBeWMeBMbQ3QI3eQ==", "updater": "rhel-vex", "name": "CVE-2026-6791", "description": "A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application.", "issued": "2026-08-10T18:41:25Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6791 https://bugzilla.redhat.com/show_bug.cgi?id=2513603 https://www.cve.org/CVERecord?id=CVE-2026-6791 https://nvd.nist.gov/vuln/detail/CVE-2026-6791 https://sourceware.org/bugzilla/show_bug.cgi?id=34091 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6791.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mouoWVvs12H8FynnB5qIsQ==": { "id": "mouoWVvs12H8FynnB5qIsQ==", "updater": "rhel-vex", "name": "CVE-2019-14250", "description": "This issue resides on libiberty code, a part of binutils, distributed with different versions of RH software. The vulnerability is triggered when the shstrndx (Section Header String Table Index) is zero in the ELF file. This specific condition leads to the integer overflow and subsequent buffer overflow.", "issued": "2019-08-09T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-14250 https://bugzilla.redhat.com/show_bug.cgi?id=1739490 https://www.cve.org/CVERecord?id=CVE-2019-14250 https://nvd.nist.gov/vuln/detail/CVE-2019-14250 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-14250.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gcc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "n83jaRl/T6kiaoMyWtX8xw==": { "id": "n83jaRl/T6kiaoMyWtX8xw==", "updater": "rhel-vex", "name": "CVE-2021-24032", "description": "A flaw was found in zstd. While the final file mode is reflective of the input file, when compressing or uncompressing, the file can temporarily gain greater permissions than the input and potentially leading to security issues (especially if large files are being handled).", "issued": "2021-02-11T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-24032 https://bugzilla.redhat.com/show_bug.cgi?id=1928090 https://www.cve.org/CVERecord?id=CVE-2021-24032 https://nvd.nist.gov/vuln/detail/CVE-2021-24032 https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-24032.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "zstd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nYtstWEUOCTbjAlmYOKURA==": { "id": "nYtstWEUOCTbjAlmYOKURA==", "updater": "rhel-vex", "name": "CVE-2025-4516", "description": "A vulnerability has been identified in CPython's bytes.decode() function when used with the \"unicode_escape\" encoding and the \"ignore\" or \"replace\" error handling modes. This flaw can result in the incorrect decoding of byte strings. While this may not directly lead to traditional security breaches like data exfiltration, the resulting unexpected program behavior could introduce instability, logic errors, or unintended side effects within applications that rely on this specific decoding functionality.", "issued": "2025-05-15T13:29:20Z", "links": "https://access.redhat.com/security/cve/CVE-2025-4516 https://bugzilla.redhat.com/show_bug.cgi?id=2366509 https://www.cve.org/CVERecord?id=CVE-2025-4516 https://nvd.nist.gov/vuln/detail/CVE-2025-4516 https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142 https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e https://github.com/python/cpython/issues/133767 https://github.com/python/cpython/pull/129648 https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4516.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ngbKDtxhn33NKWC2lhOQNQ==": { "id": "ngbKDtxhn33NKWC2lhOQNQ==", "updater": "rhel-vex", "name": "CVE-2026-1485", "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1485 https://bugzilla.redhat.com/show_bug.cgi?id=2433325 https://www.cve.org/CVERecord?id=CVE-2026-1485 https://nvd.nist.gov/vuln/detail/CVE-2026-1485 https://gitlab.gnome.org/GNOME/glib/-/issues/3871 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1485.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nhJPQpDYg9We/U8oBJw4JQ==": { "id": "nhJPQpDYg9We/U8oBJw4JQ==", "updater": "rhel-vex", "name": "CVE-2026-6019", "description": "A flaw was found in Python's `http.cookies` module. The `Morsel.js_output()` function, responsible for generating JavaScript output for cookies, does not properly neutralize the `\u003c/script\u003e` HTML sequence. This oversight could allow a remote attacker to inject malicious script into a web page, potentially leading to Cross-Site Scripting (XSS) attacks. Such an attack could result in information disclosure or arbitrary code execution within the user's browser.", "issued": "2026-04-22T19:28:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6019 https://bugzilla.redhat.com/show_bug.cgi?id=2460869 https://www.cve.org/CVERecord?id=CVE-2026-6019 https://nvd.nist.gov/vuln/detail/CVE-2026-6019 https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104 https://github.com/python/cpython/issues/90309 https://github.com/python/cpython/pull/148848 https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6019.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "noXaVqkCbpzn51NS8fKFEA==": { "id": "noXaVqkCbpzn51NS8fKFEA==", "updater": "rhel-vex", "name": "CVE-2026-7168", "description": "A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user.", "issued": "2026-05-13T08:29:08Z", "links": "https://access.redhat.com/security/cve/CVE-2026-7168 https://bugzilla.redhat.com/show_bug.cgi?id=2476979 https://www.cve.org/CVERecord?id=CVE-2026-7168 https://nvd.nist.gov/vuln/detail/CVE-2026-7168 http://www.openwall.com/lists/oss-security/2026/04/29/14 https://curl.se/docs/CVE-2026-7168.html https://curl.se/docs/CVE-2026-7168.json https://hackerone.com/reports/3697719 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7168.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "npBrFSWnZYxq9cizdfDfCQ==": { "id": "npBrFSWnZYxq9cizdfDfCQ==", "updater": "rhel-vex", "name": "CVE-2026-1489", "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1489 https://bugzilla.redhat.com/show_bug.cgi?id=2433348 https://www.cve.org/CVERecord?id=CVE-2026-1489 https://nvd.nist.gov/vuln/detail/CVE-2026-1489 https://gitlab.gnome.org/GNOME/glib/-/issues/3872 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1489.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "npQpPXYG8xMJ1LRSVSnKGA==": { "id": "npQpPXYG8xMJ1LRSVSnKGA==", "updater": "rhel-vex", "name": "CVE-2025-8114", "description": "A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.", "issued": "2025-07-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-8114 https://bugzilla.redhat.com/show_bug.cgi?id=2383220 https://www.cve.org/CVERecord?id=CVE-2025-8114 https://nvd.nist.gov/vuln/detail/CVE-2025-8114 https://git.libssh.org/projects/libssh.git/commit/?id=53ac23ded4cb2c5463f6c4cd1525331bd578812d https://git.libssh.org/projects/libssh.git/commit/?id=65f363c9 https://www.libssh.org/security/advisories/CVE-2025-8114.txt https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-8114.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "o8knMpkoquoumaFb+1FM4A==": { "id": "o8knMpkoquoumaFb+1FM4A==", "updater": "rhel-vex", "name": "CVE-2026-58055", "description": "A flaw in nghttp2's nghttpx proxy allows a remote attacker to perform HTTP request smuggling and cross-client response-queue poisoning. This occurs because the proxy ambiguously forwards HTTP/1.1 Upgrade requests that contain a Content-Length header to reusable keep-alive backend connections.", "issued": "2026-06-28T01:32:57Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58055 https://bugzilla.redhat.com/show_bug.cgi?id=2493954 https://www.cve.org/CVERecord?id=CVE-2026-58055 https://nvd.nist.gov/vuln/detail/CVE-2026-58055 https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58055.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "nghttp2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oWl6C8goK/FnQDlax8YX9Q==": { "id": "oWl6C8goK/FnQDlax8YX9Q==", "updater": "rhel-vex", "name": "CVE-2026-42771", "description": "A flaw was found in OpenSSL. When an application uses the X509_VERIFY_PARAM_set1_email() function to validate a specially crafted S/MIME (Secure/Multipurpose Internet Mail Extensions) email address, an out-of-bounds read can occur. A remote attacker could exploit this vulnerability by sending a malicious email, leading to an application crash and a Denial of Service (DoS). This issue does not directly expose sensitive data.", "issued": "2026-07-10T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-42771 https://bugzilla.redhat.com/show_bug.cgi?id=2481895 https://www.cve.org/CVERecord?id=CVE-2026-42771 https://nvd.nist.gov/vuln/detail/CVE-2026-42771 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42771.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ofnnqzvHUpmPXQD17CK0Og==": { "id": "ofnnqzvHUpmPXQD17CK0Og==", "updater": "rhel-vex", "name": "CVE-2018-19211", "description": "A vulnerability was found in GNU ncurses due to a NULL pointer dereference in the _nc_parse_entry function within parse_entry.c, where an attacker could exploit this flaw by persuading a victim to open a specially crafted file, leading to a crash and causing a denial of service condition.", "issued": "2018-10-28T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-19211 https://bugzilla.redhat.com/show_bug.cgi?id=1652600 https://www.cve.org/CVERecord?id=CVE-2018-19211 https://nvd.nist.gov/vuln/detail/CVE-2018-19211 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-19211.json", "severity": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qC/lM94bJkHuTCcx6Z47mQ==": { "id": "qC/lM94bJkHuTCcx6Z47mQ==", "updater": "rhel-vex", "name": "CVE-2026-32778", "description": "A flaw was found in libexpat. This vulnerability allows an attacker to trigger a NULL pointer dereference in the `setContext` function. This occurs when the system attempts to retry an operation after an out-of-memory condition, which can lead to a Denial of Service (DoS) for the affected application.", "issued": "2026-03-16T07:02:34Z", "links": "https://access.redhat.com/security/cve/CVE-2026-32778 https://bugzilla.redhat.com/show_bug.cgi?id=2447885 https://www.cve.org/CVERecord?id=CVE-2026-32778 https://nvd.nist.gov/vuln/detail/CVE-2026-32778 https://github.com/libexpat/libexpat/pull/1159 https://github.com/libexpat/libexpat/pull/1163 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32778.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qXNASosSuCsudML1MqXPjw==": { "id": "qXNASosSuCsudML1MqXPjw==", "updater": "rhel-vex", "name": "CVE-2023-27534", "description": "A path traversal vulnerability exists in curl \u003c8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.", "issued": "2023-03-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-27534 https://bugzilla.redhat.com/show_bug.cgi?id=2179069 https://www.cve.org/CVERecord?id=CVE-2023-27534 https://nvd.nist.gov/vuln/detail/CVE-2023-27534 https://curl.se/docs/CVE-2023-27534.html https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27534.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qld8Wk8WGHJZFjcPP6Ptwg==": { "id": "qld8Wk8WGHJZFjcPP6Ptwg==", "updater": "rhel-vex", "name": "CVE-2026-40468", "description": "A flaw was found in gawk. An integer overflow vulnerability could allow a local attacker to cause memory exhaustion, leading to a denial of service. This flaw may also enable an attacker to corrupt gawk's internal memory, potentially leading to system instability.", "issued": "2026-07-13T12:07:54Z", "links": "https://access.redhat.com/security/cve/CVE-2026-40468 https://bugzilla.redhat.com/show_bug.cgi?id=2499655 https://www.cve.org/CVERecord?id=CVE-2026-40468 https://nvd.nist.gov/vuln/detail/CVE-2026-40468 https://cert.pl/en/posts/2026/07/CVE-2026-40467 https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40468.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "gawk", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rEd6JdG2xx5NZ9bcsFRNpw==": { "id": "rEd6JdG2xx5NZ9bcsFRNpw==", "updater": "rhel-vex", "name": "CVE-2026-28388", "description": "A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application.", "issued": "2026-04-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-28388 https://bugzilla.redhat.com/show_bug.cgi?id=2451097 https://www.cve.org/CVERecord?id=CVE-2026-28388 https://nvd.nist.gov/vuln/detail/CVE-2026-28388 https://openssl-library.org/news/secadv/20260407.txt https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28388.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rEg00U8+//igCt+0+QBUhA==": { "id": "rEg00U8+//igCt+0+QBUhA==", "updater": "rhel-vex", "name": "CVE-2023-50495", "description": "A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry().", "issued": "2023-12-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-50495 https://bugzilla.redhat.com/show_bug.cgi?id=2254244 https://www.cve.org/CVERecord?id=CVE-2023-50495 https://nvd.nist.gov/vuln/detail/CVE-2023-50495 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-50495.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rP7oa42+SZpvxen+n93BaQ==": { "id": "rP7oa42+SZpvxen+n93BaQ==", "updater": "rhel-vex", "name": "CVE-2026-58010", "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses \u003e instead of \u003e=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.", "issued": "2026-03-26T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58010 https://bugzilla.redhat.com/show_bug.cgi?id=2492243 https://www.cve.org/CVERecord?id=CVE-2026-58010 https://nvd.nist.gov/vuln/detail/CVE-2026-58010 https://gitlab.gnome.org/GNOME/glib/-/issues/3915 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58010.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rVgBV65FWtFg3jitEqotFA==": { "id": "rVgBV65FWtFg3jitEqotFA==", "updater": "rhel-vex", "name": "CVE-2024-0727", "description": "A flaw was found in OpenSSL. The optional ContentInfo fields can be set to null, even if the \"type\" is a valid value, which can lead to a null dereference error that may cause a denial of service.", "issued": "2024-01-22T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2024-0727 https://bugzilla.redhat.com/show_bug.cgi?id=2259944 https://www.cve.org/CVERecord?id=CVE-2024-0727 https://nvd.nist.gov/vuln/detail/CVE-2024-0727 https://github.com/openssl/openssl/pull/23362 https://www.openssl.org/news/secadv/20240125.txt https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0727.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ruDQdx7OmIsgMCpioWbqOQ==": { "id": "ruDQdx7OmIsgMCpioWbqOQ==", "updater": "rhel-vex", "name": "CVE-2025-5351", "description": "A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.", "issued": "2025-06-24T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-5351 https://bugzilla.redhat.com/show_bug.cgi?id=2369367 https://www.cve.org/CVERecord?id=CVE-2025-5351 https://nvd.nist.gov/vuln/detail/CVE-2025-5351 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5351.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "s7NZ7NlWAuuGAV0/d83+kA==": { "id": "s7NZ7NlWAuuGAV0/d83+kA==", "updater": "rhel-vex", "name": "CVE-2026-13346", "description": "A flaw was found in pip. When processing doubly-encoded package URLs from malicious package indexes, pip incorrectly handles the file paths. A remote attacker could exploit this by convincing a user to download or install a package from such an index. This could allow for files to be installed to arbitrary locations on the system, potentially leading to system compromise. This vulnerability primarily affects users utilizing the `pip download` command with the `--only-binary` option.", "issued": "2026-07-29T18:33:50Z", "links": "https://access.redhat.com/security/cve/CVE-2026-13346 https://bugzilla.redhat.com/show_bug.cgi?id=2508514 https://www.cve.org/CVERecord?id=CVE-2026-13346 https://nvd.nist.gov/vuln/detail/CVE-2026-13346 https://github.com/pypa/pip/pull/14110 https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13346.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "python-pip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sExC9WXn4M01POjg0haQrA==": { "id": "sExC9WXn4M01POjg0haQrA==", "updater": "rhel-vex", "name": "CVE-2026-34933", "description": "A flaw was found in Avahi. An unprivileged local user can exploit this vulnerability by sending a D-Bus method call with conflicting publish flags. This can lead to a denial of service (DoS) by crashing the avahi-daemon, making the service unavailable.", "issued": "2026-04-03T22:43:26Z", "links": "https://access.redhat.com/security/cve/CVE-2026-34933 https://bugzilla.redhat.com/show_bug.cgi?id=2454978 https://www.cve.org/CVERecord?id=CVE-2026-34933 https://nvd.nist.gov/vuln/detail/CVE-2026-34933 https://github.com/avahi/avahi/commit/625ca0fac19229f6dfa3a6c6b698ae657187e50c https://github.com/avahi/avahi/pull/891 https://github.com/avahi/avahi/security/advisories/GHSA-w65r-6gxh-vhvc https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34933.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "avahi", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sGwL9v57mGx7f18qBkIacA==": { "id": "sGwL9v57mGx7f18qBkIacA==", "updater": "rhel-vex", "name": "CVE-2025-6075", "description": "A vulnerability in Python’s os.path.expandvars() function that can cause performance degradation. When processing specially crafted, user-controlled input with nested environment variable patterns, the function exhibits quadratic time complexity, potentially leading to excessive CPU usage and denial of service (DoS) conditions. No code execution or data exposure occurs, so the impact is limited to performance slowdown.", "issued": "2025-10-31T16:41:34Z", "links": "https://access.redhat.com/security/cve/CVE-2025-6075 https://bugzilla.redhat.com/show_bug.cgi?id=2408891 https://www.cve.org/CVERecord?id=CVE-2025-6075 https://nvd.nist.gov/vuln/detail/CVE-2025-6075 https://github.com/python/cpython/issues/136065 https://mail.python.org/archives/list/security-announce@python.org/thread/IUP5QJ6D4KK6ULHOMPC7DPNKRYQTQNLA/ https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6075.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sRVcQFAdq4Ll42smqacaCw==": { "id": "sRVcQFAdq4Ll42smqacaCw==", "updater": "rhel-vex", "name": "CVE-2022-27943", "description": "A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service.", "issued": "2022-03-26T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2022-27943 https://bugzilla.redhat.com/show_bug.cgi?id=2071728 https://www.cve.org/CVERecord?id=CVE-2022-27943 https://nvd.nist.gov/vuln/detail/CVE-2022-27943 https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-27943.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "gcc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sThg2GGoKqa1RTJ5skEJTA==": { "id": "sThg2GGoKqa1RTJ5skEJTA==", "updater": "rhel-vex", "name": "CVE-2026-24883", "description": "A flaw was found in GnuPG. A remote attacker could provide a specially crafted long signature packet that, when processed, causes the application to crash. This vulnerability leads to a denial of service (DoS), making the GnuPG application unavailable to legitimate users.", "issued": "2026-01-27T18:43:18Z", "links": "https://access.redhat.com/security/cve/CVE-2026-24883 https://bugzilla.redhat.com/show_bug.cgi?id=2433463 https://www.cve.org/CVERecord?id=CVE-2026-24883 https://nvd.nist.gov/vuln/detail/CVE-2026-24883 https://dev.gnupg.org/T8049 https://www.openwall.com/lists/oss-security/2026/01/27/8 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24883.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "srdggAxrYxj8SIe8dBdTNA==": { "id": "srdggAxrYxj8SIe8dBdTNA==", "updater": "rhel-vex", "name": "CVE-2026-11979", "description": "A flaw was found in libxml2, specifically within the xmlcatalog utility when operating in shell mode. An attacker can exploit multiple stack-based buffer overflows by providing an excessively long input line. This leads to memory corruption, which may cause the application to crash or potentially allow the attacker to execute arbitrary code within the context of the xmlcatalog process.", "issued": "2026-06-29T13:21:42Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11979 https://bugzilla.redhat.com/show_bug.cgi?id=2494191 https://www.cve.org/CVERecord?id=CVE-2026-11979 https://nvd.nist.gov/vuln/detail/CVE-2026-11979 https://cert.pl/en/posts/2026/06/CVE-2026-11979 https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11979.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "t3XJyztcU9aOXTMLI8NRmA==": { "id": "t3XJyztcU9aOXTMLI8NRmA==", "updater": "rhel-vex", "name": "CVE-2026-29111", "description": "A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).", "issued": "2026-03-23T21:03:56Z", "links": "https://access.redhat.com/security/cve/CVE-2026-29111 https://bugzilla.redhat.com/show_bug.cgi?id=2450505 https://www.cve.org/CVERecord?id=CVE-2026-29111 https://nvd.nist.gov/vuln/detail/CVE-2026-29111 https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6 https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8 https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29111.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "t4oe6DBPNf5Ikk93RfTdig==": { "id": "t4oe6DBPNf5Ikk93RfTdig==", "updater": "rhel-vex", "name": "CVE-2019-12904", "description": "[Disputed] A vulnerability has been identified in Libgcrypt due to a flaw in its C implementation of AES. This vulnerability enables a remote attacker to perform a flush-and-reload side-channel attack, potentially accessing sensitive information. The vulnerability arises from the availability of physical addresses to other processes, particularly on platforms lacking an assembly-language implementation.", "issued": "2019-07-16T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-12904 https://bugzilla.redhat.com/show_bug.cgi?id=1730320 https://www.cve.org/CVERecord?id=CVE-2019-12904 https://nvd.nist.gov/vuln/detail/CVE-2019-12904 https://dev.gnupg.org/T4541 https://lists.gnupg.org/pipermail/gcrypt-devel/2019-July/004760.html https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-12904.html https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-12904.json", "severity": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "libgcrypt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tGsvzSy2YAolN7IIXG6tpA==": { "id": "tGsvzSy2YAolN7IIXG6tpA==", "updater": "rhel-vex", "name": "CVE-2019-9936", "description": "A vulnerability was found in SQLite, where a heap-based buffer over-read occurs in the fts5HashEntrySort function within sqlite3.c, an attacker could exploit this vulnerability by running specially crafted queries, lead to an information leak.", "issued": "2019-03-18T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2019-9936 https://bugzilla.redhat.com/show_bug.cgi?id=1692365 https://www.cve.org/CVERecord?id=CVE-2019-9936 https://nvd.nist.gov/vuln/detail/CVE-2019-9936 https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-9936.json", "severity": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tYeLT/YUKIk7yaK07WvPeA==": { "id": "tYeLT/YUKIk7yaK07WvPeA==", "updater": "rhel-vex", "name": "CVE-2026-32776", "description": "A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted XML content with empty external parameter entities. This could lead to a NULL pointer dereference, causing the application to crash and resulting in a Denial of Service (DoS).", "issued": "2026-03-16T06:54:20Z", "links": "https://access.redhat.com/security/cve/CVE-2026-32776 https://bugzilla.redhat.com/show_bug.cgi?id=2447888 https://www.cve.org/CVERecord?id=CVE-2026-32776 https://nvd.nist.gov/vuln/detail/CVE-2026-32776 https://github.com/libexpat/libexpat/pull/1158 https://github.com/libexpat/libexpat/pull/1159 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32776.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tYyvZPBVQRP63VPhfANtWw==": { "id": "tYyvZPBVQRP63VPhfANtWw==", "updater": "rhel-vex", "name": "CVE-2026-56407", "description": "An integer overflow exists in libexpat's doProlog function due to improper handling of entity value lengths. A local attacker could exploit this to execute arbitrary code or access sensitive system data.", "issued": "2026-06-21T15:49:35Z", "links": "https://access.redhat.com/security/cve/CVE-2026-56407 https://bugzilla.redhat.com/show_bug.cgi?id=2491184 https://www.cve.org/CVERecord?id=CVE-2026-56407 https://nvd.nist.gov/vuln/detail/CVE-2026-56407 https://github.com/libexpat/libexpat/pull/1262 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56407.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "teoauN/Djw6odXikmjP4Lw==": { "id": "teoauN/Djw6odXikmjP4Lw==", "updater": "rhel-vex", "name": "CVE-2025-68471", "description": "A flaw was found in Avahi, a system that enables devices to discover services on a local network using the mDNS/DNS-SD (Multicast Domain Name System/DNS-based Service Discovery) protocols. A remote attacker can exploit this by sending two specific network messages, known as unsolicited announcements with CNAME resource records, within a two-second timeframe. This action can cause the `avahi-daemon` process to crash, leading to a Denial of Service (DoS) for the affected system.", "issued": "2026-01-12T17:39:57Z", "links": "https://access.redhat.com/security/cve/CVE-2025-68471 https://bugzilla.redhat.com/show_bug.cgi?id=2428717 https://www.cve.org/CVERecord?id=CVE-2025-68471 https://nvd.nist.gov/vuln/detail/CVE-2025-68471 https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1 https://github.com/avahi/avahi/issues/678 https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68471.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "avahi", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tlWVK61iOpKPkvmeShS9AQ==": { "id": "tlWVK61iOpKPkvmeShS9AQ==", "updater": "rhel-vex", "name": "CVE-2025-69421", "description": "A flaw was found in OpenSSL. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by providing a specially crafted, malformed PKCS#12 file to an application that processes it. The flaw occurs due to a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function when handling the malformed file, leading to an application crash.", "issued": "2026-01-27T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-69421 https://bugzilla.redhat.com/show_bug.cgi?id=2430387 https://www.cve.org/CVERecord?id=CVE-2025-69421 https://nvd.nist.gov/vuln/detail/CVE-2025-69421 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69421.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tnBbKyfWYMq7GMqd8UCfIw==": { "id": "tnBbKyfWYMq7GMqd8UCfIw==", "updater": "rhel-vex", "name": "CVE-2025-70873", "description": "A flaw was found in SQLite. This information disclosure vulnerability exists within the zipfile extension, specifically in the zipfileInflate function. A remote attacker could exploit this by providing a specially crafted ZIP file. Successful exploitation could lead to the disclosure of sensitive heap memory information.", "issued": "2026-03-12T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-70873 https://bugzilla.redhat.com/show_bug.cgi?id=2447086 https://www.cve.org/CVERecord?id=CVE-2025-70873 https://nvd.nist.gov/vuln/detail/CVE-2025-70873 https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054 https://sqlite.org/forum/forumpost/761eac3c82 https://sqlite.org/src/info/3d459f1fb1bd1b5e https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-70873.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uEggs7thHCRp4eZu5EDH0A==": { "id": "uEggs7thHCRp4eZu5EDH0A==", "updater": "rhel-vex", "name": "CVE-2026-27171", "description": "A flaw was found in zlib. An attacker providing specially crafted input to the `crc32_combine64` or `crc32_combine_gen64` functions could trigger an infinite loop within the `x2nmodp` function. This leads to excessive CPU consumption, which can result in a Denial of Service (DoS) for the affected system.", "issued": "2026-02-18T02:36:19Z", "links": "https://access.redhat.com/security/cve/CVE-2026-27171 https://bugzilla.redhat.com/show_bug.cgi?id=2440530 https://www.cve.org/CVERecord?id=CVE-2026-27171 https://nvd.nist.gov/vuln/detail/CVE-2026-27171 https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/ https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf https://github.com/madler/zlib/issues/904 https://github.com/madler/zlib/releases/tag/v1.3.2 https://ostif.org/zlib-audit-complete/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27171.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "zlib", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "usSOeO0eis4fMxpUrYF1Og==": { "id": "usSOeO0eis4fMxpUrYF1Og==", "updater": "rhel-vex", "name": "CVE-2026-11856", "description": "A flaw was found in curl. When `libcurl` performs a transfer to an HTTP origin using Digest authentication and then reuses the same connection handle for a subsequent transfer to a different origin, it may incorrectly send the authentication header intended for the first origin to the second. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data.", "issued": "2026-07-03T06:13:31Z", "links": "https://access.redhat.com/security/cve/CVE-2026-11856 https://bugzilla.redhat.com/show_bug.cgi?id=2496767 https://www.cve.org/CVERecord?id=CVE-2026-11856 https://nvd.nist.gov/vuln/detail/CVE-2026-11856 https://curl.se/docs/CVE-2026-11856.html https://curl.se/docs/CVE-2026-11856.json https://hackerone.com/reports/3793260 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11856.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "v1exQXePimNPt3tveLBP9g==": { "id": "v1exQXePimNPt3tveLBP9g==", "updater": "rhel-vex", "name": "CVE-2026-1965", "description": "A flaw was found in curl. When an application uses libcurl to make multiple Negotiate-authenticated HTTP or HTTPS requests to the same server with different credentials, libcurl may incorrectly reuse an existing connection. This logical error can cause a subsequent request to be sent using the authentication of a previous user, leading to an authentication bypass.", "issued": "2026-03-11T10:08:52Z", "links": "https://access.redhat.com/security/cve/CVE-2026-1965 https://bugzilla.redhat.com/show_bug.cgi?id=2446448 https://www.cve.org/CVERecord?id=CVE-2026-1965 https://nvd.nist.gov/vuln/detail/CVE-2026-1965 https://curl.se/docs/CVE-2026-1965.html https://curl.se/docs/CVE-2026-1965.json https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1965.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vTJZ/R8pdcyDbwAwRi8cBw==": { "id": "vTJZ/R8pdcyDbwAwRi8cBw==", "updater": "rhel-vex", "name": "CVE-2025-15079", "description": "A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks.", "issued": "2026-01-07T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-15079 https://bugzilla.redhat.com/show_bug.cgi?id=2426409 https://www.cve.org/CVERecord?id=CVE-2025-15079 https://nvd.nist.gov/vuln/detail/CVE-2025-15079 https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15079.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vx2N2RZTm7neux8kVlqgEg==": { "id": "vx2N2RZTm7neux8kVlqgEg==", "updater": "rhel-vex", "name": "CVE-2026-5704", "description": "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.", "issued": "2026-04-06T13:36:20Z", "links": "https://access.redhat.com/security/cve/CVE-2026-5704 https://bugzilla.redhat.com/show_bug.cgi?id=2455360 https://www.cve.org/CVERecord?id=CVE-2026-5704 https://nvd.nist.gov/vuln/detail/CVE-2026-5704 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5704.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wbBiCPikq6Iz02EPsysTgA==": { "id": "wbBiCPikq6Iz02EPsysTgA==", "updater": "rhel-vex", "name": "CVE-2025-14017", "description": "A flaw was found in curl. When performing multi-threaded LDAPS (Lightweight Directory Access Protocol Secure) transfers, changes to Transport Layer Security (TLS) options in one thread could inadvertently apply globally, affecting other concurrent transfers. This could lead to unintended security posture changes, such as disabling certificate verification for other threads. This vulnerability can result in a security bypass, where expected security checks are not performed.", "issued": "2026-01-08T10:07:05Z", "links": "https://access.redhat.com/security/cve/CVE-2025-14017 https://bugzilla.redhat.com/show_bug.cgi?id=2427870 https://www.cve.org/CVERecord?id=CVE-2025-14017 https://nvd.nist.gov/vuln/detail/CVE-2025-14017 https://curl.se/docs/CVE-2025-14017.html https://curl.se/docs/CVE-2025-14017.json https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14017.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wxS+u/uf8o4sT9iSccXQwA==": { "id": "wxS+u/uf8o4sT9iSccXQwA==", "updater": "rhel-vex", "name": "CVE-2026-4426", "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.", "issued": "2026-03-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4426 https://bugzilla.redhat.com/show_bug.cgi?id=2449010 https://www.cve.org/CVERecord?id=CVE-2026-4426 https://nvd.nist.gov/vuln/detail/CVE-2026-4426 https://github.com/libarchive/libarchive/pull/2897 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4426.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Medium", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "x6XC/EvXu5oMyj7ZxrTczA==": { "id": "x6XC/EvXu5oMyj7ZxrTczA==", "updater": "rhel-vex", "name": "CVE-2026-4360", "description": "A flaw was found in the Python `Tarfile.extract()` function. This vulnerability occurs when processing untrusted tar files containing hardlinks, as the `filter` parameter is not correctly enforced. An attacker could exploit this to write files with unintended user or group ownership, potentially leading to unauthorized modifications or privilege issues on the system.", "issued": "2026-06-30T14:45:35Z", "links": "https://access.redhat.com/security/cve/CVE-2026-4360 https://bugzilla.redhat.com/show_bug.cgi?id=2494987 https://www.cve.org/CVERecord?id=CVE-2026-4360 https://nvd.nist.gov/vuln/detail/CVE-2026-4360 https://github.com/python/cpython/issues/151987 https://github.com/python/cpython/pull/151988 https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/ https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4360.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xC2ob9wKqI1kERs3y1j4vA==": { "id": "xC2ob9wKqI1kERs3y1j4vA==", "updater": "rhel-vex", "name": "CVE-2026-18508", "description": "A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.", "issued": "2026-07-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-18508 https://bugzilla.redhat.com/show_bug.cgi?id=2509843 https://www.cve.org/CVERecord?id=CVE-2026-18508 https://nvd.nist.gov/vuln/detail/CVE-2026-18508 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18508.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xCUiEQAH1lfhrKtUxQDIYA==": { "id": "xCUiEQAH1lfhrKtUxQDIYA==", "updater": "rhel-vex", "name": "CVE-2021-39537", "description": "A heap overflow vulnerability has been identified in the ncurses package, particularly in the \"tic\". This flaw results from a lack of proper bounds checking during input processing. By exploiting this boundary error, an attacker can create a malicious file, deceive the victim into opening it using the affected software, and initiate an out-of-bounds write, potentially impacting system availability.", "issued": "2020-08-04T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2021-39537 https://bugzilla.redhat.com/show_bug.cgi?id=2006978 https://www.cve.org/CVERecord?id=CVE-2021-39537 https://nvd.nist.gov/vuln/detail/CVE-2021-39537 https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-39537.json", "severity": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xKLQGv5zNwcnWtQQKiO3Ww==": { "id": "xKLQGv5zNwcnWtQQKiO3Ww==", "updater": "rhel-vex", "name": "CVE-2026-25645", "description": "A flaw was found in the `requests` HTTP library, specifically in the `requests.utils.extract_zipped_paths()` function, which is used to load Certificate Authority (CA) bundles. A local attacker can exploit this vulnerability by pre-creating a malicious CA bundle file in the system's temporary directory. When a vulnerable application initializes the `requests` library, it may load this malicious file instead of the legitimate CA bundle, leading to a bypass of security controls and potential integrity compromise.", "issued": "2026-03-25T17:02:48Z", "links": "https://access.redhat.com/security/cve/CVE-2026-25645 https://bugzilla.redhat.com/show_bug.cgi?id=2451408 https://www.cve.org/CVERecord?id=CVE-2026-25645 https://nvd.nist.gov/vuln/detail/CVE-2026-25645 https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7 https://github.com/psf/requests/releases/tag/v2.33.0 https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25645.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "python-pip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xLIujTim86EomaRofe4tDg==": { "id": "xLIujTim86EomaRofe4tDg==", "updater": "rhel-vex", "name": "CVE-2023-32611", "description": "A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.", "issued": "2022-12-14T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2023-32611 https://bugzilla.redhat.com/show_bug.cgi?id=2211829 https://www.cve.org/CVERecord?id=CVE-2023-32611 https://nvd.nist.gov/vuln/detail/CVE-2023-32611 https://gitlab.gnome.org/GNOME/glib/-/issues/2797 https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-32611.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "normalized_severity": "Low", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xjRJnKlNaH/FGi0NN5VKBQ==": { "id": "xjRJnKlNaH/FGi0NN5VKBQ==", "updater": "rhel-vex", "name": "CVE-2026-0992", "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated \u003cnextCatalog\u003e elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.", "issued": "2026-01-15T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-0992 https://bugzilla.redhat.com/show_bug.cgi?id=2429975 https://www.cve.org/CVERecord?id=CVE-2026-0992 https://nvd.nist.gov/vuln/detail/CVE-2026-0992 https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0992.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "y9TonkypWBSeUSxUDKIRrw==": { "id": "y9TonkypWBSeUSxUDKIRrw==", "updater": "rhel-vex", "name": "CVE-2026-18477", "description": "A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.", "issued": "2026-07-31T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-18477 https://bugzilla.redhat.com/show_bug.cgi?id=2509735 https://www.cve.org/CVERecord?id=CVE-2026-18477 https://nvd.nist.gov/vuln/detail/CVE-2026-18477 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18477.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yiTWIBfruE5rPxLBPqTezA==": { "id": "yiTWIBfruE5rPxLBPqTezA==", "updater": "rhel-vex", "name": "CVE-2018-1000880", "description": "A vulnerability was found in libarchive, where improper input validation in the _warc_read function in libarchive/archive_read_support_format_warc.c can lead to a denial of service, a remote attacker could exploit this flaw by persuading a victim to open a specially crafted file, causing the application to crash.", "issued": "2018-11-20T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2018-1000880 https://bugzilla.redhat.com/show_bug.cgi?id=1663892 https://www.cve.org/CVERecord?id=CVE-2018-1000880 https://nvd.nist.gov/vuln/detail/CVE-2018-1000880 https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-1000880.json", "severity": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "libarchive", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yrec5aYK5L1Cn+46ZF7wbw==": { "id": "yrec5aYK5L1Cn+46ZF7wbw==", "updater": "rhel-vex", "name": "CVE-2026-6253", "description": "A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials.", "issued": "2026-04-29T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-6253 https://bugzilla.redhat.com/show_bug.cgi?id=2461202 https://www.cve.org/CVERecord?id=CVE-2026-6253 https://nvd.nist.gov/vuln/detail/CVE-2026-6253 https://curl.se/docs/CVE-2026-6253.html https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6253.json", "severity": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N", "normalized_severity": "Medium", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yuFlxOGqQlDuMCywIIELNw==": { "id": "yuFlxOGqQlDuMCywIIELNw==", "updater": "rhel-vex", "name": "CVE-2025-30258", "description": "A flaw was found in GnuPG. In affected versions, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, leading to a verification denial of service.", "issued": "2025-03-19T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2025-30258 https://bugzilla.redhat.com/show_bug.cgi?id=2353427 https://www.cve.org/CVERecord?id=CVE-2025-30258 https://nvd.nist.gov/vuln/detail/CVE-2025-30258 https://dev.gnupg.org/T7527 https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158 https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-30258.json", "severity": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zWleXlh1b6JsvwGVnX0JVA==": { "id": "zWleXlh1b6JsvwGVnX0JVA==", "updater": "rhel-vex", "name": "CVE-2026-8286", "description": "A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.", "issued": "2026-07-03T06:14:17Z", "links": "https://access.redhat.com/security/cve/CVE-2026-8286 https://bugzilla.redhat.com/show_bug.cgi?id=2496763 https://www.cve.org/CVERecord?id=CVE-2026-8286 https://nvd.nist.gov/vuln/detail/CVE-2026-8286 https://curl.se/docs/CVE-2026-8286.html https://curl.se/docs/CVE-2026-8286.json https://hackerone.com/reports/3718195 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8286.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "normalized_severity": "High", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zXrrwuYD9wK+seRCGBDutA==": { "id": "zXrrwuYD9wK+seRCGBDutA==", "updater": "rhel-vex", "name": "CVE-2026-58013", "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.", "issued": "2026-04-03T00:00:00Z", "links": "https://access.redhat.com/security/cve/CVE-2026-58013 https://bugzilla.redhat.com/show_bug.cgi?id=2492248 https://www.cve.org/CVERecord?id=CVE-2026-58013 https://nvd.nist.gov/vuln/detail/CVE-2026-58013 https://gitlab.gnome.org/GNOME/glib/-/issues/3925 https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58013.json", "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "normalized_severity": "Medium", "package": { "id": "", "name": "glib2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "", "name": "", "version": "", "version_code_name": "", "version_id": "", "arch": "", "cpe": "", "pretty_name": "" }, "repository": { "name": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*", "key": "rhel-cpe-repository", "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:*:*:*:*:*:*" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false } }, "package_vulnerabilities": { "+hvIC0Et/RtHi7EAFCmfEw==": [ "dGtImtgXxemdBTM1vCCLUg==", "+et2nlLBpUOdsIiOQHCCVQ==" ], "+qrxjVH7Im8eBfrz4h4P/w==": [ "Zp9+pixFuNBueE2yO610gQ==" ], "2gKctomQ2vBMxlyAOjcc7g==": [ "k3o+5yuHivArIfBtIXx02Q==" ], "6TosRb2Tsu+lux2SVlDfZw==": [ "iP8YLvnxQemAwp/nhhOW0w==", "IItHEdPWz5fl9O7ZhzjDAA==", "0QzoXQSqkKieJ7Oc+px0JA==", "nhJPQpDYg9We/U8oBJw4JQ==", "ZlxfTVb/4bi6yWQ+JLaOnw==", "HKrLnQyTw1292mNt3MQ0aQ==", "h6rS2s3xilGaG0a+pIjl8A==", "Z98lUsU1mVOsrmb49hActA==", "2U8ppg+02PjFDuM5YqFstQ==", "L3k0cIIlkMGQFiWnZm8Mlg==", "/jsmptxiHRXbuYhopHC+AQ==", "OFdQC3/0S5rItoyqpACTFw==", "HB9r/GLycEmk6aXttwtBlw==", "cCowLuOsLfTMmPFOoqUVww==", "eO2vvxX2WuQSx4VuCGHAwQ==", "5ZHvcDYhgzWjwNpRgF2u1w==", "Fd2ov7jSJY3Im+378GMgdA==", "fg5E5MKinCbJn9w+SABeOA==", "8rvqTFlh9aOz4UvxQN0SBQ==", "RVCidRUm4D1IKoPhoUi2AA==", "6Xr5PbPGSy+aHLDQ9q4L9w==", "8qOJVWAut1+UqTXPOWH12g==", "x6XC/EvXu5oMyj7ZxrTczA==", "sGwL9v57mGx7f18qBkIacA==", "nYtstWEUOCTbjAlmYOKURA==", "XXiaw1EwhFkuilI94EKiqQ==", "mRazAXjBcgFrTolNDZHDsA==" ], "7ImMeyXZ75qIGtloaQtHNw==": [ "EiJx6rOT8KoLX+Wu7/N6HQ==", "RXjd5U95osIGXnqCa34Jkg==", "G7IyfoPhe9f8QzIGbOfn7Q==", "7Puka2o1jq4jSr2Hekrfhg==", "619DQiII/+IW12e6tmtrxw==", "xjRJnKlNaH/FGi0NN5VKBQ==", "CwmELSAfO/DM/HghGDWwow==", "srdggAxrYxj8SIe8dBdTNA==", "HdAyLUATPStr/HXiy9fgQw==" ], "7WjsyjO4dyAYyLB4UAj3bQ==": [ "Fp999hDC/lucBsNHwOlp/A==", "cERFf1oFvXQnx4BPCz9RhA==", "gagftKXuSuh9pi4dRu9yPQ==", "UPzTyNn8ZLXlb+bwRFPPTA==", "rVgBV65FWtFg3jitEqotFA==", "QUtTYJuHdkAOgtveagWUfA==", "F2aHNsZ7wIxMKRFoRhLULQ==", "VLzwKVDYC7fQrtcpCzjXjA==", "PcNbuWOo0ahqjfbOQhXvvQ==", "6FQUI3OxX4C5skWXKgq80Q==", "WcChSpNAL6V9Xfxc9AqW7g==", "BV++s35Ur4bQRS6HK0QCIA==", "OpUahpCA4oBceG962KxTMA==", "OLKvdPVgT9/lPcflJTxE3Q==", "rEd6JdG2xx5NZ9bcsFRNpw==", "LWLSX4FCLbzYWK97i5Or+A==", "/hG2eFl/EZ15/sR5oOZbCA==", "tlWVK61iOpKPkvmeShS9AQ==", "86unVXyTxdffdcXWZTYw5g==", "oWl6C8goK/FnQDlax8YX9Q==", "97PwDrD8knMveLXwKCvQjA==", "ZkEez7f24VNVhTaTCDhuEg==", "iFhWPnp6w/VV9hJa/b0oig==", "8D3i4K1ylUr5dGk9imV9zA==", "HDr4rB3dwHneK78KvohfHQ==", "6pD/2IKN8cR6N6PBQHwPrQ==" ], "9uhqFNTCJ7/bpzSlc7qCaQ==": [ "t4oe6DBPNf5Ikk93RfTdig==", "5e3gC+KDeb36jTLxBYtijg==", "fXpWtuXNPi3tb2edhk37bw==", "Zp5q2R9PHTn/pmrn158k9A==" ], "ACY3djwkey7ZIXbd0V+Giw==": [ "+nHq7dak7Hkjcru/xpwzhQ==", "L7QbkTbsy8v3tMfOqNsVKQ==" ], "AuC6XQzcU/5tB4luIfjLFg==": [ "HTk+AAyRWNCrZTtBLx34Aw==" ], "AzR13YeWt5QuEhdGyJ1bsQ==": [ "8rDgIikh0LbAtcEOjHed4Q==", "mVZw6HfBeWMeBMbQ3QI3eQ==", "6Cqvzp5JbuVfHsuYnIJNFw==", "cqYWiTibDLM7aibErMKang==" ], "AziZ1oGI+oDXVPzldKNj+w==": [ "3O4IzHXnRQMZXCe1gYATvw==" ], "BC2SLYOMYLcx8DhgPt8T+w==": [ "ZvX4VR3jvMBd1Wq+RxNTgg==" ], "BbZqfCvuyJyaO67Dr03HHg==": [ "KaROgE0QmtiOixMG9Wi1RA==", "CmGl35oJyKxCfItoqDiYoQ==", "0fCtWwB6iclgRvIA+IqiJQ==", "DoTF+GSVr6bH3qr9kb98Iw==", "EiL50P2QSOoRA18XAAH6Pg==", "EKs36DFwHVCzU/cF0Be9pQ==", "ngbKDtxhn33NKWC2lhOQNQ==", "rP7oa42+SZpvxen+n93BaQ==", "ElIjMFAz33tt/XVMysRkdA==", "Yruwfu4Vkg/KNSmhqw2VEg==", "zXrrwuYD9wK+seRCGBDutA==", "npBrFSWnZYxq9cizdfDfCQ==", "4jAWcNPbUa6mXzywmxFG1g==", "xLIujTim86EomaRofe4tDg==", "iEGZHZXt8HWPSM5eJesddQ==", "GWg5WOvOqfRt4sWhRhSM+A==", "YbAnIQEqWeedb46YJk3cBg==" ], "CP6fmHsRon29d9dGmAC8yQ==": [ "+nHq7dak7Hkjcru/xpwzhQ==", "L7QbkTbsy8v3tMfOqNsVKQ==" ], "CUMXU+cfm9pjhlqh7KtdUQ==": [ "1lUHOMB3ANHGWpqCBv9Ynw==", "BooDzA4nzaDI1l3E5zAHgg==", "2DLcncUUd6/1/JtsPnknxw==", "a067YUjLHWzR99JNl/RtGQ==", "t3XJyztcU9aOXTMLI8NRmA==" ], "DV119Dw0W4RdsbJkdoHU9w==": [ "AsUlQvbhYUzI8ZRGAIAAkw==", "yrec5aYK5L1Cn+46ZF7wbw==", "0v/g0Z/XEXV13r48i52JgA==", "J0YQQx6sv/Elt2kRDVPlXg==", "2U6d1qsPVwS8vUnflv9AcQ==", "TuBnhFrkwMqIcYtYYgNGNQ==", "v1exQXePimNPt3tveLBP9g==", "usSOeO0eis4fMxpUrYF1Og==", "PRkbEOx7V6ePRT/WUyklHg==", "Pe4IHqZpuBtuSkrgd2HMEg==", "8KJb4x3mXgChaQULEsid2A==", "jKke6Txz52GXq3xidnEMgg==", "crmilTSJ/pTSPBKY9EJmZg==", "qXNASosSuCsudML1MqXPjw==", "4JszZEguo/SAFbgp6PdKMQ==", "dYucp/SettSQd/Hpukj6pA==", "Znm2hdK/FULQhTTGTVX59Q==", "noXaVqkCbpzn51NS8fKFEA==", "zWleXlh1b6JsvwGVnX0JVA==", "fayrPya6DVXP9weWvA6obQ==", "wbBiCPikq6Iz02EPsysTgA==", "fT6cIVRM+743nfHJKo4yuQ==", "A0ZMrO+gsPP+1kjH7JYgNw==", "vTJZ/R8pdcyDbwAwRi8cBw==" ], "DgyhtZBcSIlVmY6xC8s1mA==": [ "eFkHRGAjSFu9sbgr+RArOA==", "U8up9/ZYW+CTO5UcJB1hZQ==", "WnU62DA2fwlfQLbeba0AYA==" ], "Dmgfuk4/ZGW2Pjrf3pzOwg==": [ "+nHq7dak7Hkjcru/xpwzhQ==", "L7QbkTbsy8v3tMfOqNsVKQ==" ], "FS5/DAbDsXWURU9onlACPA==": [ "Q5xJp4zJ1MCYcYbDi9qrdQ==" ], "IzLcxZDtcvtJR5Gwdq9HDg==": [ "7Fk3wVCUvtHC5JGu/YwCEw==" ], "J34PJ2GThOWZuKVgFIoieA==": [ "uEggs7thHCRp4eZu5EDH0A==" ], "JNDNKhJbFTSevs7EALfE9A==": [ "8WDcymWmuQ3Sn9ymHvtn4Q==" ], "KYSXsdsObSOPb3/iOOdbDw==": [ "+nHq7dak7Hkjcru/xpwzhQ==", "L7QbkTbsy8v3tMfOqNsVKQ==" ], "LXiVkIlXLq/usMYIwCTH8Q==": [ "WGvgNwrW2u5APZcidQ6v1Q==", "0IkIJ5q/xNX41U2yF71Pyw==" ], "N1RbIRo2SyHosQefv+skDw==": [ "R0kLLh/19P/mLd+t6ufaFg==", "UbmdE2pHXRFccv8l1e02Jw==", "mQtrNhzMQ9mAh/coURV/3g==", "qld8Wk8WGHJZFjcPP6Ptwg==" ], "N3ZaMrNJKoumMpaY0smlMQ==": [ "5B1tQ2BK8z/YjRkYcvwqag==", "tGsvzSy2YAolN7IIXG6tpA==", "tnBbKyfWYMq7GMqd8UCfIw==", "8ZxbhBIT+9Mj99/XbMpLSQ==", "CPZo3oXfySRcVVjDJkrS3g==", "mS0YOFVdBeDRbPVhCEovGQ==" ], "NguWV8S6YQYvQsGQDJm2Rg==": [ "ofnnqzvHUpmPXQD17CK0Og==", "673FKazcUiydbfN5c6amaw==", "jw1ZiDut5Ot+DyVFjCrixg==", "rEg00U8+//igCt+0+QBUhA==", "HuOxI+pWjgGV0XsBvltzlg==", "SHxE0qXbBmDEp/LL1ieJeA==", "xCUiEQAH1lfhrKtUxQDIYA==", "ZTGiJlkqcqrCLJSY/Sq8lA==", "VsocCwaFpF6PzdX5PxR+sQ==" ], "ORsDK2A5479NPB0r01PoXQ==": [ "AsUlQvbhYUzI8ZRGAIAAkw==", "yrec5aYK5L1Cn+46ZF7wbw==", "0v/g0Z/XEXV13r48i52JgA==", "J0YQQx6sv/Elt2kRDVPlXg==", "2U6d1qsPVwS8vUnflv9AcQ==", "TuBnhFrkwMqIcYtYYgNGNQ==", "v1exQXePimNPt3tveLBP9g==", "usSOeO0eis4fMxpUrYF1Og==", "PRkbEOx7V6ePRT/WUyklHg==", "Pe4IHqZpuBtuSkrgd2HMEg==", "8KJb4x3mXgChaQULEsid2A==", "jKke6Txz52GXq3xidnEMgg==", "crmilTSJ/pTSPBKY9EJmZg==", "qXNASosSuCsudML1MqXPjw==", "4JszZEguo/SAFbgp6PdKMQ==", "dYucp/SettSQd/Hpukj6pA==", "Znm2hdK/FULQhTTGTVX59Q==", "noXaVqkCbpzn51NS8fKFEA==", "zWleXlh1b6JsvwGVnX0JVA==", "fayrPya6DVXP9weWvA6obQ==", "wbBiCPikq6Iz02EPsysTgA==", "fT6cIVRM+743nfHJKo4yuQ==", "A0ZMrO+gsPP+1kjH7JYgNw==", "vTJZ/R8pdcyDbwAwRi8cBw==" ], "P5UTXxqhA6R98OWY7h85rQ==": [ "yiTWIBfruE5rPxLBPqTezA==", "DDWmqlxBSfXi2KJJ5mwTNg==", "HNpGGr9eP5twQKC3yCh1mA==", "F0n/1XXyzTob8lElmXmB6g==", "YiJlkUTKf0/7+ORZMmQ2cw==", "O8fIVXqcGshIonMWsEH9gA==", "8Sec+JvKiQWGqYCOBdZhjg==", "G2Djh6mj4eOKfpIiPPuLew==", "AE8Cp1u8I9t52OYW7oGU4w==", "klCkJxhhNVG564GOUQMh+Q==", "OPNDKUsVLJt2v1gO1zvkBA==", "wxS+u/uf8o4sT9iSccXQwA==", "AFfQXLrpt1jw7bczIIvo6Q==", "XygysGe2kdlyCRQHM1fu3w==" ], "PYGQE1Mr52aqIP4tEB4VSw==": [ "+nHq7dak7Hkjcru/xpwzhQ==", "L7QbkTbsy8v3tMfOqNsVKQ==" ], "PcSVlceQ6PCKCKw9Y7o89w==": [ "EpK5bQtJedMNlT+XQ842nA==", "GY12kVf6J5Mt34JLrWLJkw==", "2GyYg2XSUSR6EJven3MV7w==", "RYqFgDYIttLgJc8B82sK/w==", "Tld/B+HymU17Pebpq5Rixg==", "Lt2Hg7sVYgz0GD7ldFmjjA==", "qC/lM94bJkHuTCcx6Z47mQ==", "YNodYYe4cB6HofVRKHeLCw==", "tYyvZPBVQRP63VPhfANtWw==", "gt35pyOzR5Ohdk7qjUsg2w==", "KExChYIaW0MvXNLWbjS/Hw==", "LTmcTrhW8bJGvJXJVPjm/g==", "BWyeN3+8e4QAjW/V4C/Ktg==", "tYeLT/YUKIk7yaK07WvPeA==" ], "Q0uPb/t/3IQ8GEwlv/J3Cw==": [ "WGvgNwrW2u5APZcidQ6v1Q==", "0IkIJ5q/xNX41U2yF71Pyw==" ], "QC6e3OaV78mjs678tGU2KQ==": [ "KCgCqCavM9U0xL+GHJqzSg==", "0fRIluxuaC1n6wm+qP9Pjw==", "H9Ud41wofJc/QlL6Rm7WkA==", "Ig/iNncFD4P4EYoOu9TAeQ==", "Wp4+QBQm4nhI8rQxVklEXw==", "YOjk++xRTh9VXO273YBySg==", "a9FCHpokzVfpw+gdnrzSXg==", "Rfm1tD+QxSP/TVjKFDNabg==", "OgFGrvrnAoXXvapnatTrxQ==", "assnsOgZ19ItYfuh/iKLMA==", "W0l4QAgarxrOkTlGvtp0uA==", "npQpPXYG8xMJ1LRSVSnKGA==", "jO9fUvpFi0R9/mJ1YH7KXA==", "ruDQdx7OmIsgMCpioWbqOQ==", "XbpXfbeApuDuIKvY0/qWiA==", "R90VfdEewbj2ZB0bKqbhNA==", "UUIKm7f4jyfDWGKvptUQ8Q==" ], "RtlxSleee0sHxodv8Zav/g==": [ "RdjNn4dAdZKcn6VS95a/SQ==", "9oBjtBiHtz7+Hwc4swPaAw==", "kCsMurCi7F77HxJoLqd9jA==", "/1CYFiexnJcM7p4YrI/FVg==", "9ZCmRufeuC0TKSSi9pcU6g==", "eCNdMtt9JN2Rrb8I23NIsA==", "3IgZDz5UYkhu/U1/4kSWKg==", "K3eafQ/8P8PEZ3BPWZfCgg==", "UyCjBcpeB0nhkRTVhUcAJQ==" ], "TpA/hV9k8pWHhLODuSJ+Zg==": [ "8rDgIikh0LbAtcEOjHed4Q==", "mVZw6HfBeWMeBMbQ3QI3eQ==", "6Cqvzp5JbuVfHsuYnIJNFw==", "cqYWiTibDLM7aibErMKang==" ], "UUZyda9G/ffvF6rJ5W1UnQ==": [ "mouoWVvs12H8FynnB5qIsQ==", "ieASPdYzGxWke8nZZhE02Q==", "sRVcQFAdq4Ll42smqacaCw==" ], "VT/lJKaSpr1RIIPMBOKV+A==": [ "WGOq+rhe3/NaL51WCyZSeA==", "QwBnC+2unbl7BaURui6Tng==", "fvGjL9hw9hDQockMTb7lrA==" ], "W66WOQ3v6r7mSn6+o7gaew==": [ "6UnjveNMgk4ukDQJdTGvOQ==", "DkHpdzAuAlElCotBlgVgPA==" ], "YjDcGmvP0/z8VqRiUvkhOQ==": [ "W/d4trZ7jb2yxjrq4cNOWA==", "sThg2GGoKqa1RTJ5skEJTA==", "0nQ3GJDLY22M176Z5ESg6A==", "yuFlxOGqQlDuMCywIIELNw==", "DdbtHYUAFK3EvhnE38LOBw==" ], "ZALhBg0G9taJfH1fvOjqNg==": [ "54QMeb97RdTZwYWYELMfPw==" ], "auI8KtI6OozP7EAIr9UlQQ==": [ "icj6a8bc4dYK/DJNvkU0+A==" ], "bWUdPEYmtshwdmuX5VapfQ==": [ "WGvgNwrW2u5APZcidQ6v1Q==", "0IkIJ5q/xNX41U2yF71Pyw==" ], "dOwQwVL1NxmF6ouACZklrQ==": [ "8WDcymWmuQ3Sn9ymHvtn4Q==" ], "f/Al/eNlUhjEgKSV0J2z7w==": [ "QSNBg/XspHcBwSxBTMU4rg==", "gaFOKxy9D9KR/Iyd+kDZoA==", "HuLJLN6ajygY/CpLyzV5lw==", "8I2jFG8JRR+6+eqqYlXhAg==", "xKLQGv5zNwcnWtQQKiO3Ww==", "s7NZ7NlWAuuGAV0/d83+kA==" ], "h53SWWmMQUh4cLyBmYeNvw==": [ "7lnphmrb/VojuhlikpNO5w==", "Bgew407C4GMDdNe8dNeN7w==", "A1UDSDMkPKOSx7ma/geQyg==", "teoauN/Djw6odXikmjP4Lw==", "9jHXNtwzqlOir/Op7pd9+w==", "sExC9WXn4M01POjg0haQrA==", "NZdLkPGdPGyb8ltD0LX9SQ==", "MW3KGjkk7BWuR5JCc6cywg==", "Rw8DyDlyRHRJOeZaAbGMRA==" ], "hSTTMcRX1DBcXc+8jKeg3Q==": [ "mouoWVvs12H8FynnB5qIsQ==", "ieASPdYzGxWke8nZZhE02Q==", "sRVcQFAdq4Ll42smqacaCw==" ], "isKqi8Xwt9MjwRVhU+6KzQ==": [ "8rDgIikh0LbAtcEOjHed4Q==", "mVZw6HfBeWMeBMbQ3QI3eQ==", "6Cqvzp5JbuVfHsuYnIJNFw==", "cqYWiTibDLM7aibErMKang==" ], "isPl2YxnCTfcLmUYH6Q0sA==": [ "WGvgNwrW2u5APZcidQ6v1Q==", "0IkIJ5q/xNX41U2yF71Pyw==" ], "jJ8GFze+u3yX6EECKEDlVA==": [ "iP8YLvnxQemAwp/nhhOW0w==", "IItHEdPWz5fl9O7ZhzjDAA==", "0QzoXQSqkKieJ7Oc+px0JA==", "nhJPQpDYg9We/U8oBJw4JQ==", "ZlxfTVb/4bi6yWQ+JLaOnw==", "HKrLnQyTw1292mNt3MQ0aQ==", "h6rS2s3xilGaG0a+pIjl8A==", "Z98lUsU1mVOsrmb49hActA==", "2U8ppg+02PjFDuM5YqFstQ==", "L3k0cIIlkMGQFiWnZm8Mlg==", "/jsmptxiHRXbuYhopHC+AQ==", "OFdQC3/0S5rItoyqpACTFw==", "HB9r/GLycEmk6aXttwtBlw==", "cCowLuOsLfTMmPFOoqUVww==", "eO2vvxX2WuQSx4VuCGHAwQ==", "5ZHvcDYhgzWjwNpRgF2u1w==", "Fd2ov7jSJY3Im+378GMgdA==", "fg5E5MKinCbJn9w+SABeOA==", "8rvqTFlh9aOz4UvxQN0SBQ==", "RVCidRUm4D1IKoPhoUi2AA==", "6Xr5PbPGSy+aHLDQ9q4L9w==", "8qOJVWAut1+UqTXPOWH12g==", "x6XC/EvXu5oMyj7ZxrTczA==", "sGwL9v57mGx7f18qBkIacA==", "nYtstWEUOCTbjAlmYOKURA==", "XXiaw1EwhFkuilI94EKiqQ==", "mRazAXjBcgFrTolNDZHDsA==" ], "k4gCNgIfg7MM/e42ThRx2w==": [ "AZQ9MHTiNLYiRU7sYZlVGw==", "n83jaRl/T6kiaoMyWtX8xw==" ], "kwc9NYOQig+qWs5qmBRL/w==": [ "ofnnqzvHUpmPXQD17CK0Og==", "673FKazcUiydbfN5c6amaw==", "jw1ZiDut5Ot+DyVFjCrixg==", "rEg00U8+//igCt+0+QBUhA==", "HuOxI+pWjgGV0XsBvltzlg==", "SHxE0qXbBmDEp/LL1ieJeA==", "xCUiEQAH1lfhrKtUxQDIYA==", "ZTGiJlkqcqrCLJSY/Sq8lA==", "VsocCwaFpF6PzdX5PxR+sQ==" ], "lU0MYRg2dg5wynl2dMGsgA==": [ "hfBpyVezkUAf98QWnlvzIA==" ], "mlTBgPgv44eBdmn7f2Thag==": [ "dLBwvrbHvvMzC4tdzDzNMw==" ], "mtrWxjnWyzrIFOuHVeUG6g==": [ "O0WA+v5udE7etzYMGY4hKQ==", "y9TonkypWBSeUSxUDKIRrw==", "UMD4nV1Ky5C5eKUMgtnKzw==", "W/DMqBRMDYVkVH3D67luGg==", "XBiy/XVR6SoThCkYUmkD1g==", "8rxYDEPu2XxazQ3cBUhX0Q==", "vx2N2RZTm7neux8kVlqgEg==", "9uK7ZDYgFtqP786n0QunAg==", "xC2ob9wKqI1kERs3y1j4vA==", "AIctk9Oe2AgHDAC8E7gw8Q==" ], "peUaHHW4E9Y6Nd8+gJR5cQ==": [ "KCgCqCavM9U0xL+GHJqzSg==", "0fRIluxuaC1n6wm+qP9Pjw==", "H9Ud41wofJc/QlL6Rm7WkA==", "Ig/iNncFD4P4EYoOu9TAeQ==", "Wp4+QBQm4nhI8rQxVklEXw==", "YOjk++xRTh9VXO273YBySg==", "a9FCHpokzVfpw+gdnrzSXg==", "Rfm1tD+QxSP/TVjKFDNabg==", "OgFGrvrnAoXXvapnatTrxQ==", "assnsOgZ19ItYfuh/iKLMA==", "W0l4QAgarxrOkTlGvtp0uA==", "npQpPXYG8xMJ1LRSVSnKGA==", "jO9fUvpFi0R9/mJ1YH7KXA==", "ruDQdx7OmIsgMCpioWbqOQ==", "XbpXfbeApuDuIKvY0/qWiA==", "R90VfdEewbj2ZB0bKqbhNA==", "UUIKm7f4jyfDWGKvptUQ8Q==" ], "s5qs8lj0/L/p9c08upXwSg==": [ "M59UwDbs3+/LtSu1P1x+Rg==" ], "trIX86+UkjuJsaeYfHvnYw==": [ "o8knMpkoquoumaFb+1FM4A==" ], "uCw7c1p0VzVV36rFL2/j4Q==": [ "5N/X0o1/JN9fqvD4aiuURA==" ], "wJ4dAQ6SE4hHS42wVhzrWg==": [ "8TgjbHNGzIFm7/fF9DBU7Q==", "FkRDB0vpJYeh2ipqLS0/Iw==", "Te9j1HGn7feNCE/Fduu0+A==", "29qrZyz+fmdn9Nzjpl2/Pg==", "1vG4ZYIu07BTj9XJ+a+P9Q==", "YoCxZvEp16Bt9LDv+Ficeg==" ] }, "enrichments": { "message/vnd.clair.map.vulnerability; enricher=clair.cvss schema=https://csrc.nist.gov/schema/nvd/api/2.0/cve_api_json_2.0.schema": [ { "+et2nlLBpUOdsIiOQHCCVQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L", "baseScore": 4.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "+nHq7dak7Hkjcru/xpwzhQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "/1CYFiexnJcM7p4YrI/FVg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "/jsmptxiHRXbuYhopHC+AQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "0IkIJ5q/xNX41U2yF71Pyw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0QzoXQSqkKieJ7Oc+px0JA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0nQ3GJDLY22M176Z5ESg6A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "0v/g0Z/XEXV13r48i52JgA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1vG4ZYIu07BTj9XJ+a+P9Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2DLcncUUd6/1/JtsPnknxw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "baseScore": 4.3, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "2GyYg2XSUSR6EJven3MV7w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "baseScore": 6.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "LOW" } ], "3IgZDz5UYkhu/U1/4kSWKg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "4JszZEguo/SAFbgp6PdKMQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "4jAWcNPbUa6mXzywmxFG1g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "54QMeb97RdTZwYWYELMfPw==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "5B1tQ2BK8z/YjRkYcvwqag==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "619DQiII/+IW12e6tmtrxw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "673FKazcUiydbfN5c6amaw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "6FQUI3OxX4C5skWXKgq80Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7lnphmrb/VojuhlikpNO5w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "86unVXyTxdffdcXWZTYw5g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "8I2jFG8JRR+6+eqqYlXhAg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "8Sec+JvKiQWGqYCOBdZhjg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H", "baseScore": 6.6, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8TgjbHNGzIFm7/fF9DBU7Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "baseScore": 4.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "8ZxbhBIT+9Mj99/XbMpLSQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8rxYDEPu2XxazQ3cBUhX0Q==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9ZCmRufeuC0TKSSi9pcU6g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "ADJACENT_NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "AFfQXLrpt1jw7bczIIvo6Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "AIctk9Oe2AgHDAC8E7gw8Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "AZQ9MHTiNLYiRU7sYZlVGw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "BV++s35Ur4bQRS6HK0QCIA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "BooDzA4nzaDI1l3E5zAHgg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "CPZo3oXfySRcVVjDJkrS3g==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "CwmELSAfO/DM/HghGDWwow==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "EKs36DFwHVCzU/cF0Be9pQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EiJx6rOT8KoLX+Wu7/N6HQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EiL50P2QSOoRA18XAAH6Pg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EpK5bQtJedMNlT+XQ842nA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "baseScore": 6.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "LOW" } ], "Fd2ov7jSJY3Im+378GMgdA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "G7IyfoPhe9f8QzIGbOfn7Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GWg5WOvOqfRt4sWhRhSM+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", "baseScore": 8.6, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "GY12kVf6J5Mt34JLrWLJkw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "H9Ud41wofJc/QlL6Rm7WkA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "baseScore": 3.1, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "HKrLnQyTw1292mNt3MQ0aQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "HuLJLN6ajygY/CpLyzV5lw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N", "baseScore": 4.2, "baseSeverity": "MEDIUM", "attackVector": "ADJACENT_NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "HuOxI+pWjgGV0XsBvltzlg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "K3eafQ/8P8PEZ3BPWZfCgg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N", "baseScore": 6.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "KCgCqCavM9U0xL+GHJqzSg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L", "baseScore": 6.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "KaROgE0QmtiOixMG9Wi1RA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "L3k0cIIlkMGQFiWnZm8Mlg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "L7QbkTbsy8v3tMfOqNsVKQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "LTmcTrhW8bJGvJXJVPjm/g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 2.5, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "LWLSX4FCLbzYWK97i5Or+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Lt2Hg7sVYgz0GD7ldFmjjA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "M59UwDbs3+/LtSu1P1x+Rg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "NZdLkPGdPGyb8ltD0LX9SQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "O8fIVXqcGshIonMWsEH9gA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H", "baseScore": 5.6, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OFdQC3/0S5rItoyqpACTFw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OPNDKUsVLJt2v1gO1zvkBA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "QSNBg/XspHcBwSxBTMU4rg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "QUtTYJuHdkAOgtveagWUfA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "R0kLLh/19P/mLd+t6ufaFg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "R90VfdEewbj2ZB0bKqbhNA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "RVCidRUm4D1IKoPhoUi2AA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "RYqFgDYIttLgJc8B82sK/w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "RdjNn4dAdZKcn6VS95a/SQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.2, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Rfm1tD+QxSP/TVjKFDNabg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "SHxE0qXbBmDEp/LL1ieJeA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Tld/B+HymU17Pebpq5Rixg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "baseScore": 6.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "LOW" } ], "UMD4nV1Ky5C5eKUMgtnKzw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "UPzTyNn8ZLXlb+bwRFPPTA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "UbmdE2pHXRFccv8l1e02Jw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "UyCjBcpeB0nhkRTVhUcAJQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.2, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VsocCwaFpF6PzdX5PxR+sQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "W/d4trZ7jb2yxjrq4cNOWA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "XBiy/XVR6SoThCkYUmkD1g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "XbpXfbeApuDuIKvY0/qWiA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XygysGe2kdlyCRQHM1fu3w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.0, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YOjk++xRTh9VXO273YBySg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YbAnIQEqWeedb46YJk3cBg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YiJlkUTKf0/7+ORZMmQ2cw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Yruwfu4Vkg/KNSmhqw2VEg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "Z98lUsU1mVOsrmb49hActA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ZTGiJlkqcqrCLJSY/Sq8lA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ZvX4VR3jvMBd1Wq+RxNTgg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "a9FCHpokzVfpw+gdnrzSXg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dGtImtgXxemdBTM1vCCLUg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L", "baseScore": 4.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "dYucp/SettSQd/Hpukj6pA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "fayrPya6DVXP9weWvA6obQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fvGjL9hw9hDQockMTb7lrA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gaFOKxy9D9KR/Iyd+kDZoA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "gt35pyOzR5Ohdk7qjUsg2w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "h6rS2s3xilGaG0a+pIjl8A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "hfBpyVezkUAf98QWnlvzIA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "icj6a8bc4dYK/DJNvkU0+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ieASPdYzGxWke8nZZhE02Q==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jO9fUvpFi0R9/mJ1YH7KXA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "jw1ZiDut5Ot+DyVFjCrixg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mQtrNhzMQ9mAh/coURV/3g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mouoWVvs12H8FynnB5qIsQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "n83jaRl/T6kiaoMyWtX8xw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "nhJPQpDYg9We/U8oBJw4JQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "noXaVqkCbpzn51NS8fKFEA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "npQpPXYG8xMJ1LRSVSnKGA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ofnnqzvHUpmPXQD17CK0Og==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qC/lM94bJkHuTCcx6Z47mQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qXNASosSuCsudML1MqXPjw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "qld8Wk8WGHJZFjcPP6Ptwg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "rEd6JdG2xx5NZ9bcsFRNpw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rEg00U8+//igCt+0+QBUhA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rP7oa42+SZpvxen+n93BaQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rVgBV65FWtFg3jitEqotFA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "sGwL9v57mGx7f18qBkIacA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "sRVcQFAdq4Ll42smqacaCw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "sThg2GGoKqa1RTJ5skEJTA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "srdggAxrYxj8SIe8dBdTNA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "t4oe6DBPNf5Ikk93RfTdig==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "tGsvzSy2YAolN7IIXG6tpA==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "tYeLT/YUKIk7yaK07WvPeA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "tlWVK61iOpKPkvmeShS9AQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uEggs7thHCRp4eZu5EDH0A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "vx2N2RZTm7neux8kVlqgEg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "x6XC/EvXu5oMyj7ZxrTczA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "xCUiEQAH1lfhrKtUxQDIYA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "xKLQGv5zNwcnWtQQKiO3Ww==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "xLIujTim86EomaRofe4tDg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "yiTWIBfruE5rPxLBPqTezA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "yuFlxOGqQlDuMCywIIELNw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zXrrwuYD9wK+seRCGBDutA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ] } ] }, "PackageNotVulnerable": {} }